← Back to list
Job · Senior

Lead Application Security/DevSecOps Engineer

Other • Senior • Remote • Full-time • Poland Poland

Build the application security program from the ground up across five products, embed a secure SDLC, integrate AppSec tooling (SAST, DAST, SCA) into CI/CD, and handle cloud security and incident response within the Product Engineering team.

Responsibilities

  • ▹Stand up and own the application security program across five products
  • ▹Define and embed a secure SDLC (shift-left)
  • ▹Select, deploy, and operationalize AppSec tooling (SAST, DAST, SCA) in CI/CD
  • ▹Implement and operationalize secrets management
  • ▹Build risk-based vulnerability management
  • ▹Lead threat modeling and security reviews
  • ▹Improve cloud security posture across AWS and Azure
  • ▹Lead technical incident response for application-layer incidents
  • ▹Build security awareness and a security-champions network

Requirements

  • ▹7+ years in application/product security, ideally standing up an AppSec program
  • ▹Strong AI knowledge and curiosity in the space
  • ▹Comfortable as a founding, hands-on, solo function under ambiguity
  • ▹Experience across Ruby on Rails, PHP/Laravel, .NET/C#, and Python
  • ▹Strong cloud security across AWS (primary) and Azure
  • ▹Deep grasp of vulnerability classes and secure coding practices
  • ▹Hands-on with AppSec tooling and DevSecOps/CI-CD integration
  • ▹Threat-modeling experience

Nice to have

  • ▹GitHub Advanced Security experience
  • ▹Experience with student data or PII-heavy regulated environments (FERPA, COPPA, GDPR)
  • ▹Managing large vulnerability backlogs

Soft skills

Excellent communication and influencing skillsSelf-direction and pragmatism under ambiguity

About the company

Faria is a leader in international education systems and services, trusted by 10,000+ schools and 4 million students across 155 countries.

Similar jobs