← Back to list

Job
· Senior
Application Security Specialist (regular/senior)
Security Engineer
• Senior
• On-site
• Full-time
•
Warsaw, Poland
Accenture Security's cyber security team in Poland is hiring an Application Security Specialist (regular and senior levels) to embed security into the development lifecycle, cloud and AI-enabled systems at client sites.
Responsibilities
- ▹Assess where a client stands against OWASP ASVS, OWASP Top 10, OWASP API Top 10 or CWE Top 25 and turn gaps into a prioritized roadmap
- ▹Run threat modelling and secure design reviews with clients' architects and developers across hybrid, distributed, cloud-native, containerized, microservices, event-driven and monolithic systems
- ▹Review code, APIs, Infrastructure as Code and CI/CD pipelines from a security point of view and help teams fix the findings
- ▹Build security into pipelines, build systems and artefact repositories, and address software supply chain risk (dependencies, build integrity, SBOMs, third-party components)
- ▹Select, roll out and tune AppSec tooling (SAST, DAST, SCA, secrets scanning) so that results are trusted and acted on
- ▹Work on the security of AI-enabled systems: LLM-based applications, AI agents, model and data pipelines, and risks such as prompt injection, data poisoning and unsafe integration
- ▹Define controls across the AI lifecycle, use AI-based tooling for code analysis and vulnerability triage, and support governance and compliance around responsible AI use
- ▹Create secure coding standards and design guidance, guardrails for developers' use of AI coding assistants, a security champions program and hands-on developer training
- ▹Present findings and recommendations from team leads up to CISO level
Requirements
- ▹Engineering or IT background: practical experience building, running or designing software systems or infrastructure
- ▹Foundational security knowledge: confidentiality, integrity and availability; familiarity with encryption, hashing and key management, including common misuse patterns
- ▹Understanding of the software development lifecycle
- ▹Familiarity with DevOps and CI/CD: hands-on experience with at least one platform (GitHub, GitLab, Azure DevOps, Bitbucket, Jenkins or equivalent) and understanding of build processes and pipeline configuration
- ▹Hands-on experience with at least one public cloud platform (AWS, Azure or GCP), including core services and security controls
- ▹Ability to read code and identify common vulnerabilities (SQL injection, XSS, command injection, CSRF) in at least one language (Java, C#/.NET, JavaScript, Go, Python or equivalent)
- ▹Professional proficiency in both English and Polish (mandatory; English for client-facing work, Polish for day-to-day team operations)
- ▹Regular level: approximately 2-5 years of relevant experience, independent delivery of defined workstreams (threat modelling, pipeline and IaC reviews, findings reporting), working knowledge of the OWASP Top 10 and secure coding principles
- ▹Senior level: approximately 5+ years of relevant experience, leading workstreams, providing technical direction and mentoring juniors, demonstrated depth in at least one domain (cloud security, software supply chain, AppSec tooling, secure design and threat modelling, or AI security)
Nice to have
- ▹Application security fundamentals in practice: OWASP Top 10, OWASP ASVS, OWASP API Top 10, CWE Top 25, secure coding best practice, common vulnerability classes and exploitation techniques
- ▹Threat modelling experience that takes business logic, architecture and deployment model into account
- ▹Authentication, authorization and session management: OAuth 2.0, OpenID Connect, SAML, SSO and modern identity-centric security models
- ▹Experience running, tuning or fixing SAST, DAST and SCA deployments that had lost developer trust
- ▹Securing CI/CD pipelines, Infrastructure as Code, container platforms and the software supply chain: dependency scanning, SBOM, SLSA, artefact signing
- ▹Hands-on experience with additional cloud platforms (AWS, Azure, GCP) and their native security services
Soft skills
Strong communication skills, translating complex technical findings into clear, actionable recommendationsProactive, ownership-oriented mindset, driving security improvements independently in a client environmentAdaptability and commitment to continuous learning
What we offer
- ▹Work on international cybersecurity transformation programs for leading organizations
- ▹Breadth of exposure across banking, manufacturing, healthcare, retail and public sector clients within a single year
- ▹Room to set direction and grow as a trusted advisor
- ▹A team of over 150 cybersecurity experts in Poland and thousands across the globe
- ▹A wide catalogue of development opportunities: technical, soft-skills and language training, e-learning platforms, GenAI training, security certifications
- ▹Flexible work location: a mix of remote work, onsite at a client or in an Accenture office
About the company
Accenture Security's cyber security team helps organizations build resilient, scalable security capabilities and integrate security into software development, cloud adoption and digital transformation. Accenture has about 791,000 people in more than 120 countries.
Languages: Angol: professzionális szint (kötelező), Lengyel: professzionális szint (kötelező)
Similar jobs

Job
· Senior
Staff Security Engineer
RTB House
AI/MLArgocdCpp
+9
💰 Salary: not specified
🌍 Remote
🗣️ EN
Himalayas

Job
· Senior
Product Security Engineer
Aras Corporation
Azure DevopsBicep
+7
💰 Salary: not specified
🌍 Remote
🗣️ EN
Himalayas

Job
· Senior
Information Security Architect
Unit4
Bicep
+5
266,882–284,974 zł/yr
gross
🌍 Remote
🗣️ EN
Himalayas
Job
· Senior
Cloud Security Engineer (Team Lead)
ProwlerPro, Inc.
AI/ML
+5
💰 Salary: not specified
🌍 Remote
🗣️ EN
Himalayas

Job
· Senior
Senior Security Analyst
abby-care
AI/ML
+3
💰 Salary: not specified
🔀 Hybrid
San Francisco
🗣️ EN

Job
· Senior
Senior Application Delivery & Edge Security Engineer (Remote)
Wipro
+4
$80,000–$158,000/yr
gross
🌍 Remote
Minneapolis
🗣️ EN