GetGlobalJob

Application Security Architect

Capital · Warsaw, Mazowieckie, Poland | Sofia City +2

Hybride
Postuler sur le site d'origine ↗Connectez-vous pour enregistrer

Connectez-vous et importez votre CV pour voir votre compatibilité avec cette offre.

Se connecter

Résumé du poste

Lieu
Warsaw, Mazowieckie, Poland | Sofia City +2
Mode de travail
Hybride
Date de publication
29 sept. 2026
Dernière vérification à la source
11 oct. 2026
Source de l'offre
Site carrières officiel de l'entreprise

Missions

Security Architecture & Standards: • Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services • Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing • Lead the redesign of user authentication and the delivery of security features into the product • Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room • Define internal policies for the safe use of AI-assisted and vibe-coding tools • Define security requirements for acquired technology and guide its secure integration Threat Modelling & Design Review: • Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product's risk tier • Own the security review stage of the new product approval process, covering architecture design and configuration • Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors • Identify design-level risks and agree practical, prioritised mitigations with engineering teams Secure SDLC, DevSecOps & Supply Chain: • Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership • Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering • Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths • Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity • Improve the security of our internal tools

Profil recherché

Experience: • 8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership • Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation • Deep, demonstrable threat-modelling experience across product portfolios Technical: • Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome • Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management • Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients Collaboration: • Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives • Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan • Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration

Compétences

Visa et relocalisation

L'annonce ne parle pas de visa. Vérifiez l'annonce d'origine ou demandez à l'entreprise.

L'annonce ne mentionne pas de relocalisation.

Description du poste

Responsibilities: Security Architecture & Standards: • Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services • Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing • Lead the redesign of user authentication and the delivery of security features into the product • Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room • Define internal policies for the safe use of AI-assisted and vibe-coding tools • Define security requirements for acquired technology and guide its secure integration Threat Modelling & Design Review: • Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product's risk tier • Own the security review stage of the new product approval process, covering architecture design and configuration • Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors • Identify design-level risks and agree practical, prioritised mitigations with engineering teams Secure SDLC, DevSecOps & Supply Chain: • Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership • Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering • Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths • Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity • Improve the security of our internal tools Requirements: Experience: • 8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership • Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation • Deep, demonstrable threat-modelling experience across product portfolios Technical: • Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome • Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management • Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients Collaboration: • Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives • Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan • Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration Nice to have: • Experience in fintech, trading, brokerage, or another regulated environment • Awareness of relevant regulatory and compliance drivers: FCA and CySEC operational resilience, GDPR, and PCI DSS • Software supply-chain security, including SBOMs and artifact and build integrity • Experience securing AI-integrated product features, or using AI to scale an AppSec programme • Experience building or running a Security Champions programme • CSSLP, GIAC GDSA, or a hands-on offensive security certification. Certifications are valued but secondary to demonstrated experience What you'll get in return: • You will join the company, that cares about work and life balance • Annual Bonus based on the performance review cycle • Generous Annual Leave Policy • Medical Insurance and Pension fund, with additional benefit packages based on the location • Hybrid working model (3 days from our modern office and 2 days fully remotely) • Comprehensive Workation Policy with 30 more remote days available. • Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.
Postuler sur le site d'origine ↗Source de l'offre : Site carrières officiel de l'entreprise

GetGlobalJob n'est ni l'employeur ni un intermédiaire de recrutement. La candidature se fait sur le site d'origine : vérifiez toujours l'annonce avant d'envoyer vos données et ne payez jamais pour un emploi.

Évaluez votre adéquation avec ce poste

Créez votre compte gratuitement et importez votre CV pour voir votre taux d'adéquation avec ce poste et les compétences qui vous manquent.

Évaluer mon adéquation