Senior Java Developer with strong Application Security Focus m/f/d, ŁÓDŹ

Which technology & skills are important for us? 👌



  • High knowledge of Secure coding, vulnerability identification


    and application security

  • High knowledge of Java programming and scripting

  • High knowledge of Strong code analysis and reverse-


    engineering skills

  • High knowledge of Impact and risk assessment of code changes

  • Good knowledge of Spring, Spring Boot

  • Good knowledge of Problem - solving and analytical thinking.

📢 Join our team as a Senior Java Developer with Strong Application Security Focus (m/f/d)!📢


The Senior Java Developer with strong Application Security Focus is a security-minded senior developer role, rather than a generic Java developer position. The role requires deep hands-on Java development experience and the ability to understand complex Java-based applications, but its primary purpose is to take ownership of application security topics and vulnerability remediation within the development context. The position is not intended to directly develop new code or make code changes.


The candidate will review existing application code, analyze security findings and potential defects, assess vulnerabilities based on severity, exploitability, business impact, and remediation urgency, and provide expert guidance on robust remediation approaches. This includes knowledge of AI-supported code analysis methods as well as application security tooling such as SAST, DAST, dependency scanning, and vulnerability management solutions. A core responsibility is to own and coordinate application security topics for the development team, drive vulnerability remediation follow-up, and support developers with experience-based recommendations while the actual implementation remains with the development teams.


By combining senior development expertise with a strong security mindset, the role helps safeguard the integrity, confidentiality, and availability of applications, strengthens secure development practices, and ensures that vulnerability remediation is understood, prioritized, tracked, and technically guided. The role acts as an advisory and review function as well as the technical interface to central security teams, for example the Cyber Hygiene team, translating centralrequirements into practical development guidance and providing technical feedback from the application teams.

  • What we offer? 🥳

    Of course, we offer Development Plans for employees, Life insurance, flexible working hours, integration events and much more 😎

  • Below you can find more information about Commerzbank 👇


Commerzbank is a leading international commercial bank with branches and offices in almost 50 countries. The world is changing, becoming digital, and so we are. We are leaving the traditional bank behind us and are choosing to move forward as a digital enterprise. This is exactly why we need talented people who will join us on this journey. We work in inter-locational and international teamwork in agile methodologies.


🚩 Please add the following clause to your application:


1. I consent to the processing of personal data contained in this document by Commerzbank Aktiengesellschaft with its registered office in Kaiserstrasse 16, 60311 Frankfurt am Main, Germany, operating through the Branch in Poland with its registered office in Łódź, 91-203 Łódź, ul. Wersalska 6, KRS 0000631053, for the implementation of the current recruitment process and for the future recruitment for a period of 6 months, in accordance with the Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data the free flow of such data and the repeal of Directive 95/46 / EC (RODO) and in accordance with the Act of 10 May 2018 on the protection of personal data (Journal of Laws of 2018, item 1000). I provided my personal data voluntarily and I declare that they are truthful. I have the right to withdraw this consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.


2. I have read the content of the information clause, including information about the purpose and methods of processing personal data and the right to access my personal data and about the right to correct, rectify and delete it.

,[Analyze static code, SAST/DAST results and dependency-scanning findings for security threats, Assess vulnerabilities based on severity, exploitability, business impact and remediation urgency, Support and track remediation activities together with Dev and Ops teams without directly implementing code changes, Act as technical counterpart for central teams in the context of Cyber / IT security., Define and promote secure coding standards for Java/Spring applications, Support continuous improvement of Secure SDLC practices and bank-wide application security standards.] Requirements: Security, Java, Spring, Boot Additionally: Sport subscription, Training budget, Private healthcare, Lunch card, International projects, E-learning platform (mindtools), Free coffee, Bike parking, Shower, Modern office, No dress code.
Data publikacji: 2026-07-30
APLIKUJ