# Application Security Engineer

**Company:** [Starburst](https://hotfix.jobs/companies/starburst)
**Location:** Warsaw, Poland
**Role:** Security Engineering
**Experience:** 2+ years
**Skills:** Application Security, Owasp Top 10, Cwe, CI/CD, Git, AWS, Azure, GCP, Python, Go, Java, JavaScript, TypeScript, Ruby, Owasp Zap
**Posted:** 2026-05-19

> The Application Security Engineer will integrate security into the software development lifecycle, maintain automated security tooling, conduct code reviews and threat modeling, and support vulnerability remediation. The role requires 2–5 years of relevant experience, cloud familiarity, programming skills, and a bachelor's degree or equivalent experience.

## Job Description

## Responsibilities
- Integrate application security best practices into the development lifecycle by partnering with engineering teams and enabling automated security checks within CI/CD pipelines.
- Support and maintain application security tooling, including SAST, DAST, SCA, and secrets scanning, and help developers interpret and remediate findings.
- Conduct secure code reviews, threat modeling sessions, and application architecture assessments to identify risks and propose mitigation strategies.
- Develop and maintain security automation, guardrails, and reusable components.
- Assist in defining and improving secure coding standards and application hardening practices.
- Improve application-level logging, telemetry, and alerting to support monitoring and detection.
- Assist with incident response activities related to application vulnerabilities, including verification, triage, and remediation support.
- Stay current on emerging threats, vulnerabilities, and application and product security best practices.
- Contribute to documentation, including security requirements, guidelines, and remediation playbooks.
- Participate in internal security reviews, compliance-driven assessments, and architectural walkthroughs.
- Maintain application security tools, pipelines, and workflows.
- Collaborate with engineering and product teams to ensure secure deployment and continuous improvement of applications.

## Requirements
- Bachelor's degree in Computer Science, Engineering, MIS, or equivalent practical experience.
- 2–5 years of experience in application security, product security, software engineering with a security focus, or a related technical role.
- Strong understanding of application vulnerabilities and mitigation strategies, including OWASP Top 10 and CWE.
- Experience with CI/CD tooling, Git-based workflows, and modern development practices.
- Familiarity with cloud security concepts and hands-on experience with at least one cloud platform, such as AWS, Azure, or GCP.
- Experience with one or more programming languages, such as Python, Go, Java, JavaScript/TypeScript, or Ruby; Java and Python are preferred.
- Experience with application security tools such as OWASP ZAP, Burp Suite, SAST/DAST tools, SCA, or dependency scanning.
- Knowledge of secure coding principles, API security, authentication, authorization, and secrets management.
- Strong problem-solving skills and ability to communicate technical issues clearly to developers and cross-functional stakeholders.
- Understanding of agile development processes and experience working within engineering teams.
- Ability to travel approximately 25% for onboarding, team and department offsites, customer engagements, and other company events.

## Work Arrangement
- Based in the Warsaw office with a hybrid model and an expectation of being onsite 1–2 days per week.

## Compensation and Benefits
- Competitive pay.
- Attractive stock grants.
- Flexible paid time off.
- Competitive total rewards program and additional benefits.

## Similar jobs

- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Compliance Engineer](https://hotfix.jobs/jobs/63197ba5-a12d-497a-a0b9-91e5e7050ac1) - Retell AI - Remote - $72k – $90k/yr
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr

**Apply:** https://hotfix.jobs/jobs/dd588533-5a99-4d55-9393-5c58fe9b38b3
**Canonical:** https://hotfix.jobs/jobs/dd588533-5a99-4d55-9393-5c58fe9b38b3