# Application Security Engineer (f/m/d)

[Awin](https://gurify.com/jobs?q=Awin) · Berlin, Poland · Posted yesterday

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/awin/jobs/7988783003)

## Job description

### Purpose of Position

Your role is to establish and lead an AppSec program within the Product and Technology department, acting as an evangelist for AppSec, trusted by engineers and managers alike.

As a member of the core security team, you will engage in assessing application design proposals, to identify improvements to enable our engineers to create secure products.

You will own the existing training program, redesign it to better equip engineers with the knowledge needed to develop secure applications, and create a Security Champions program to scale and embed a DevSecOps mindset across P&T.

### What you'll be responsible for

- Secure the SDLC: Integrate security tooling (e.g. SAST, DAST, dependency scanning) into CI/CD pipelines and IDEs. Automate and optimise checks so teams can identify and fix issues early and efficiently.

- Threat modelling & secure design: Collaborate with product and engineering teams during the design phase to conduct threat modelling sessions and pre-implementation security reviews.

- Code & architecture reviews: Guide developers on secure coding practices, perform targeted code reviews, and help resolve vulnerabilities with actionable remediation support.

- Vulnerability lifecycle management:

- Identify, triage, track and report on vulnerabilities across internal and external apps and systems.

- Collaborate with engineers to close gaps efficiently.

- Support the bug bounty process with finding validation.

- Present vulnerability management reports to our heads of department.

- AI/ML & LLM security:

- Provide guidance on secure development of AI/LLM-powered features.

- Help teams manage risks such as prompt injection, model misuse, and data leakage.

- Lead threat modelling exercises for AI components and advise on secure integration patterns.

- Incident response collaboration: Support investigation and root cause analysis of application-layer incidents. Contribute to post-incident reviews and longer-term mitigation strategies.

- Security culture & enablement:

- Act as a security champion for development teams.

- Be an enthusiastic and vocal advocate for application security across all engineering and product teams.

- Nurture and report on our application security training program for our code contributors.

- Deliver workshops and technical deep-dives on secure development practices.

- Contribute to playbooks, documentation, and internal standards.

- Research & innovation:

- Stay ahead of industry threats and attack trends. Propose and test innovative ideas to reduce risk across our software supply chain and platforms.

- Showcase how to use AI and AI-powered tools to enhance productivity and improve our security posture.

### Your skills

- 5+ years in application security, product security or related technical roles.

- Experience working directly with software engineer and product managers to secure web applications.

- Experience in working within an Agile environment.

- Good working proficiency in spoken and written English.

- Excellent interpersonal skills and ability to clearly communicate at every level of the organisation.

- Mentorship and training skills.

- Ability to work across two different departments with multiple touch points.

- Coding proficiency in languages such as JS, PHP, Python.

- Experience with Cloud Native environments (AWS), Containers and Terraform.

- Hands on experience with DAST, SAST, SCA tools, reporting and dashboarding platforms.

### Our Offer

•
Flexi-Week: We prioritise your mental health and wellbeing by offering you a four-day Flexi-Week (with one lighter or completely disconnected day per week) at full pay, with no reduction to your annual holiday allowance.

•
Flexi-office: We offer an international culture and flexibility through our hybrid/remote working scheme which is designed to foster a culture of mutual trust and working flexibility.

•
Work Expense Contribution & Remote Working Furniture: You will receive a monthly allowance to cover part of your running costs, as well as a furniture package to support you in setting up a comfortable workspace when working from home.

•
Health and Wellbeing: With our support and access to various initiatives and sports offers, you can focus on your mental and physical wellbeing.

•
Development: We’ve built our extensive training suite, Awin Academy, to cover a wide range of skills that support your professional and personal growth, with trainings conveniently packaged to help your overall development.

•
Appreciation: Thank and reward colleagues by sending them a voucher through our peer-to-peer recognition programme.

We are hiring in multiple countries for this role. Additional benefits, including health and wellbeing offerings, will be discussed during the initial interview.

Established in 2000, Awin is proud of our dynamic, social and inclusive culture.

Like all businesses, we’ve had to adapt and nurture our culture in a virtual environment. Our virtual ‘Life @ Awin’ hub brings our colleagues from across the globe together for various social activities.

