Application Security Tooling Engineer III

3 tygodni temu


Warsaw, Polska Box Pełny etat
WHAT IS BOX?Box is the market leader for Cloud Content Management. Our mission is to power how the world works together. Box is partnering with enterprise organizations to accelerate their digital transformation by creating a single platform for secure content management, collaboration and workflow. We have an amazing opportunity to further establish ourselves as leaders in the space, and we need strong advocates to help us achieve that goal. By joining Box, you will have the unique opportunity to help capture a majority of this developing market and define what content management looks like for the digital enterprise. Today, Box powers 100,000+ businesses, including many top Fortune 500 companies who trust our secure collaboration platform to manage the entire content lifecycle. WHY BOX NEEDS YOU

Box is looking for an engineer who has worked to onboard and optimize SAST, DAST and SCA tools. This engineer understands the various automated scanning methodologies and can build scanning tools, when needed. This person will onboard, optimize and automate testing solutions that scale the verification of security vulnerabilities with high quality output.

We’re looking for someone who can optimize output from security scanning tools to reduce false positives to enable high quality actionable vulnerability outputs.

WHAT YOU'LL DO Propose and implement data-driven enhancement strategies for dynamic (DAST), static (SAST), open source application security testing (SCA), API security scanning and container security scanning including troubleshooting, and continuous process improvementProvide vulnerability risk and remediation analysisImplement automation of software security vulnerability verification across the development processes and toolsBuild security scripting tools for solutions not available as a part of existing toolset WHO YOU ARE

3+ years previous experience in DevSecOps with a strong focus on security tool onboarding and/or optimization

Experience with security testing tools and devops integrations

Knowledge of OWASP Top 10, Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), and Threat Modeling tools

Experience with software vulnerability management, including thorough vulnerability risk analysis and mitigation plans

Familiarity with multiple languages such as Java, React, Node JS, PHP, Scala, C and/or Python

Understanding of how to detect and prioritize Front End, API's, Microservices and Container vulnerabilities

Familiar with common build/automation tooling: ex. Jenkins, GIT

You understand secure engineering best practices, can articulate problem statements and propose solutions to both technically savvy and non-technical audiences

You are either a passionate security minded devsecops/software engineer/devops who has been a part of building high quality applications and services

You have worked on onboarding and/or maintaining SAST, DAST and SCA tools

You have a growth mindset, push yourself towards excellence and focus on continuous functional improvements

You are a curious person who looks at problem statements and can clearly propose actionable solutions

You have a passion for cyber security demonstrated through participation/leadership in conferences, webinars, Capture the Flag (CTF), TryHackMe, HacktheBox, Bug Bounty, Submission of CVEs and/or personal projects

Strong understanding of past, current, and emerging security exploits

Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 2 days per week, with a focus on Tuesdays and Thursdays. Your Recruiter will share more about how we work and company culture during the hiring process.

EQUAL OPPORTUNITYWe are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation. For details on how we protect your information when you apply, please see our .For more details on how Box Poland protects your information, please see our . #LI-KS2

  • Warsaw, Polska Box Pełny etat

    WHAT IS BOX?Box is the market leader for Cloud Content Management. Our mission is to power how the world works together. Box is partnering with enterprise organizations to accelerate their digital transformation by creating a single platform for secure content management, collaboration and workflow. We have an amazing opportunity to further establish...


  • Warsaw, Polska PROVIDENT Polska Pełny etat

    responsibilities : Define and update IT security requirements (policies, standards, baselines), in particular in the area of application and cloud security. Define and support implementation of application security strategy taking into account cloud operating model and shift-left security. Develop and support implementation of cloud security strategy,...


  • Warsaw, Polska Goldman Sachs Pełny etat

    Business Unit Overview Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our...

  • DevOps Security Engineer

    4 tygodni temu


    Warsaw, Polska ING Pełny etat

    DevOps Security Engineer We are looking for you, if you have: Experience in security monitoring use cases development and hands-on experience with security technologies such as SIEM, endpoint or network security monitoring detection tooling, Strong security analytics or threat hunting skills, Experience with an enterprise SIEM solutions...


  • Warsaw, Polska Mindbox S.A. Pełny etat

    technologies-expected : AWS Google Cloud Platform Terraform Kubernetes about-project : We’re looking for a Cloud security engineer to join our Client's growing Technology team. Working within the security team you’ll play a key part in securing their cloud native IaaS and PaaS services. They have services across both AWS and GCP responsibilities...

  • Cloud Engineer

    4 tygodni temu


    Warsaw, Polska Ingersoll Rand Pełny etat

    about-project : The Cloud Engineer brings a blend of technical skills and leadership ability, with the communication and teamwork skills to collaborate with other members of the IT team. This experienced and passionate Azure cloud engineer will be responsible for modernizing and consolidating IT infrastructure, automate workloads, and pursue next-generation...

