Application Security Engineer II

7 dni temu


Kraków, Lesser Poland Viator Pełny etat 60 000 zł - 120 000 zł rocznie

About Viator
Viator, a Tripadvisor company, is the leading marketplace for travel experiences. We believe that making memories is what travel is all about. And with 300,000+ travel experiences to explore—everything from simple tours to extreme adventures (and all the niche, interesting stuff in between)—making memories that will last a lifetime has never been easier. With industry- leading flexibility and last-minute availability, it's never too late to make any day extraordinary. Viator. One app, 300,000+ travel experiences you'll remember.

We are seeking a proactive and skilled Application Security Engineer II to join our team. In this role, you will be instrumental in identifying and mitigating security vulnerabilities, integrating security tools into our CI/CD pipelines, and educating developers on secure coding practices. You will collaborate with engineering teams to ensure our applications are secure by design and contribute to the continuous improvement of our security posture.

Responsibilities

  • Proactively identify and mitigate security vulnerabilities in collaboration with engineering teams.
  • Integrate automated security testing tools into the CI/CD pipeline.
  • Provide feedback on secure design principles for new features and systems.
  • Review and contribute to playbooks for handling security incidents.
  • Lead basic threat modeling sessions and educate developers on secure coding.
  • Perform penetration assessments to identify security weaknesses.
  • Propose and implement improvements to security operations and processes.
  • Lead moderately complex security initiatives and projects.
  • Mentor junior application security engineers and contribute to their development.
  • Build strong relationships with development teams to influence and promote security best practices.

Qualifications

  • Experience in threat modeling, focusing on common attack vectors like SQL injection and XSS.
  • Familiarity with the deployment order of AppSec tools, such as SCA, SAST, and DAST.
  • Ability to work with development teams to prioritize and manage vulnerability backlogs.
  • Understanding of the primary risks associated with open-source libraries, including outdated or vulnerable components.
  • Experience in following escalation processes for critical library vulnerabilities and assisting in their remediation.
  • Proficiency in using secret scanning tools and refining scanning rules to minimize false positives.
  • Participation in internal bug bounty programs is a plus.
  • Knowledge of the difference between Application Security and Product Security.
  • Experience in following and reviewing security development guidelines.
  • Proven ability to lead smaller projects, such as implementing SAST tools or conducting developer training.
  • Can spot most security flaws in a system, but may miss complex ones.
  • Can describe how vulnerabilities can be exploited and provide valid attack scenarios.
  • Offers reasonable mitigation strategies for identified vulnerabilities (e.g., parameterized queries for SQLi).
  • Can explain most security concepts clearly.
  • Basic knowledge of secure authentication best practices like hashed passwords and MFA.
  • Understands application-level risks and focuses on fixing specific issues.
  • Basic awareness of the secure development lifecycle (SDLC).

Perks of Working at Viator

  • Competitive compensation packages (routinely benchmarked against the latest industry data), including base salary and annual bonuses
  • "Work your way" with flexibility to suit your lifestyle. Viator takes a remote-friendly approach to collaboration across a worldwide team, with the option to join on-site as often as you'd like.
  • Flexible schedule. Work-life balance is ingrained in our culture by design. Trust and accountability make it work.
  • Donation matching. Give back? Give more We match qualifying charitable donations annually.
  • Tuition assistance. Want to level up your career? We love to hear it Receive annual support for qualified programs.
  • Lifestyle benefit. An annual benefit to spend on yourself. Use it on travel, wellness, or whatever suits you.
  • Travel perks. We believe that travel is employee development, so we provide discounts and more.
  • Employee assistance program. We're here for you with resources and programs to help you through life's challenges.
  • Health benefits. We offer great coverage and competitive premiums.

Our Values

  • We aspire to lead. Tap into your talent, ambition, and knowledge to bring us – and you – to new heights.
  • We're relentlessly curious. We push beyond the usual, the known, the "that's just how it's done."
  • We're better together. We learn from, accept, respect, support, and value one another– and are creating something remarkable in the process.
  • We serve our customers, always. We listen, question, respond, and strive for wow moments.
  • We strive for better, not perfect. We won't get it right the first time – or every time. We'll provide a safe environment in which to make mistakes, iterate, improve, and grow.
  • Our workplace is for everyone, as is our people powered platform. At Tripadvisor, we want you to bring your unique identities, abilities, and experiences, so we can collectively revolutionize travel and together find the good out there.

