PepsiCo

Senior Application Security Engineer

PepsiCo Warsaw, Masovian Voivodeship, Poland

Food and Beverage Services · 10,001+ employees

Yesterday
security Mid (2-5 yrs) Full-time Poland
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The engineer will configure, operate, and tune application security tools while integrating them into developer workflows and CI/CD pipelines. They are also responsible for triaging security findings, performing manual security reviews, and developing backend automation to manage vulnerability data.

What they look for

Application Security SAST DAST SCA API Security Python Go CI/CD Vulnerability Management OWASP Top 10 Security Automation Burp Suite REST APIs Cloud Security Container Security Identity and Access Management

Requirements

Candidates must have a bachelor's degree in a technical field and 3-5 years of professional experience in application security or secure software development. Strong proficiency in Python or Go, experience with security scanning tools, and a deep understanding of web and API vulnerabilities are required.

Full description

Overview

PepsiCo’s Global Application Security Program integrates security into software development at enterprise scale. Our mission is to make application security risks visible, actionable, and measurable so they can be remediated efficiently.

Approximately 80% of this role focuses on web application and API security. The engineer will configure, tune, validate, and operate security tools such as SAST/SCA/Secret/DAST scanners; manually triage findings; perform targeted security reviews; integrate scanning into developer workflows through custom development; and manage results through centralized findings-management processes.

The engineer will also support the development and operation of backend automation that initiates scans, monitors scan status, ingests and normalizes results, manages failures and retries, and routes findings into enterprise vulnerability-management workflows.

The remaining capacity may support mobile application security tooling and integrations as needed. Working knowledge of mobile security reviews and relevant tooling is preferred but not required. This may include supporting backend automation and CI/CD integrations.

Responsibilities

Responsibilities

  • Configure, tune, administer, and maintain SAST/SCA/Secret/DAST and API scanning security tools.
  • Manually triage security findings, reproduce representative issues, determine exploitability, identify false positives, assess business impact, and provide actionable remediation guidance.
  • Perform targeted manual security reviews of web applications and APIs, including authentication, authorization, session management, input validation, data exposure, business logic, and access-control testing.
  • Develop, test, tune, and maintain SAST rules, policies, rule packs, severity mappings, exclusions, and quality gates aligned with organizational standards.
  • Configure and optimize DAST scanning profiles, authentication workflows, crawl settings, scan scopes, schedules, policies, and integrations to improve coverage and finding quality.
  • Integrate security scanning into source-control, pull-request, build, CI/CD, release, ticketing, and developer workflows using reusable pipeline components, APIs, webhooks, and automation.
  • Develop and support backend automated scanning systems that onboard applications, initiate scans, track scan state, manage queues and retries, ingest results, normalize findings, and route data to downstream systems.
  • Integrate findings into centralized application-security, vulnerability-management, or ASPM platforms, including normalization, correlation, deduplication, enrichment, ownership mapping, suppression, exception handling, and state synchronization.
  • Establish risk-based prioritization and remediation workflows that account for exploitability, application exposure, data sensitivity, asset criticality, compensating controls, and business impact.
  • Partner with developers, product teams, DevOps engineers, platform owners, and security stakeholders to resolve findings, improve developer experience, and implement practical security guardrails.
  • Monitor scanner and integration health, including scan success rates, job queues, runners, connectivity, authentication, timeouts, capacity, licensing, logs, and service reliability.
  • Evaluate emerging application-security tools and capabilities through proofs of concept, comparative testing, technical scorecards, detection-quality analysis, integration assessment, and operational-fit reviews.
  • Develop and maintain security-testing standards, integration patterns, technical documentation, onboarding guides, operational runbooks, troubleshooting procedures, and developer-facing remediation guidance.
  • Develop metrics and KPIs for application onboarding, scan coverage, workflow adoption, scan success, execution time, finding quality, false-positive rates, remediation performance, and platform reliability.
  • As needed, support mobile application-security tooling and integrations, including limited finding triage and backend automation for initiating scans, processing results, and integrating into CI/CD pipelines.
  • Participate in Agile development activities and an appropriate platform-support or on-call rotation, including weekends and holidays where required.