  • Cloud Engineer

    1 tydzień temu


    Warsaw, Polska Ingersoll Rand Pełny etat

    Operating system, Windows About the project, The Cloud Engineer brings a blend of technical skills and leadership ability, with the communication and teamwork skills to collaborate with other members of the IT team. This experienced and passionate Azure cloud engineer will be responsible for modernizing and consolidating IT infrastructure, automate...


  • Warsaw, Polska Snowflake Pełny etat

    Build the future of data. Join the Snowflake team. As a member of the , you’ll be responsible for maintaining (and raising) the security bar across our production cloud environments. We are looking for motivated, passionate experts in cloud security architecture and operations who can help us maintain highly defensible cloud infrastructure, and follow...


  • Warsaw, Polska Snowflake Pełny etat

    Build the future of data. Join the Snowflake team.As a member of the Cloud Security Assurance team, you’ll be responsible for maintaining (and raising) the security bar across our production cloud environments. We are looking for motivated, passionate experts in cloud security architecture and operations who can help us maintain highly defensible cloud...


  • Warsaw, Polska b2bnetwork Pełny etat

    Detailed description of work task to be carried outWeb Application Performance EngineerWe are seeking a talented and experienced Web Application Performance Engineer to join our team. As a Web Application Performance Engineer, you will be responsible for optimizing the performance and scalability of our Core Banking Application web module, ensuring a...

  • Security Lead Engineer

    2 tygodni temu


    Warsaw, Polska RELOUT sp. z o.o. Pełny etat

    technologies-expected : AWS Linux Docker Serverless technologies-optional : Python TypeScript Node.js about-project : We are currently looking for a Security Lead Engineer, willing to join a project for our strategic client – one of the largest manufacturing companies from Sweden, offering IoT solutions and assets management. In this role, you will be...


  • Warsaw, Polska emagine Consulting Pełny etat

    PROJECT INFORMATION: Industry: Banking Location: Tri-City / Warsaw / - hybrid model office 1 per week Remuneration: ~ PLN/H net + VAT Type of assignment: B2B contract Duration of assignment: long-term We are seeking a talented and experienced Web Application Performance Engineer to join our team. As a Web Application Performance...


  • Warsaw, Polska C.H. Robinson Pełny etat

    C.H. Robinson is seeking an to join our Warsaw office/global team. In this role, you'll lead red team exercises, fortifying our applications' security. Your expertise will integrate offensive security practices into our SDLC, identifying vulnerabilities and bolstering our digital resilience against threats. You'll embody C.H. Robinson...


  • Warsaw, Polska F5 Pełny etat

    At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.    Everything we do centers...

  • Field Service Engineer

    4 tygodni temu


    Warsaw, Polska TE Connectivity Pełny etat

    At TE, you will unleash your potential working with people from diverse backgrounds and industries to create a safer, sustainable and more connected world.  Job Overview TE Connectivity’s Field Application Engineering Teams work intimately with customers to recommend products and solutions for new and existing applications. They identify new...


  • Warsaw, Polska PAYBACK Pełny etat

    The Application Support Engineer will work in a team environment with operations and development colleagues to ensure application operations for PAYBACK Italy, Mexico, Austria and Poland. Your responsibilities: This role serves the organization in the following capacity: 2nd level operation, and closely working with development teams supporting...

  • Application Engineer

    3 tygodni temu


    Warsaw, Polska Xylem Pełny etat

    Rola: Application Engineer odpowiada za przygotowywanie analiz hydraulicznych, dobór urządzeń, przygotowywanie ofert oraz wsparcie techniczne dla klientów wewnętrznych i zewnętrznych. analiza układów pompowych oraz dobór odpowiednich urządzeń przygotowywanie ofert wsparcie techniczne dla klientów wewnętrznych i zewnętrznych ...

  • Senior ML Engineer

    4 tygodni temu


    Warsaw, Polska Daxx Pełny etat

    We are looking for ML Engineer to join Artificial Intelligence and Machine Learning team in the HEIS (Health and Essential Industry Solutions) domain, which focuses on applying cutting-edge machine learning techniques to revolutionize health and essential industry sectors. As a Machine Learning Engineer, you will collaborate with talented researchers and...


  • Warsaw, Polska Snowflake Pełny etat

    Build the future of data. Join the Snowflake team.We are actively hiring talented distributed systems developers from Europe and around the world for our European Engineering Center. Our office is located at Kasprzaka 4, in Warsaw. It is conveniently accessible by train, subway, bus, or bicycle – with a large number of restaurants, cafes, and shops...


  • Warsaw, Polska JPMorgan Chase & Co. Pełny etat

    We know that people want great value combined with an excellent experience from a bank they can trust, so we launched our digital bank, Chase, to revolutionise mobile banking with seamless journeys that our customers love. We're already trusted by millions in the US and we're quickly catching up in the United Kingdom – but how we do things here is a...