Application Security Engineer

Toyota Digital HUB & SSC (TME NV/SA) WROCŁAW 2026-09-23

Qualifications

  • Relevant experience in Application Security, Penetration Testing, Secure Software Development, or a closely related area
  • Experience working in large and/or complex environments with a range of stakeholders
  • Experience as a developer, architect, security engineer, or in another relevant background with exposure to the software development lifecycle

We welcome candidates from non-traditional career paths and those with transferable skills or equivalent practical experience. If you meet many of the requirements but not every single one, we still encourage you to apply. We value potential, curiosity, and a willingness to learn alongside technical experience.

Core Technical Skills

  • Good understanding of application security vulnerabilities and remediation techniques
  • Experience performing threat modelling with development teams
  • Practical programming experience in at least one language
  • Ability to help integrate and scale security testing within CI/CD pipelines

Communication & Leadership Skills

  • Ability to explain complex technical concepts clearly to a range of audiences
  • Ability to build strong working relationships and positively influence stakeholders across different teams
  • Collaborative mindset with an interest in coaching, mentoring, continuous learning, and helping others succeed

Desirable Skills

  • Familiarity with frameworks such as SAMM, BSIMM, NIST SSDF
  • Knowledge of:
  • Cloud security (AWS, Azure, GCP)
  • Container and Kubernetes security

Certifications (Optional)

  • CSSLP, OSCP, or equivalent security certifications

You have a TOYOTA DNA, this means:

  • Courage: you are ready to let go of the easy path to reach challenging targets.
  • Collaboration: you are a team player, respectful and inclusive in your style, and you take a customer-oriented approach.
  • Creativity: your passion drives you to explore innovative ideas and challenge the impossible.
  • Curiosity: you combine imagination and fact-based observation.
  • Coaching: you share knowledge and feedback with your colleagues and celebrate each other’s success.

Team description:

The Cybersecurity team is a strategic function within TME’s IT & Digital division, supporting the transformation of Toyota’s European IT operations. Joining this team means contributing to resilient security frameworks, helping manage cyber risks in a modern enterprise environment, and playing a visible role in building a proactive security culture across digital assets and operations. The team’s mission is to protect Toyota’s information assets, support regulatory compliance, and enable secure innovation across the organization.

Role Summary:

We are looking for an Application Security Engineer who is excited to help shape and strengthen secure software development practices across a complex enterprise environment.

In this role, you will work closely with development teams to embed security by design, promote a shift-leftsecurity approach, and support secure development practices at scale. You will lead threat modelling activities, help teams strengthen secure coding practices, and contribute to the evolution of application security capabilities across the organization. This is a strong opportunity for someone who enjoys combining technical depth, collaboration, and practical impact.

Formal Role Details:

  • Job Type: Permanent contract
  • Start date: From October 2026
  • Location: Wrocław, Silver Tower Office Center
  • Working Pattern: Hybrid – typically 2 to 3 days per week in the office, offering flexibility alongside collaboration with the team
  • Reporting line: Manager Application security
  • Education level: Master’s degree or equivalent relevant experience

What we can offer you:

  • Health insurance
  • Sport card
  • Lunch subsidy
  • Car leasing
  • Languages lessons
  • Bonuses
,[Integrate security practices into development pipelines, including SAST/DAST and CI/CD security controls , Promote secure-by-design principles and “shift-left” engineering practices across teams , Conduct threat modelling for applications and projects, defining mitigation strategies and security requirements , Support teams in identifying and remediating vulnerabilities effectively , Act as a trusted application security partner for development teams and projects , Translate complex technical risks into clear, actionable guidance for technical and non-technical stakeholders , Help grow a Security Champions community and strengthen security awareness across engineering teams , Support and coach engineers in strengthening secure coding practices and shared ownership of security , Collaborate with security experts and cross-functional teams to share best practices and standardise approaches , Contribute to documentation, guidelines, and reusable security assets , Measure and improve application security maturity (e.g., using models such as SAMM) , Provide regular reporting on security posture, risks, and improvement actions ] Requirements: CI/CD, Cloud, Kubernetes Additionally: Sport subscription, Training budget, Private healthcare, Lunch card, Retirement savings scheme (PPK), Car leasing options, Annual or Quarterly bonus, Employee Recommendation Programm, Mindfulness and Stress Management Programme, No dress code, Modern office.