Application Security Engineer

AXA Avanssur SA Spółka Akcyjna Oddział II w Polsce WARSAW 2026-09-23
  • Strong practical knowledge of the OWASP Top 10 and common web application attack vectors.
  • Deep understanding of securing modern web applications, REST APIs, authentication and authorisation mechanisms (OAuth2, OIDC, JWT).
  • Experience implementing and managing SAST, DAST, SCA, API security and penetration testing programmes.
  • Experience automating security controls within CI/CD pipelines and software delivery processes.
  • Strong knowledge of secure software engineering practices and secure-by-design principles.
  • Experience with .NET, Angular, JavaScript/TypeScript, and modern web application architectures.
  • Ability to identify strategic security improvements rather than focusing solely on vulnerability remediation.
  • Strong stakeholder management skills, with the ability to influence development teams, architects, and security functions.
  • Highly motivated, enthusiastic, and capable of working both independently and collaboratively in a team-oriented environment.
  • Exceptional analytical and problem-solving skills, with attention to detail and a business-focused approach.
  • Strong interpersonal skills, with the ability to influence technical decisions and communicate effectively in a fast-paced environment.
  • Demonstrates creativity and resourcefulness in presenting solutions to complex security challenges

AXA IT Solutions

We are an internal software house operating within the international insurance group AXA. We provide IT solutions for the needs of AXA companies in Europe. We work in English on a daily basis, in close-knit teams, carrying out international development projects.

We are looking for an Application Security Engineer (F/M) to join our engineering team and help us build security into the software development lifecycle.
This role is an opportunity to move beyond traditional vulnerability management and drive a proactive approach to application security. You will work closely with software engineers, architects, DevOps and security teams to automate security controls, integrate security into CI/CD pipelines, improve secure development practices and help teams build secure-by-design applications.

This is how we work

  • in house
  • you have influence on the technological solutions applied
  • you have influence on the product
  • you focus on product development
  • agile
  • scrum

What we offer

  • The opportunity to influence technological solutions and product direction in an international financial organization
  • Ambitious projects with a high degree of autonomy and responsibility
  • A stable, long-term assignment with flexible working hours and a hybrid work model


,[Own and continuously improve the application security posture, embedding security throughout the SDLC., Monitor, assess, prioritise, and manage vulnerabilities from penetration testing, SAST, DAST, dependency scanning, bug bounty programmes, and other security assessments, ensuring remediation within agreed SLAs., Triage security findings, assess business risk, identify false positives, and provide clear technical justification for decisions., Design and implement scalable security controls, automation, and preventative measures to reduce recurring vulnerabilities and manual remediation., Drive a shift-left security approach by integrating automated security testing, policies, and secure development practices into CI/CD pipelines., Act as the primary liaison with external penetration testing providers and partner with Group Security on vulnerability management, risk ratings, and remediation requirements., Provide expert guidance on securing web applications, APIs, authentication, and cloud-native architectures, particularly .NET and Angular solutions., Act as the Application Security SME, promoting secure-by-default design principles across solution delivery., Maintain application security standards, policies, and processes aligned with OWASP, NIST, and industry best practices., Monitor emerging threats, OWASP trends, attack techniques, and security tooling to address evolving application security risks., Deliver secure coding guidance and security awareness to developers, technical leads, architects, and delivery teams., Report on application security posture, vulnerability trends, remediation performance, and risk reduction to governance and steering groups.] Requirements: OWASP, Web applications, REST API, SAST, DAST, API, Security, Testing, CD pipelines, .NET, Angular, JavaScript, TypeScript, Stakeholder management Tools: Agile, Scrum. Additionally: Sport subscription, Training budget, Private healthcare, Small teams, International projects, remote work opportunities, Integration events, Free coffee, Bike parking, Playroom, Free parking, No dress code, Fruits, Video games at work, Coffee / tea, Drinks, Leisure zone.