Diversity & Inclusion are paramount to us, and we proudly pursue and hire diverse team members. We champion uniqueness and authenticity; this is who we are at our core. Our network of affiliate partnerships are diverse and transparent, as are the employees powering our vision to build the world’s leading open partner ecosystem. We welcome all backgrounds, identities, and experiences. If you need support at any point in the application or interview process, please let us know.

Awin is part of the Axel Springer group. Learn more at axelspringer.com/en/, and explore the Axel Springer Essentials here: axelspringer.com/en/inside/the-essentials-what-we-have-adapted-and-why

Apply now to begin the next stage of your career at a progressive company that supports both your professional and personal development.

**Live in Awin’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- RT [Staff Security Engineer](https://gurify.com/job/staff-security-engineer-at-rtbhouse-14f338af67a4) Rtbhouse · Warsaw, Poland · 5 days ago
- SO [Application Security Engineer - Sonar](https://gurify.com/job/application-security-engineer-sonar-at-sonarsource-7bfd29fc9b53) Sonarsource · Austin, Texas · last week
- ON [Application Security Engineer - ONE ZERO](https://gurify.com/job/application-security-engineer-one-zero-at-onezerobank-2e8386af9bda) Onezerobank · Tel Aviv-Yafo, Israel · 2 days ago
- RT [Junior SOC Security Engineer](https://gurify.com/job/junior-soc-security-engineer-at-rtbhouse-1ca973d7c20c) Rtbhouse · Warsaw, Poland · 2 months ago
- CA [Corporate Security Engineer, AI](https://gurify.com/job/corporate-security-engineer-ai-at-capital-1a9cc64a63a7) Capital · Warsaw, Poland · 6 weeks ago
- SO [Application Security Engineer](https://gurify.com/job/application-security-engineer-at-sonarsource-a1847194c1cb) Sonarsource · Geneva · last week

