Junior Application Security Engineer

Toyota Digital HUB & SSC (TME NV/SA) WROCŁAW 2026-09-23

Qualifications

  • Experience can be gained through work, internships, academic projects, community involvement, self-directed learning, or personal projects in Application Security, Secure Software Development, Software Engineering, or a related area
  • Understanding of the software development lifecycle and interest in secure development practices, with the expectation to continue learning on the job
  • Relevant knowledge may come from development, engineering, computer science, cybersecurity, or other comparable technical backgrounds

We welcome candidates from a wide range of backgrounds, including non-traditional career paths, career returners, internships, academic projects, self-directed learning, and transferable technical experience. If you are excited about application security and meet many of the requirements, we still encourage you to apply. We value potential, curiosity, a growth mindset, and the different perspectives people bring to the team.

Core Technical Skills

  • Awareness of common application security vulnerabilities and interest in learning how to identify and address them
  • Awareness of threat modelling concepts and interest in learning how to apply them in practice
  • Experience with programming can come from academic work, bootcamps, personal projects, internships, or professional roles
  • Exposure to secure development practices, code review, or security testing through coursework, projects, internships, or early professional experience is helpful

Communication & Collaboration Skills

  • Ability to explain technical concepts clearly and willingness to learn from feedback
  • Collaborative mindset and ability to work effectively with developers, security colleagues, and other stakeholders
  • Strong curiosity, constructive and collaborative approach, and motivation to develop technical and professional skills

Desirable Skills

  • Awareness of frameworks such as OWASP SAMM, BSIMM, or NIST SSDF is helpful but not required
  • Exposure to cloud platforms, containers, or Kubernetes security through study, labs, projects, or practical experience is beneficial

Certifications (Optional)

  • Entry-level or foundational certifications such as Security+, ISC2 CC, or equivalent can be an advantage, but they are not required

You have a TOYOTA DNA, this means:

  • Courage: you are ready to let go of the easy path to reach challenging targets.
  • Collaboration: you are a team player, respectful and inclusive in your style, and you take a customer-oriented approach.
  • Creativity: your passion drives you to explore innovative ideas and challenge the impossible.
  • Curiosity: you combine imagination and fact-based observation.
  • Coaching: you share knowledge and feedback with your colleagues and celebrate each other’s success.

Team description:

The Cybersecurity team plays a key role in supporting Toyota’s digital transformation across Europe. By joining the team, you will help strengthen security in a modern enterprise environment, contribute to protecting critical digital assets, and support secure innovation across the business. We are committed to creating a collaborative, respectful, and inclusive environment where people with different backgrounds, experiences, and perspectives can thrive, learn, and grow.

Role Summary:

We are looking for a Junior Application Security Engineer who is passionate about technology, eager to learn, and excited to build a career in secure software development and application security within a supportive and inclusive enterprise environment.

In this role, you will work closely with development and security teams to help embed secure-by-design practices into the software development lifecycle. You will gain hands-on exposure to areas such as threat modelling, vulnerability remediation, secure coding, and application security tooling, while learning from experienced colleagues in a supportive team environment. This position offers an excellent opportunity for someone who is curious, collaborative, and motivated to grow into a capable application security professional.

Formal Role Details:

  • Job Type: Permanent contract
  • Start date: From October 2026
  • Location: Wrocław, Silver Tower Office Center
  • Working Pattern: Hybrid – typically 2 to 3 days per week in the office, offering flexibility alongside collaboration with the team
  • Reporting line: Manager Application security
  • Education level: Degree in a relevant field or equivalent practical experience
,[Support the integration of security practices into development pipelines, including SAST/DAST and CI/CD security controls , Help promote secure-by-design principles and shift-left engineering practices across teams , Assist in threat modelling activities for applications and projects, helping document risks and mitigation actions , Support teams in identifying, tracking, and remediating vulnerabilities , Partner with developers and project teams to provide practical application security support , Help translate technical security findings into clear and actionable guidance , Contribute to security awareness and secure coding initiatives within engineering teams , Learn from and collaborate with security experts and cross-functional teams to share best practices , Support the creation and maintenance of documentation, guidelines, and reusable security assets , Contribute to tracking application security improvements and reporting activities ] Requirements: CI/CD Additionally: Sport subscription, Training budget, Private healthcare, Lunch card, Annual or Quarterly bonus, Mindfulness and Stress Management Programme, Employee Recommendation Programm, Car leasing options, No dress code, Modern office, Retirement savings scheme (PPK).