Winning combination of software products for iGaming
Senior Application Security Engineer
Location
Poland
Posted
13 hours ago
Salary
0
Seniority
Senior
Job Description
Senior Application Security Engineer
SOFTSWISS
• Partner with product teams during the design phase to lead threat modeling and risk assessments sessions, translating complex security threats into clear, actionable security requirements • Perform in-depth manual code reviews on critical applications to identify complex logical vulnerabilities as part of white-box security assessment • Plan, design, implement, automate and (if you wish) support AppSec tools • Contribute to building a company-wide processes for secure code development and deployment • Triage identified security vulnerabilities, provide clear and actionable descriptions and ensure these findings are properly addressed and mitigated • Manage the bug bounty program, collaborate with researches and internal teams to resolve the discovered vulnerabilities • Partner with Dev/QA teams throughout the development lifecycle to enhance the application's security posture by providing expert consulting, continuous knowledge sharing, and actionable security guidance
Job Requirements
- 5+ years of experience in Application Security
- Knowledge of secure development processes and best practices
- Deep understanding of web application security mechanisms (i.e., how the web actually works? What is SOP and why do we need CORS? What is CSP?)
- Deep understanding of common web application vulnerabilities (i.e., OWASP Top 10), and the most effective ways to prevent them
- Knowledge of secure system/application architecture and design principles
- Understanding of modern threats to high-performance web applications that are used by millions of users daily
- Understanding of modern authentication/authorisation patterns (OAuth, OIDC, JWT, etc.)
- Practical hands-on expertise in identifying vulnerabilities through security assessment and secure code review, coupled with the ability to perform deep root-cause analysis to drive systemic fixes
- University degree in Computer Science, Information Security, or related field, or equivalent combination of education and experience
- English and Russian proficiency at an upper-intermediate level (B2+)
Benefits
- Private health insurance
- Sports benefits
- Comprehensive Mental Health Program
- Free English lessons (online)
- Local language courses
- Paid time off
- Maternity leave support
- Referral program rewards
- Upskilling, internal workshops, and participation in professional conferences and corporate events
Related Guides
Related Categories
Related Job Pages
More Application Engineer Jobs
Senior C++ Engineer, Desktop Applications
Sigma Software GroupWe support enterprises, product houses, and startups with custom software solutions development and IT consulting.
• Develop and maintain high-quality desktop application components using modern C++ • Implement scalable multithreading and concurrency solutions • Analyze, identify, and resolve performance bottlenecks in complex desktop systems • Participate in modernization and refactoring of legacy codebases • Collaborate with architects, QA engineers, and product teams to deliver stable and efficient solutions • Contribute to software quality improvements, debugging activities, and system stability initiatives • Utilize AI-assisted development tools to improve development workflows and accelerate implementation activities • Participate in technical discussions, code reviews, and engineering best practices initiatives
Application Infra Engineer
Sequoia ConnectOur core expertise lies in connecting Top Technologists with Top Companies through unparalleled IT headhunting solutions
Role Description We are currently searching for a Application Infra Engineer (storage) : - Identify and catalogue residual NAS file shares, CPU allocations, and object storage linked to decommissioned applications. - Analyze data in Excel and internal tools to identify decommissioning candidates and measure outcomes. - Engage application owners to notify them of remaining infrastructure and secure formal approval for deletion. - Raise and manage Change Requests for approved decommissioning actions. - Work with Storage, Compute, and Platform teams to execute permanent infrastructure removal. - Track progress, escalations, and blockers via Jira—maintain clean boards and accurate status at all times. - Produce and distribute structured notifications, reports, and dashboards to stakeholders and senior leadership. - Proactively follow up on outstanding approvals and escalate delays per SLA with clear professional communication. - Continuously improve processes, templates, and automation to increase decommissioning throughput. Qualifications - Bachelor’s or Masters in Computer Science, Applied Mathematics, Engineering, or a related quantitative field. - 3–5 years of professional experience in infrastructure management, technology project delivery, and/or enterprise-scale environments. - Proficiency in Unix/Linux Shell Scripting (PowerShell, Bash). - Basic proficiency in Python (scripting, automation, data manipulation). - Solid understanding of NAS / File Storage (mounts, shares, volumes, quotas, and lifecycle management). - Familiarity with on-prem capacity management and decommissioning procedures for CPU / Compute Infrastructure. - Awareness of cloud/on-prem object stores and data retention policies. - Familiarity with change management processes in regulated financial industries. - High-Performance Mindset: Resilience, emotional intelligence, and a focus on agile delivery. - Technologist DNA: A deep understanding of the difference between "coding" and "engineering." Requirements - Working knowledge of IDEs such as VS Code, IntelliJ IDEA, and PyCharm. - Familiarity with AI engines and assistants (e.g., GitHub Copilot, ChatGPT, Gemini, Claude) to accelerate operational tasks and reporting. - Experience with data analysis and reporting using Excel (pivot tables, VLOOKUP, conditional formatting) and dashboards. - Familiarity with cloud-native foundations or AI coding assistants. - Advanced Oral English: For seamless collaboration with global teams. - Advanced Spanish. Benefits - Flexible work arrangement: Remote.
Windows Application & Custom Engineer
C5MI InsightC5MI is not your typical consulting firm. We are a high-performance team of SAP and supply chain experts who solve complex, mission-critical challenges for organizations that cannot afford failure. Our culture rewards initiative, accountability, and continuous growth.
