Application Security Tooling Engineer III

4 tygodni temu


Warsaw, Polska myGwork Pełny etat
Job Description

This role is with Box, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.

What is Box?

Box is the world's leading Content Cloud. We are trusted by more than 115K organizations around the world today, including nearly 70% of the Fortune 500 and leaders across deeply regulated industries (such as AstraZeneca, JLL, and Nationwide), to protect their data, fuel collaboration, and power critical workflows with secure, enterprise AI.

By joining Box, you will have the unique opportunity to continue driving our platform forward. Content powers how we work. It's the billions of files and information flowing across teams, departments, and key business processes every single day: contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our mission is to bring intelligence to the world of content management and empower our customers to completely transform workflows across their organizations.

With the combination of AI and enterprise content, the opportunity has never been greater to transform how the world works together and at Box you will be on the front lines of this massive shift.

Why Box Needs You

Box is looking for an application security engineer with a good grounding in application security, penetration testing, and familiar with SAST, DAST and SCA tools. This person will detect and analyze vulnerabilities, optimize and automate testing solutions, and devise mitigation strategies.

Key Responsibilities

  1. Build and maintain CI/CD secure tooling and support other security tools as well as automate tools and processes (SAST, DAST, SCA)
  2. Provide vulnerability risk and remediation analysis
  3. Penetration testing
  4. Optimizing vulnerability detection tools
  5. Grow your AppSec skills to widen your responsibilities
  6. Define how we establish, grow, and expand our partnerships with Box engineering organizations
  7. Contribute to the development of Secure Design Patterns
  8. Conduct Bug Bounty issue evaluation, reproduction, and recommendations
  9. Help develop and deliver Security Education and Training - prepare materials and communication through diverse parts of the organization
  10. Plan and perform penetration testing
  11. Test application code with the OWASP Testing Methodology

Requirements

  • 3+ years previous experience in Application security /red team/DevSecOps with a strong focus on security tool onboarding and/or optimization
  • Knowledge of OWASP Top 10, Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), and Threat Modeling
  • Experience with security testing tools, software vulnerability management, including thorough vulnerability risk analysis and mitigation plans
  • Familiarity with multiple languages such as Java, React, Node JS, PHP, Scala, C and/or Python
  • Understanding of how to detect and prioritize Front End, API's, Microservices and Container vulnerabilities
  • Familiar with common build/automation tooling: ex. Jenkins, GIT
  • You understand application security fundamentals, OWASP vulnerabilities and their mitigations
  • You understand secure engineering best practices, can articulate problem statements and propose solutions to both technically savvy and non-technical audiences
  • You are either a passionate security minded devsecops/software engineer/devops who has been a part of building high quality applications and services
  • You have a growth mindset, push yourself towards excellence and focus on continuous functional improvements
  • You are a curious person who looks at problem statements and can clearly propose actionable solutions
  • You have a passion for cyber security demonstrated through participation/leadership in conferences, webinars, Capture the Flag (CTF), TryHackMe, HacktheBox, Bug Bounty, Submission of CVEs and/or personal projects
  • Good understanding of past, current, and emerging security exploits

Equal Opportunity

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation. For details on how we protect your information when you apply, please see our Personnel Privacy Notice.For more details on how Box Poland protects your information, please see our Supplemental Personnel and Candidate Privacy Notice. #LI-KS2



  • Warsaw, Polska myGwork Pełny etat

    This job is with Box, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. WHAT IS BOX? Box is the world's leading Content Cloud. We are trusted by more than 115K organizations around the world today, including nearly 70% of the Fortune 500 and leaders...


  • Warsaw, Polska Box Pełny etat

    WHAT IS BOX?Box is the world’s leading Content Cloud. We are trusted by more than 115K organizations around the world today, including nearly 70% of the Fortune 500 and leaders across deeply regulated industries (such as AstraZeneca, JLL, and Nationwide), to protect their data, fuel collaboration, and power critical workflows with secure, enterprise AI.By...

  • Security Tooling Engineer II

    6 miesięcy temu


    Warsaw, Polska Box Pełny etat

    WHAT IS BOX?Box is the world’s leading Content Cloud. We are trusted by more than 115K organizations around the world today, including nearly 70% of the Fortune 500 and leaders across deeply regulated industries (such as AstraZeneca, JLL, and Nationwide), to protect their data, fuel collaboration, and power critical workflows with secure, enterprise AI.By...


  • Warsaw, Polska Sportradar Pełny etat

    Job DescriptionSenior Cloud Application Security EngineerLocation: Warsaw (Hybrid) or Anywhere from Poland (Remote)Sportradar is the leading global provider of sports data and entertainment products and services. Since 2001, we have occupied a unique position at the intersection of the sports, media and betting industries; providing sports federations, news...


  • Warsaw, Polska Sportradar Pełny etat

    Job DescriptionSenior Cloud Application Security EngineerLocation: Warsaw (Hybrid) or Anywhere from Poland (Remote)Sportradar is the leading global provider of sports data and entertainment products and services. Since 2001, we have occupied a unique position at the intersection of the sports, media and betting industries; providing sports federations, news...


  • Warsaw, Polska Goldman Sachs Pełny etat

    Business Unit Overview Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our...


