# Application Security Engineer

[Starburst](https://gurify.com/jobs?q=Starburst) · Warsaw, Poland · Posted 7 months ago

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/starburst/jobs/5119301008)

## Job description

### About Starburst

Starburst delivers enterprise intelligence at scale by giving organizations secure, governed access to all their data, wherever it lives. Built for distributed data environments, Starburst helps enterprises power AI and analytics without the cost and complexity of traditional data consolidation. With open standards including Trino and Apache Iceberg, Starburst enables trusted access to complete enterprise context while helping organizations avoid vendor lock-in. Leading global enterprises trust Starburst to fuel AI, analytics, and enterprise intelligence. Learn more at starburst.ai.

### About the Role:

As a Security Engineer focused on Application and Product Security, you will play a key role in improving the security posture of our applications, services, and development ecosystem. You will work closely with engineering teams to integrate security into the software development lifecycle, build secure-by-default patterns, and ensure that products are resilient against modern threats. This role combines hands-on technical work, security engineering, and collaboration with developers to guide secure design and remediation. You will help implement security controls, perform assessments, and contribute to the continuous improvement of our security program.

### As an Application Security Engineer at Starburst you will:

- Integrate application security best practices into the development lifecycle by partnering with engineering teams and enabling automated security checks within CI/CD pipelines.

- Support and maintain Application Security based tooling—including SAST, DAST, SCA, and secrets scanning—and help developers interpret and remediate findings.

- Conduct secure code reviews, threat modeling sessions, and application architecture assessments to identify risks and propose mitigation strategies.

- Develop and maintain security automation, guardrails, and reusable components.

- Assist in defining and improving secure coding standards and application hardening practices.

- Support monitoring and detection efforts by helping improve application-level logging, telemetry, and alerting.

- Assist in incident response activities related to application vulnerabilities, including verification, triage, and remediation support.

- Stay current on emerging threats, vulnerabilities, and best practices in application and product security.

- Contribute to documentation including security requirements, guidelines, and remediation playbooks.

- Participate in internal security reviews, compliance-driven assessments, and architectural walkthroughs.

- Develop and help maintain existing application security tools, pipelines, and workflows.

- Collaborate with engineering and product teams to ensure secure deployment and continuous improvement of applications.

### Some of the things we look for:

- Bachelor’s degree in Computer Science, Engineering, MIS, or equivalent practical experience.

- 2–5 years of experience in application security, product security, software engineering with a security focus, or a related technical role.

- Strong understanding of application vulnerabilities and mitigation strategies (OWASP Top 10, CWE).

- Experience with CI/CD tooling, Git-based workflows, and modern development practices.

- Familiarity with cloud security concepts and hands-on experience with at least one cloud platform (AWS, Azure, or GCP).

- Experience with one or more programming languages such as Python, Go, Java, JavaScript/Typescript, or Ruby. (Java and Python preferred.)

- Experience with application security tools such as OWASP ZAP, Burp Suite, SAST/DAST tools, SCA, or dependency scanning.

- Knowledge of secure coding principles, API security, authentication, authorization, and secrets management.

- Strong problem-solving skills and the ability to communicate technical issues clearly to developers and cross-functional stakeholders.

- Understanding of agile development processes and working within engineering teams.

- Ability to Travel: This role will require 25% in-person travel for purposes including but not limited to new hire onboarding, team and department offsites, customer engagements, and other company events. Actual travel expectations may vary by role and business needs.

### Where could this role be based?

This role is based in our Warsaw office and follows a hybrid model, with an expectation of being onsite 1-2 days per week.

### Build your career at Starburst

All-Stars have the opportunity and freedom to realize their true potential. By building alongside top talent, we’re empowered to take ownership of our careers and drive meaningful change. Anchored in industry-proven technology and unprecedented success, All-Stars are taking on the challenge everyday to disrupt our industry – and the future.

Our global workforce is supported by a competitive Total Rewards program that reflects our commitment to a rewarding and supportive work environment. This includes a variety of benefits like competitive pay, attractive stock grants, flexible paid time off, and more.

We are committed to fostering an intentional, inclusive, and diverse culture that drives deep engagement, authentic belonging, and an exceptional All-Star experience. We believe that diversity of thought, perspective, background and experience will enable us to own what we do, drive our success and empower our All-Stars to show up authentically.

Starburst provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state
or local laws.

**Live in Starburst’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- AW [Application Security Engineer (f/m/d)](https://gurify.com/job/application-security-engineer-f-m-d-at-awin-fb24719a88c0) Awin · Berlin, Poland · last week
- TA [Cloud Security Engineer](https://gurify.com/job/cloud-security-engineer-at-tango-f1269c61ab1e) Tango · Warszawa, Poland · last week
- RT [Staff Security Engineer](https://gurify.com/job/staff-security-engineer-at-rtbhouse-14f338af67a4) Rtbhouse · Warsaw, Poland · 2 weeks ago
- OS [Senior Backend Engineer , Experience Edge](https://gurify.com/job/senior-backend-engineer-experience-edge-at-ox-security-2e6f8a5753c0) Ox Security · Poland · 3 days ago
- OS [Vibesec](https://gurify.com/job/vibesec-at-ox-security-742020ab9eef) Ox Security · Poland · 4 days ago
- TR [Senior Application Security Engineer](https://gurify.com/job/senior-application-security-engineer-at-tripadvisor-e6adf974d3c7) Tripadvisor · Oxford, London · last week

