Application Security Engineer / Penetration tester
GROWE Warsaw, Masovian Voivodeship, Poland
IT Services and IT Consulting · 11-50 employees
About the role
The role involves triaging and validating security findings from automated tools and conducting manual code reviews to identify vulnerabilities. Additionally, the engineer will perform hands-on penetration testing on web applications and APIs to uncover business logic flaws.
What they look for
Requirements
Candidates must have at least 3 years of experience in application security or penetration testing and proficiency with security scanning tools. A deep understanding of OWASP vulnerabilities, identity protocols, and modern application code analysis is required.
Full description
Growe welcomes those who are excited to:
• Triage, validate, and prioritize security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation;
• Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production;
• Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws;
• Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorization, and business logic.
We need your professional experience:
• 3 years of experience in Application Security, Product Security, or Penetration Testing;
• Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner;
• Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec;
• Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialization, and Mass Assignment;
• Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures;
• Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC);
• Ability to identify complex authorization bypasses, session management flaws, and business logic bugs;
• Ability to read and analyze modern application code to spot security flaws;
• Basic understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals;
• Pragmatic approach to security, balancing risk mitigation with development workflow;
• Intermediate level of English (spoken and written).
We appreciate if you have those personal features:
• Strong communication skills to effectively collaborate with engineering, product, and DevOps teams;
• Result-oriented mindset;
• Multitasking and time management skills.
We are seeking those who align with our core values:
• GROWE TOGETHER: Our team is our main asset. We work together and support each other to achieve our common goals;
• DRIVE RESULT OVER PROCESS: We set ambitious, clear, measurable goals in line with our strategy and driving Growe to success;
• BE READY FOR CHANGE: We see challenges as opportunities to grow and evolve. We adapt today to win tomorrow.
Similar roles
-
Security Engineer
Applied Network Solutions Inc Linthicum, Maryland, United States · $100K–$200K/yr
-
Security Engineer with Akamai WAF
Syncreon Consulting New York, New York, United States
-
Cyber Security Engineer
UL Solutions Northbrook, Illinois, United States · $96K–$130K/yr
-
OT Network & Security Engineer
Vulcan Elements Research Triangle Park, North Carolina, United States
-
Senior Security Engineer, Access Security
Google New York, New York, United States · $174K–$252K/yr
-
Senior Security Engineer
Zepz United Kingdom