Application Security Engineer

Tooploox REMOTE WROCŁAW 2026-09-17

Basic qualifications

  • 5+ years of experience in application security, security engineering, or a closely related role. 
  • Experience performing threat modelling and architecture security reviews on complex, multi-component platforms. 
  • Strong knowledge of authentication and authorization patterns — OAuth, OIDC, RBAC, privileged access management. 
  • Hands-on experience validating API security and reviewing integration patterns across third-party services. 
  • Solid understanding of secrets management, credential handling, and token lifecycle best practices. 
  • Experience supporting or coordinating vulnerability scanning and penetration testing programmes. 
  • Knowledge of encryption standards and secure data handling practices across storage and transit. 
  • Familiarity with GDPR and privacy-by-design engineering requirements. 
  • Ability to produce clear remediation guidance and security acceptance documentation for engineering and delivery teams.
     

Preferred qualifications

  • Experience securing composable CMS or media platform architectures — AEM, Amplience, or similar. 
  • Background working on high-traffic, public-facing platforms where availability and security intersect. 
  • Experience with security logging and monitoring tooling — SIEM, alerting, incident response playbooks. 
  • Familiarity with third-party vendor security assessment processes. 
  • Relevant certification — CISSP, OSCP, CEH, or equivalent. 
  • Experience working within a phased, full-lifecycle delivery programme alongside engineering and architecture teams.  

We are looking for an Application Security Engineer to join a greenfield digital news platform build for a major international news brand. Security is not a pre-launch checklist here — it is an engineering requirement embedded across every phase of delivery, from architecture through launch and into multi-year support.

You'll be the security authority on a full-lifecycle engagement, validating controls across a composable CMS, video pipeline, advertising integrations, personalisation services, and public-facing APIs — on a platform designed to sustain extreme traffic during breaking-news events.

,[Define and validate application and platform security controls across all delivery phases. , Perform architecture and threat-model reviews at design stage and as the platform evolves. , Review authentication, authorization, and privileged-access controls across CMS, APIs, and integrated services. , Validate API and integration security across a composable, multi-vendor platform architecture. , Review secrets, credentials, and token-management practices across the full stack. , Support vulnerability scanning and penetration-testing activities — coordinating findings and remediation. , Validate encryption and secure data handling across storage, transit, and third-party integrations. , Review security logging, monitoring, and incident-response requirements. , Support GDPR and privacy engineering requirements throughout delivery. , Conduct third-party security assessments for integrated services and vendors. , Provide remediation guidance and produce security acceptance evidence ahead of launch.] Requirements: Security, API, Storage, GDPR, OAuth, RBAC, CMS, Testing, CISSP, OSCP Tools: Agile, Scrum. Additionally: Private healthcare, Sport subscription, International projects, Free coffee, Playroom, Shower, Free snacks, Free beverages, No dress code.