If you need a reasonable accommodation or support during the application or the recruiting process due to a medical condition or disability, please reach out to your individual recruiter or send an email to and let us know the nature of your request. Please include the job requisition number in your message.

Viator

  • Kraków, Lesser Poland ABB Pełny etat 40 000 zł - 80 000 zł rocznie

    W ABB pomagamy przemysłowi wyprzedzać konkurencję - działać sprawniej i ekologicznie. U nas postęp to standard – dla Ciebie, Twojego zespołu i całego świata. Jako globalny lider dajemy Ci to, czego potrzebujesz, by to osiągnąć. Nie zawsze będzie łatwo, rozwój wymaga determinacji. Ale w ABB nigdy nie będziesz działać sam. Zarządzaj tym,...


  • Kraków, Lesser Poland ABB Pełny etat 56 000 € - 100 000 € rocznie

    At ABB, we help industries outrun - leaner and cleaner. Here, progress is an expectation - for you, your team, and the world. As a global market leader, we'll give you what you need to make it happen. It won't always be easy, growing takes grit. But at ABB, you'll never run alone. Run what runs the world.This Position reports to:Software Product Development...


  • Kraków, Lesser Poland Euroclear Pełny etat

    Job DescriptionDivision: CISOThe role requires a self-motivated analyst conversant and experienced with the use of static code testing for application risk assessment. Static Application Security Testing is performed as part of the overall application testing process. The individual is required to be experienced in security of applications and how they need...

  • Application Security Intern

    1 tydzień temu


    Kraków, Lesser Poland Motorola Solutions Pełny etat 30 000 zł - 60 000 zł rocznie

    Company OverviewAt Motorola Solutions, we believe that everything starts with our people. We're a global close-knit community, united by the relentless pursuit to help keep people safer everywhere. Our critical communications, video security and command center technologies support public safety agencies and enterprises alike, enabling the coordination that's...

  • Security Engineer

    7 dni temu


    Kraków, Lesser Poland beqom Pełny etat 60 000 zł - 120 000 zł rocznie

    Join beqom - where tech meets impactbeqom is a high-growth B2B SaaS company that provides industry-leading tools for pay equity and transparency, compensation, and performance management.Trusted by some of the world's most respected companies, beqom enables HR and business leaders to navigate global compliance and make smarter pay decisions that attract,...

  • Security Engineer

    7 dni temu


    Kraków, Lesser Poland beqom Pełny etat 60 000 zł - 120 000 zł rocznie

    Join beqom - where tech meets impactbeqom is a high-growth B2B SaaS company that provides industry-leading tools for pay equity and transparency, compensation, and performance management.Trusted by some of the world's most respected companies, beqom enables HR and business leaders to navigate global compliance and make smarter pay decisions that attract,...


  • Kraków, Lesser Poland LotusFlare Pełny etat 80 000 zł - 120 000 zł rocznie

    LotusFlare is a provider of cloud-native SaaS products based in the heart of Silicon Valley. Founded by the team that helped Facebook reach over one billion users, LotusFlare was founded to make affordable mobile communications available to everyone on Earth.Today, LotusFlare focuses on designing, building, and continuously evolving a digital commerce and...


  • Kraków, Lesser Poland Usermind Pełny etat 80 000 zł - 120 000 zł rocznie

    BACK TO SEARCH RESULTSPrevious job Next jobJob DescriptionAt Qualtrics, we create software the world's best brands use to deliver exceptional frontline experiences, build high-performing teams, and design products people love. But we are more than a platform—we are the creators and stewards of the Experience Management category serving over 18K clients...


  • Kraków, Lesser Poland Qualtrics Pełny etat 80 000 zł - 120 000 zł rocznie

    At Qualtrics, we create software the world's best brands use to deliver exceptional frontline experiences, build high-performing teams, and design products people love. But we are more than a platform—we are the creators and stewards of the Experience Management category serving over 18K clients globally. Building a category takes grit, determination, and...


  • Kraków, Lesser Poland Westinghouse Electric Company Pełny etat 60 000 zł - 120 000 zł rocznie

    Are you interested in being part of an innovative team that supports Westinghouse's mission to provide clean energy solutions? At Westinghouse, we recognize that our employees are our most valuable asset and we seek to identify, attract and recruit the most qualified talent while recognizing and encouraging the value of diversity in the global workplace.A...