Application Security Manager Product & AI Security
- 8+ years of experience in Cybersecurity, Application Security, Product Security, Information Security or a related field.
- Strong hands-on experience in Application Security / Product Security and Secure SDLC practices.
- Experience with SAST, DAST and SCA tools, including Veracode or a comparable application security platform.
- Experience integrating application security testing into CI/CD pipelines and DevSecOps processes.
- Strong understanding of application vulnerabilities, vulnerability triage, remediation, risk prioritization and exception management.
- Experience conducting application security risk assessments, security architecture reviews and application design reviews.
- Knowledge of OWASP standards, particularly OWASP ASVS, and ability to apply them in product and application security assessments.
- Experience working directly with Product, Engineering, DevOps and Architecture teams across the software lifecycle.
- Experience conducting third-party / SaaS security assessments and reviewing vendor security evidence.
- Strong understanding of modern application, API, integration and cloud architectures.
- Excellent stakeholder management, communication and influencing skills, with the ability to translate technical risks into clear business recommendations
- Fluency in English and Polish.
Preferred Qualifications
- Experience with AI security assessments, AI governance, AI risk management or agentic AI security.
- Experience with threat modeling, API security, application security architecture and application risk assessment.
- Knowledge of cloud security across Azure, AWS or GCP environments.
- Experience with tools such as Checkmarx, Fortify, Snyk, SonarQube or other equivalent SAST/DAST/SCA platforms.
- Understanding of third-party security evidence and frameworks, including SOC 1, SOC 2, ISO 27001, Trust Center reviews and vendor security questionnaires.
- Experience supporting M&A integration, application onboarding or security integration of acquired technology environments.
- Ability to build scalable processes, metrics, dashboards and reporting for application security leadership and governance forums.
- Leadership, mentoring and ownership mindset, with the ability to influence teams without relying solely on authority.
Education & Certifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering or a related discipline.
- Preferred certifications: CISSP, CSSLP, CISM, OSCP / OSWE, CEH, GIAC certifications, Azure / AWS / GCP Security certifications or AI Security / AI Risk certifications.
We are looking for an experienced Application Security Manager to lead application, product and AI security initiatives across the organization. In this role, you will embed security into the software development lifecycle, manage application security testing capabilities, support DevSecOps adoption, assess risks related to third-party products and AI-enabled solutions, and partner closely with Product, Engineering, DevOps, Architecture, AI, TPRM and Security teams.
What we offer:
- Hybrid working model (2 days in the office and 3 days working remotely)
- Stable employment with an employment contract, private medical care, and a benefits package including MultiSport and a benefits platform
- Opportunity to work in an international environment and collaborate with experienced Grant Thornton experts and professionals from around the world
- A culture based on teamwork, trust, and knowledge sharing
- A well-structured onboarding program to support a smooth start and successful integration into your new role
- Clear career development paths and access to learning and certification programs
- Access to training platforms and tools that support professional growth
- An inclusive workplace that welcomes people with disabilities
- A modern office in Poznań, located in Malta Office Park
Why join Grant Thornton Capability Center Poland?
At Grant Thornton Capability Center Poland (GTCC), employees contribute to meaningful work that moves businesses forward. From day one, team members help deliver value for clients while helping shape the future of a growing delivery center in Poland.
Through supporting operations of our growing multinational platform, employees have opportunities to tackle complex projects, work with advanced technologies and develop the skills needed for what's next. Team members collaborate across countries, markets and time zones, learning from different perspectives and building experience beyond their roles.
At GTCC Poland, teammates succeed together. Knowledge is shared, diverse perspectives are valued, and employees support one another in doing their best work.
Clear career paths, learning opportunities and international exposure help employees continue building skills, expanding capabilities and growing rewarding careers.
About Global Delivery Centers (enterprise description)
Grant Thornton Capability Center (GTCC) support the operations of the Grant Thornton Advisors multinational platform.
We bring together people, technology and delivery capabilities that help teams work across markets and time zones. By supporting shared standards, technology and delivery expectations GTCC help keep work moving, connect teams across the platform and create consistency across the way work is delivered.
We are part of a multinational platform that brings together more than 25,000 professionals across 20+ firms. As organizations grow, enter new markets and face increasing complexity, our centers help provide the scale, coordination and operational support needed to keep work moving forward.
For our people, that means working with colleagues across markets, contributing to work with international reach and helping teams deliver consistently in an environment built on collaboration, accountability and quality.