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Application Security Engineer (f/m/d)","description":"\u003Ch3\u003EPurpose of Position\u003C/h3\u003E\u003Cp\u003EYour role is to establish and lead an AppSec program within the Product and Technology department, acting as an evangelist for AppSec, trusted by engineers and managers alike.\u003C/p\u003E\u003Cp\u003EAs a member of the core security team, you will engage in assessing application design proposals, to identify improvements to enable our engineers to create secure products.\u003C/p\u003E\u003Cp\u003EYou will own the existing training program, redesign it to better equip engineers with the knowledge needed to develop secure applications, and create a Security Champions program to scale and embed a DevSecOps mindset across P\u0026amp;T.\u003C/p\u003E\u003Ch3\u003EWhat you\u0026#39;ll be responsible for\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ESecure the SDLC: Integrate security tooling (e.g. SAST, DAST, dependency scanning) into CI/CD pipelines and IDEs. Automate and optimise checks so teams can identify and fix issues early and efficiently.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThreat modelling \u0026amp; secure design: Collaborate with product and engineering teams during the design phase to conduct threat modelling sessions and pre-implementation security reviews.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECode \u0026amp; architecture reviews: Guide developers on secure coding practices, perform targeted code reviews, and help resolve vulnerabilities with actionable remediation support.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EVulnerability lifecycle management:\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIdentify, triage, track and report on vulnerabilities across internal and external apps and systems.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECollaborate with engineers to close gaps efficiently.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport the bug bounty process with finding validation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPresent vulnerability management reports to our heads of department.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAI/ML \u0026amp; LLM security:\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProvide guidance on secure development of AI/LLM-powered features.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHelp teams manage risks such as prompt injection, model misuse, and data leakage.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELead threat modelling exercises for AI components and advise on secure integration patterns.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIncident response collaboration: Support investigation and root cause analysis of application-layer incidents. Contribute to post-incident reviews and longer-term mitigation strategies.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecurity culture \u0026amp; enablement:\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAct as a security champion for development teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBe an enthusiastic and vocal advocate for application security across all engineering and product teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ENurture and report on our application security training program for our code contributors.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDeliver workshops and technical deep-dives on secure development practices.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContribute to playbooks, documentation, and internal standards.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EResearch \u0026amp; innovation:\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStay ahead of industry threats and attack trends. Propose and test innovative ideas to reduce risk across our software supply chain and platforms.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EShowcase how to use AI and AI-powered tools to enhance productivity and improve our security posture.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EYour skills\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E5\u002B years in application security, product security or related technical roles.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience working directly with software engineer and product managers to secure web applications.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience in working within an Agile environment.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EGood working proficiency in spoken and written English.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExcellent interpersonal skills and ability to clearly communicate at every level of the organisation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMentorship and training skills.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to work across two different departments with multiple touch points.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECoding proficiency in languages such as JS, PHP, Python.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with Cloud Native environments (AWS), Containers and Terraform.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands on experience with DAST, SAST, SCA tools, reporting and dashboarding platforms.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EOur Offer\u003C/h3\u003E\u003Cp\u003E\u2022\u003Cbr /\u003EFlexi-Week: We prioritise your mental health and wellbeing by offering you a four-day Flexi-Week (with one lighter or completely disconnected day per week) at full pay, with no reduction to your annual holiday allowance.\u003C/p\u003E\u003Cp\u003E\u2022\u003Cbr /\u003EFlexi-office: We offer an international culture and flexibility through our hybrid/remote working scheme which is designed to foster a culture of mutual trust and working flexibility.\u003C/p\u003E\u003Cp\u003E\u2022\u003Cbr /\u003EWork Expense Contribution \u0026amp; Remote Working Furniture: You will receive a monthly allowance to cover part of your running costs, as well as a furniture package to support you in setting up a comfortable workspace when working from home.\u003C/p\u003E\u003Cp\u003E\u2022\u003Cbr /\u003EHealth and Wellbeing: With our support and access to various initiatives and sports offers, you can focus on your mental and physical wellbeing.\u003C/p\u003E\u003Cp\u003E\u2022\u003Cbr /\u003EDevelopment: We\u2019ve built our extensive training suite, Awin Academy, to cover a wide range of skills that support your professional and personal growth, with trainings conveniently packaged to help your overall development.\u003C/p\u003E\u003Cp\u003E\u2022\u003Cbr /\u003EAppreciation: Thank and reward colleagues by sending them a voucher through our peer-to-peer recognition programme.\u003C/p\u003E\u003Cp\u003EWe are hiring in multiple countries for this role. Additional benefits, including health and wellbeing offerings, will be discussed during the initial interview.\u003C/p\u003E\u003Cp\u003EEstablished in 2000, Awin is proud of our dynamic, social and inclusive culture.\u003C/p\u003E\u003Cp\u003ELike all businesses, we\u2019ve had to adapt and nurture our culture in a virtual environment. Our virtual \u2018Life @ Awin\u2019 hub brings our colleagues from across the globe together for various social activities.\u003C/p\u003E\u003Cp\u003EDiversity \u0026amp; Inclusion are paramount to us, and we proudly pursue and hire diverse team members. We champion uniqueness and authenticity; this is who we are at our core. Our network of affiliate partnerships are diverse and transparent, as are the employees powering our vision to build the world\u2019s leading open partner ecosystem. We welcome all backgrounds, identities, and experiences. If you need support at any point in the application or interview process, please let us know.\u003C/p\u003E\u003Cp\u003EAwin is part of the Axel Springer group. Learn more at axelspringer.com/en/, and explore the Axel Springer Essentials here: axelspringer.com/en/inside/the-essentials-what-we-have-adapted-and-why\u003C/p\u003E\u003Cp\u003EApply now to begin the next stage of your career at a progressive company that supports both your professional and personal development.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"application-security-engineer-f-m-d-at-awin-fb24719a88c0"},"url":"https://gurify.com/job/application-security-engineer-f-m-d-at-awin-fb24719a88c0","datePosted":"2026-09-08","validThrough":"2026-10-24T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Awin","sameAs":"https://job-boards.greenhouse.io/awin"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"PL","addressLocality":"Berlin"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Poland","item":"https://gurify.com/jobs/poland"},{"@type":"ListItem","position":3,"name":"Application Security Engineer (f/m/d)","item":"https://gurify.com/job/application-security-engineer-f-m-d-at-awin-fb24719a88c0"}]}
```