Qualifications

Years of Experience

  • Bachelor’s degree in Computer Science, Engineering, or a related technical field, with 3-5 years of relevant professional experience in application security, security engineering, secure software development, or vulnerability management.

Mandatory Technical Skills

  • Hands-on experience configuring, tuning, administering, or integrating application-security tools across enterprise development environments.
  • Experience configuring and tuning SAST/SCA/Secrets platforms, including policies, rules, rule packs, exclusions, severity mappings, quality gates, and CI/CD integrations.
  • Experience configuring and operating DAST platforms, including authenticated scanning, crawl configuration, scan policies, scheduling, scope management, and finding validation.
  • Experience manually triaging SAST/SCA/Secrets/DAST and API-security findings, reproducing representative issues, identifying false positives, assessing exploitability, and providing remediation guidance.
  • Experience performing targeted web application and API security reviews using tools such as Burp Suite, Postman, curl, browser developer tools, or comparable technologies.
  • Strong understanding of the OWASP Top 10 and common web vulnerabilities, including injection, cross-site scripting, broken access control, authentication weaknesses, SSRF, insecure deserialization, security misconfiguration, and sensitive-data exposure.
  • Strong understanding of the OWASP API Security Top 10, including BOLA/IDOR, broken authentication, authorization failures, unrestricted resource consumption, mass assignment, inventory-management weaknesses, and unsafe API consumption.
  • Understanding of API authentication and authorization technologies, including OAuth 2.0, OpenID Connect, JWT, API keys, service accounts, role-based access control, and session management.
  • Experience reviewing application code written in one or more languages such as Java, JavaScript, TypeScript, Python, Go, C#, or comparable enterprise-development languages.
  • Proficiency with Python and/or Go for security automation, API integrations, data processing, scan orchestration, custom validation, and backend service development.
  • Experience building or supporting backend automation using REST APIs, webhooks, workers, queues, databases, schedulers, retries, timeouts, rate limits, and asynchronous job-processing patterns.
  • Experience integrating security tools into CI/CD platforms such as GitHub Actions, GitLab CI/CD, Azure DevOps, Jenkins, CircleCI, or equivalent technologies.
  • Experience with centralized findings-management, ASPM, or vulnerability-management platforms, including finding ingestion, normalization, correlation, deduplication, ownership routing, lifecycle tracking, exception management, and reporting.
  • Experience managing finding state across multiple tools and systems, including remediation status, suppression decisions, risk acceptance, reopen logic, SLA tracking, and bidirectional synchronization.
  • Experience with SAST, DAST, SCA, secrets detection, API security, SBOM, container security, and related software supply-chain controls.
  • Experience operating and troubleshooting security tooling, including platform upgrades, authentication, connectivity, runner capacity, job queues, scan failures, timeouts, logs, access controls, licensing, and data retention.
  • Experience with cloud and container platforms such as AWS, Azure, GCP, Docker, or Kubernetes used to host, scale, or integrate security tooling.
  • Understanding of secure credential handling, service-to-service authentication, role-based access control, encryption, certificate management, audit logging, and data protection for security platforms.
  • Familiarity with databases, structured data formats, and integration technologies such as SQL, JSON, SARIF, REST APIs, event streams, or message queues.
  • Experience creating technical documentation, integration patterns, onboarding guides, operational runbooks, troubleshooting procedures, and developer-facing remediation guidance.

Non-technical Skills

  • Strong written and verbal communication skills.
  • High integrity with sound judgment and accountability.
  • Excellent analytical, problem-solving, and critical thinking abilities.
  • Self-motivated, curious, and committed to continuous learning, including willingness to skill up in mobile application security.
  • Strong collaboration, relationship-building, and influencing skills.
  • Comfortable working in a fast-paced, global environment with changing priorities and ambiguity.
  • Ability to perform effectively under pressure.

Differentiating Behaviors

  • Demonstrates curiosity, innovation, and a continuous improvement mindset, including a willingness to develop mobile application security expertise.
  • Makes sound decisions by balancing technical, business, and operational trade-offs.
  • Remains calm, organized, and methodical in high-pressure situations.
  • Effectively prioritizes work and manages competing commitments.

Similar roles