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Application Security Engineer","description":"\u003Ch3\u003EAbout Starburst\u003C/h3\u003E\u003Cp\u003EStarburst delivers enterprise intelligence at scale by giving organizations secure, governed access to all their data, wherever it lives. Built for distributed data environments, Starburst helps enterprises power AI and analytics without the cost and complexity of traditional data consolidation. With open standards including Trino and Apache Iceberg, Starburst enables trusted access to complete enterprise context while helping organizations avoid vendor lock-in. Leading global enterprises trust Starburst to fuel AI, analytics, and enterprise intelligence. Learn more at starburst.ai.\u003C/p\u003E\u003Ch3\u003EAbout the Role:\u003C/h3\u003E\u003Cp\u003EAs a Security Engineer focused on Application and Product Security, you will play a key role in improving the security posture of our applications, services, and development ecosystem. You will work closely with engineering teams to integrate security into the software development lifecycle, build secure-by-default patterns, and ensure that products are resilient against modern threats. This role combines hands-on technical work, security engineering, and collaboration with developers to guide secure design and remediation. You will help implement security controls, perform assessments, and contribute to the continuous improvement of our security program.\u003C/p\u003E\u003Ch3\u003EAs an Application Security Engineer at Starburst you will:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EIntegrate application security best practices into the development lifecycle by partnering with engineering teams and enabling automated security checks within CI/CD pipelines.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport and maintain Application Security based tooling\u2014including SAST, DAST, SCA, and secrets scanning\u2014and help developers interpret and remediate findings.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EConduct secure code reviews, threat modeling sessions, and application architecture assessments to identify risks and propose mitigation strategies.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDevelop and maintain security automation, guardrails, and reusable components.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAssist in defining and improving secure coding standards and application hardening practices.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport monitoring and detection efforts by helping improve application-level logging, telemetry, and alerting.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAssist in incident response activities related to application vulnerabilities, including verification, triage, and remediation support.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStay current on emerging threats, vulnerabilities, and best practices in application and product security.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContribute to documentation including security requirements, guidelines, and remediation playbooks.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EParticipate in internal security reviews, compliance-driven assessments, and architectural walkthroughs.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDevelop and help maintain existing application security tools, pipelines, and workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECollaborate with engineering and product teams to ensure secure deployment and continuous improvement of applications.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ESome of the things we look for:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EBachelor\u2019s degree in Computer Science, Engineering, MIS, or equivalent practical experience.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E2\u20135 years of experience in application security, product security, software engineering with a security focus, or a related technical role.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong understanding of application vulnerabilities and mitigation strategies (OWASP Top 10, CWE).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with CI/CD tooling, Git-based workflows, and modern development practices.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with cloud security concepts and hands-on experience with at least one cloud platform (AWS, Azure, or GCP).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with one or more programming languages such as Python, Go, Java, JavaScript/Typescript, or Ruby. (Java and Python preferred.)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with application security tools such as OWASP ZAP, Burp Suite, SAST/DAST tools, SCA, or dependency scanning.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EKnowledge of secure coding principles, API security, authentication, authorization, and secrets management.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong problem-solving skills and the ability to communicate technical issues clearly to developers and cross-functional stakeholders.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnderstanding of agile development processes and working within engineering teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to Travel: This role will require 25% in-person travel for purposes including but not limited to new hire onboarding, team and department offsites, customer engagements, and other company events. Actual travel expectations may vary by role and business needs.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhere could this role be based?\u003C/h3\u003E\u003Cp\u003EThis role is based in our Warsaw office and follows a hybrid model, with an expectation of being onsite 1-2 days per week.\u003C/p\u003E\u003Ch3\u003EBuild your career at Starburst\u003C/h3\u003E\u003Cp\u003EAll-Stars have the opportunity and freedom to realize their true potential. By building alongside top talent, we\u2019re empowered to take ownership of our careers and drive meaningful change. Anchored in industry-proven technology and unprecedented success, All-Stars are taking on the challenge everyday to disrupt our industry \u2013 and the future.\u003C/p\u003E\u003Cp\u003EOur global workforce is supported by a competitive Total Rewards program that reflects our commitment to a rewarding and supportive work environment. This includes a variety of benefits like competitive pay, attractive stock grants, flexible paid time off, and more.\u003C/p\u003E\u003Cp\u003EWe are committed to fostering an intentional, inclusive, and diverse culture that drives deep engagement, authentic belonging, and an exceptional All-Star experience. We believe that diversity of thought, perspective, background and experience will enable us to own what we do, drive our success and empower our All-Stars to show up authentically.\u003C/p\u003E\u003Cp\u003EStarburst provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state\u003Cbr /\u003Eor local laws.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"application-security-engineer-at-starburst-a6d6d2b47246"},"url":"https://gurify.com/job/application-security-engineer-at-starburst-a6d6d2b47246","datePosted":"2026-02-17","validThrough":"2026-11-04T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Starburst","sameAs":"https://job-boards.greenhouse.io/starburst"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"PL","addressLocality":"Warsaw"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Poland","item":"https://gurify.com/jobs/poland"},{"@type":"ListItem","position":3,"name":"Application Security Engineer","item":"https://gurify.com/job/application-security-engineer-at-starburst-a6d6d2b47246"}]}
```