  • Warsaw, Polska Sportradar Polska Sp. z o.o. Pełny etat

    technologies-expected : Java .NET Python JavaScript AWS Kubernetes Protobuf gRPC GraphQL MySQL Kafka technologies-optional : Google Cloud Platform about-project : The Senior Cloud Application Security Development professional will be part of the Secure Software Development team within Product Security, dedicated to fixing identified application-level...

  • Product Security Engineer

    4 tygodni temu


    Warsaw, Polska myGwork Pełny etat

    This job is with Warner Bros. Discovery, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. Welcome to Warner Bros. Discovery... the stuff dreams are made of. Who We Are... When we say, "the stuff dreams are made of," we're not just referring to the...


  • Warsaw, Polska Sportradar Pełny etat

    Job DescriptionJoin Our Team as a Senior Security Engineer at Sportradar! Are you ready to elevate your career in one of the fastest-growing sectors in the digital sports environment? At Sportradar, we provide a platform for you to gain international recognition for your expertise while working alongside industry leaders. This is more than just a job –...

  • Security Engineer

    1 miesiąc temu


    Warsaw, Polska HIRELY Pełny etat

    Spółkę HIRELY tworzą profesjonaliści, którzy posiadają wiele lat doświadczenia w takich obszarach jak: IT, BI, zarządzanie projektami i przedsiębiorstwami. Cechuje nas wysoka jakość i efektywność realizowanych projektów poprzez właściwe dopasowanie kandydata do profilu poszukiwanego stanowiska i kultury organizacyjnej panującej w...


  • Warsaw, Polska Robert Bosch Sp. z o.o. Pełny etat

    Job Title: Senior Network Security EngineerRobert Bosch Sp. z o.o. is seeking a highly skilled Senior Network Security Engineer to join our team.Job Summary:We are looking for a seasoned Network Security Engineer to implement and operate solutions that meet our internal customers' needs. The ideal candidate will have a strong background in network...

  • Security Engineer

    2 miesięcy temu


    Warsaw, Polska The Stepstone Group Pełny etat

    Job Description Your responsibilities CI/CD Integration:  Develop and integrate security tools into our CI/CD pipelines to automate security testing, code analysis, and vulnerability scanning throughout the development lifecycle. Threat Modeling Automation:  Create and maintain automated threat modeling processes to identify and assess potential...


  • Warsaw, Polska Deloitte Pełny etat

    Description & Requirements Who we are looking for We are looking for a candidate experienced with Security & GRC, dedicated to develop further in these areas and use his/her experience to advise our clients. The candidate will play a key role in handling client engagements, as well as utilizing strong technical experience to find solutions that best...

  • Cloud Security Engineer

    2 tygodni temu


    Warsaw, Polska Fusion Consulting Pełny etat

    Job DescriptionSecurity / Cloud Security EngineerWe are looking for a dedicated Security / Cloud Security Engineer to safeguard our cloud and on-premise infrastructures, ensuring they meet top-tier security standards and comply with regulatory and company policies. This role involves implementing security best practices across both environments, managing...


  • Warsaw, Polska Sportradar Pełny etat

    Job DescriptionOVERVIEW: The Security Engineering squad is a group of security engineers with the clear mission to enable IT Security and Information Security processes by internally providing specialized services. The squad acts as an internal service provider supporting both security focused teams and other business units. As Subject Matter Experts...


  • Warsaw, Polska Robert Bosch Sp. z o.o. Pełny etat

    technologies-expected : Python Ansible Git responsibilities : Senior Network Security Engineer responsible for implementing and operating solutions to meet our internal customers needs Responsible for operations and optimization of Bosch''s worldwide Loadbalancer, Secure Web gateway(Proxy) and Web Application Firewall Infrastructure Be a part of a strategic...


  • Warsaw, Polska Sportradar Pełny etat

    Job DescriptionOVERVIEW: The Security Engineering squad is a group of security engineers with the clear mission to enable IT Security and Information Security processes by internally providing specialized services. The squad acts as an internal service provider supporting both security focused teams and other business units. As Subject Matter Experts...

  • Global IT Security Engineer

    4 miesięcy temu


    Warsaw, Polska GOLDMAN RECRUITMENT Pełny etat

    For our client global manufacturing company we are looking for candidates for a position of Global IT Security Engineer.Responsibilities:develop and maintain a comprehensive IT security strategy that aligns with organizational goals,conduct security assessments and audits, identify vulnerabilities, and prioritize remediation based on potential business...


  • Warsaw, Polska SIX Pełny etat

    What You Will Do Security Tool Engineering: Design, deploy, configure, and maintain cybersecurity tools including EDR, SOAR, TIP, and sandbox environments to enhance our security operations. This includes the engineering, deployment, and configuration of the SOAR platform, ensuring its seamless integration with other security tools and systems. Threat...


  • Warsaw, Polska PAYBACK Pełny etat

    As 2nd Level Application Support Engineer you will work in an international environment with development colleagues to ensure Application availability for PAYBACK Italy, Austria and Poland. Your responsibilities: Application support Engineer 2nd Level working in DevOps model. Good verbal and written communication skills. Good...