Role Description The Windows Server & Custom Application Engineer is responsible for engineering, integrating, maintaining, and supporting Windows-based infrastructure components and custom applications that enable the DLA SAP Security program. The position serves as the technical liaison between SAP Security, Enterprise Infrastructure, Cybersecurity, and Application Development teams to ensure security-related applications are reliable, secure, and compliant with Department of Defense (DoD) and DLA requirements. - Designs, develops, and implements security solutions to safeguard digital assets and business operations. - Integrates security controls into systems, applications, and processes to protect against cyber threats, unauthorized access, and data breaches. Qualifications - Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or a related discipline with 3-5 years of experience supporting Windows Server environments; or no degree with 5-7 years of experience. - Experience supporting Windows-hosted enterprise applications. - Experience with IIS, Active Directory, and PowerShell. - Experience integrating enterprise applications with identity management solutions. - Must be able to obtain and maintain an active government clearance (requires U.S. citizenship). Requirements - Designs, configures, and maintains Windows Server environments supporting SAP Security applications. - Engineers secure and resilient Windows solutions in accordance with DLA security standards. - Coordinates server provisioning, upgrades, and maintenance activities with Enterprise Infrastructure teams. - Evaluates and recommends infrastructure improvements that enhance application availability and performance. - Supports high availability and disaster recovery planning for Windows-based security applications. - Supports the deployment, configuration, maintenance, and troubleshooting of Windows-hosted custom applications supporting SAP Security operations. - Coordinates application releases and production deployments with development teams. - Configures IIS web servers, Windows services, scheduled tasks, and application environments. - Troubleshoots application performance, connectivity, and authentication issues. - Supports software lifecycle management, including testing, upgrades, and configuration management. - Supports Active Directory integrations for SAP Security applications. - Configures and maintains authentication services, service accounts, and directory integrations. - Supports Microsoft Entra ID synchronization and identity federation services. - Manages digital certificates and Public Key Infrastructure (PKI) components supporting security applications. - Assists with implementation of multi-factor authentication (MFA) technologies where applicable. - Develops PowerShell scripts and automation solutions to improve operational efficiency. - Automates system health monitoring, reporting, and administrative processes. - Improves deployment, monitoring, and maintenance activities through scripting and automation. - Identifies opportunities to streamline manual operational tasks. - Monitors Windows-based applications and supporting services. - Analyzes system logs and application performance data to proactively identify issues. - Coordinates incident resolution with Windows Infrastructure, Application Development, Cybersecurity, and SAP Basis teams as appropriate. - Participates in problem management activities, including root cause analysis and corrective action planning. - Supports compliance with DLA cybersecurity policies and DoD security requirements. - Coordinates vulnerability remediation activities for Windows-hosted applications. - Supports Security Technical Implementation Guide (STIG) implementation and compliance. - Assists with cybersecurity assessments, audit preparation, and Authority to Operate (ATO) activities. - Maintains technical documentation supporting security accreditation and audit requirements. - Adheres to all certified processes as part of our commitment to maintaining the highest standards of quality and information security. - Performs other related tasks as assigned by direct supervisor. Benefits - Market competitive suite of benefits including medical, dental, vision, life, and long-term disability coverage. - 401(k) plan. - Bonus opportunities. - Paid holidays and paid time off.
• Design, develop, and implement enterprise AI applications utilizing Large Language Models (LLMs) and Retrieval-Augmented Generation (RAG). • Develop AI-assisted search, summarization, and question-answering capabilities using Amazon Bedrock. • Build reusable AI services supporting prompt orchestration, document retrieval, and response generation. • Implement prompt engineering and source-grounding strategies to improve AI accuracy, consistency, traceability, and clinical relevance, including source links that support human verification. • Optimize AI performance while balancing response quality, latency, and operational cost. • Design and develop secure, scalable cloud-native applications utilizing modern software engineering practices. • Develop RESTful APIs and backend services supporting AI capabilities and enterprise integrations. • Implement approved document retrieval, vector search, and semantic search capabilities within the selected patient context and CHSD document set. • Develop automated unit, integration, and functional tests and repeatable AI evaluations for groundedness, retrieval quality, and clinical relevance supporting AI-enabled applications. • Troubleshoot software defects, optimize application performance, and support activities within the approved test environment and for future production readiness. • Integrate AI capabilities into existing enterprise healthcare applications and clinical workflows. • Develop secure interfaces utilizing REST APIs and modern integration patterns. • Support interoperability utilizing healthcare standards including FHIR, HL7, and CCD. • Collaborate with Solution Architects and engineering teams to implement scalable and maintainable application designs. • Participate in code reviews and promote software engineering best practices across the development team. • Develop secure software in accordance with Federal cybersecurity and privacy requirements, including approved data-retention and purge controls. • Support CI/CD pipelines, automated deployments, and cloud-native operational practices. • Implement logging, monitoring, audit capabilities, and operational telemetry, including model and prompt version tracking, usage and cost monitoring, and controls to detect model, prompt, retrieval, and data drift. • Support application security scanning, vulnerability remediation, and activities within the approved test environment and for future production readiness. • Incorporate Responsible AI, Human-in-the-Loop (HITL), and AI governance principles into application development. • Collaborate with architects, product owners, clinicians, cybersecurity teams, and Government stakeholders throughout the software development lifecycle. • Participate in Agile ceremonies including Sprint Planning, backlog refinement, Sprint Reviews, and Retrospectives. • Contribute to technical documentation, implementation guides, and software design artifacts. • Present technical solutions and implementation approaches to project leadership and stakeholders.



