Application Security Manager Product & AI Security

Grant Thornton Global Delivery Center Poland POZNAŃ 2026-10-02
  • 8+ years of experience in Cybersecurity, Application Security, Product Security, Information Security or a related field.
  • Strong hands-on experience in Application Security / Product Security and Secure SDLC practices.
  • Experience with SAST, DAST and SCA tools, including Veracode or a comparable application security platform.
  • Experience integrating application security testing into CI/CD pipelines and DevSecOps processes.
  • Strong understanding of application vulnerabilities, vulnerability triage, remediation, risk prioritization and exception management.
  • Experience conducting application security risk assessments, security architecture reviews and application design reviews.
  • Knowledge of OWASP standards, particularly OWASP ASVS, and ability to apply them in product and application security assessments.
  • Experience working directly with Product, Engineering, DevOps and Architecture teams across the software lifecycle.
  • Experience conducting third-party / SaaS security assessments and reviewing vendor security evidence.
  • Strong understanding of modern application, API, integration and cloud architectures.
  • Excellent stakeholder management, communication and influencing skills, with the ability to translate technical risks into clear business recommendations
  • Fluency in English and Polish.

Preferred Qualifications

  • Experience with AI security assessments, AI governance, AI risk management or agentic AI security.
  • Experience with threat modeling, API security, application security architecture and application risk assessment.
  • Knowledge of cloud security across Azure, AWS or GCP environments.
  • Experience with tools such as Checkmarx, Fortify, Snyk, SonarQube or other equivalent SAST/DAST/SCA platforms.
  • Understanding of third-party security evidence and frameworks, including SOC 1, SOC 2, ISO 27001, Trust Center reviews and vendor security questionnaires.
  • Experience supporting M&A integration, application onboarding or security integration of acquired technology environments.
  • Ability to build scalable processes, metrics, dashboards and reporting for application security leadership and governance forums.
  • Leadership, mentoring and ownership mindset, with the ability to influence teams without relying solely on authority.

Education & Certifications

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering or a related discipline.
  • Preferred certifications: CISSP, CSSLP, CISM, OSCP / OSWE, CEH, GIAC certifications, Azure / AWS / GCP Security certifications or AI Security / AI Risk certifications.

We are looking for an experienced Application Security Manager to lead application, product and AI security initiatives across the organization. In this role, you will embed security into the software development lifecycle, manage application security testing capabilities, support DevSecOps adoption, assess risks related to third-party products and AI-enabled solutions, and partner closely with Product, Engineering, DevOps, Architecture, AI, TPRM and Security teams.

What we offer:

  • Hybrid working model (2 days in the office and 3 days working remotely)
  • Stable employment with an employment contract, private medical care, and a benefits package including MultiSport and a benefits platform
  • Opportunity to work in an international environment and collaborate with experienced Grant Thornton experts and professionals from around the world
  • A culture based on teamwork, trust, and knowledge sharing
  • A well-structured onboarding program to support a smooth start and successful integration into your new role
  • Clear career development paths and access to learning and certification programs
  • Access to training platforms and tools that support professional growth
  • An inclusive workplace that welcomes people with disabilities
  • A modern office in Poznań, located in Malta Office Park

Why join Grant Thornton Global Delivery Center Poland

At Grant Thornton Global Delivery Center Poland (GDC), you’ll contribute to meaningful work that moves businesses forward. From day one, you’ll help deliver value for clients while helping shape the future of a growing delivery center in Poland.

Through supporting operations of our growing multinational platform, you’ll have opportunities to tackle complex projects, work with advanced technologies and develop new skills while expanding your experience. You’ll collaborate across countries, markets and time zones, learning from different perspectives and building experience beyond their roles.

At GDC Poland, you’ll be part of a team that succeeds together. Knowledge is shared, diverse perspectives are valued, and team members support one another in doing their best work.

Clear career paths, learning opportunities and international exposure will help you continue building your skills, expanding your capabilities and growing a rewarding career.

About Grant Thornton

Grant Thornton provides audit and assurance, tax and advisory services through the member firms of the Grant Thornton International Ltd (GTIL) network. Wherever business operates, the network is there, with member firm capabilities in more than 150 markets worldwide.

Within the network, the Grant Thornton Advisors multinational platform is a group of firms that connects priority markets and operates with aligned standards, technology and delivery expectations. For work that crosses borders, this helps support collaboration and coordination across markets. Platform firms operate as separate legal entities.

Why choose a career with Grant Thornton

At Grant Thornton, we help ambitious organizations make their most important decisions across audit, tax and advisory. Our scale doesn’t create distance. You work in smaller teams, with senior people who stay involved from start to finish. You take on real work early, help shape it and see it through.

You get access to capabilities across disciplines, clients in almost every industry and colleagues around the world who are only a message away.

Build a career with meaningful work, multinational opportunities and the support to make a lasting impact.

Join our team!

We are searching for IT professionals across multiple specialties and experience levels. Click on the arrow to see current job offers.

,[Own and manage application security processes and platforms, including Veracode or comparable SAST/DAST/SCA tools, application onboarding, scan configuration, reporting and operational support., Integrate security testing into CI/CD pipelines and promote Secure SDLC and DevSecOps practices across Product and Engineering teams., Review, triage and prioritize application security findings, define remediation guidance and track vulnerabilities through closure., Conduct application security risk assessments, architecture/design reviews and security reviews of APIs, integrations, data flows and controls., Assess AI-enabled applications, AI use cases and agentic AI solutions, identifying security risks, control gaps and mitigation actions., Support AI Security Review Committee activities by reviewing proposed AI use cases and providing risk-based security recommendations., Conduct third-party SaaS and technology product security assessments in cooperation with TPRM, procurement, business and vendor stakeholders., Support cybersecurity integration of newly acquired or onboarded applications, including application security onboarding and remediation tracking., Develop and maintain application security standards, processes, runbooks, metrics, dashboards and leadership-level reporting., Communicate security risks and practical recommendations clearly to technical, business and executive stakeholders.] Requirements: Cybersecurity, Security, SDLC, SAST, DAST, Testing, CD pipelines, OWASP, DevOps, SaaS, API, Cloud, Stakeholder management, AI, risk management, Cloud security, Azure, AWS, GCP, SonarQube, ISO, Degree, CISSP, CISM, OSCP, OSWE, GIAC Additionally: Sport subscription, Private healthcare, Training budget, Free coffee, Bike parking, Mobile phone, In-house trainings, Modern office.