Wybierz usługę po lewej lub skontaktuj się z nami mailowo!
What you'll be responsible for:
We are looking for an experienced Application Security Manager to lead application, product and AI security initiatives across the organization. In this role, you will embed security into the software development lifecycle, manage application security testing capabilities, support DevSecOps adoption, assess risks related to third-party products and AI-enabled solutions, and partner closely with Product, Engineering, DevOps, Architecture, AI, TPRM and Security teams.
Key Responsibilities
-
Own and manage application security processes and platforms, including Veracode or comparable SAST/DAST/SCA tools, application onboarding, scan configuration, reporting and operational support.
-
Integrate security testing into CI/CD pipelines and promote Secure SDLC and DevSecOps practices across Product and Engineering teams.
-
Review, triage and prioritize application security findings, define remediation guidance and track vulnerabilities through closure.
-
Conduct application security risk assessments, architecture/design reviews and security reviews of APIs, integrations, data flows and controls.
-
Assess AI-enabled applications, AI use cases and agentic AI solutions, identifying security risks, control gaps and mitigation actions.
-
Support AI Security Review Committee activities by reviewing proposed AI use cases and providing risk-based security recommendations.
-
Conduct third-party SaaS and technology product security assessments in cooperation with TPRM, procurement, business and vendor stakeholders.
-
Support cybersecurity integration of newly acquired or onboarded applications, including application security onboarding and remediation tracking.
-
Develop and maintain application security standards, processes, runbooks, metrics, dashboards and leadership-level reporting.
-
Communicate security risks and practical recommendations clearly to technical, business and executive stakeholders.
Our expectations:
Required Qualifications
-
8+ years of experience in Cybersecurity, Application Security, Product Security, Information Security or a related field.
-
Strong hands-on experience in Application Security / Product Security and Secure SDLC practices.
-
Experience with SAST, DAST and SCA tools, including Veracode or a comparable application security platform.
-
Experience integrating application security testing into CI/CD pipelines and DevSecOps processes.
-
Strong understanding of application vulnerabilities, vulnerability triage, remediation, risk prioritization and exception management.
-
Experience conducting application security risk assessments, security architecture reviews and application design reviews.
-
Knowledge of OWASP standards, particularly OWASP ASVS, and ability to apply them in product and application security assessments.
-
Experience working directly with Product, Engineering, DevOps and Architecture teams across the software lifecycle.
-
Experience conducting third-party / SaaS security assessments and reviewing vendor security evidence.
-
Strong understanding of modern application, API, integration and cloud architectures.
-
Excellent stakeholder management, communication and influencing skills, with the ability to translate technical risks into clear business recommendations
- Fluency in English and Polish.
Preferred Qualifications
-
Experience with AI security assessments, AI governance, AI risk management or agentic AI security.
-
Experience with threat modeling, API security, application security architecture and application risk assessment.
-
Knowledge of cloud security across Azure, AWS or GCP environments.
-
Experience with tools such as Checkmarx, Fortify, Snyk, SonarQube or other equivalent SAST/DAST/SCA platforms.
-
Understanding of third-party security evidence and frameworks, including SOC 1, SOC 2, ISO 27001, Trust Center reviews and vendor security questionnaires.
-
Experience supporting M&A integration, application onboarding or security integration of acquired technology environments.
-
Ability to build scalable processes, metrics, dashboards and reporting for application security leadership and governance forums.
-
Leadership, mentoring and ownership mindset, with the ability to influence teams without relying solely on authority.
Education & Certifications
-
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering or a related discipline.
-
Preferred certifications: CISSP, CSSLP, CISM, OSCP / OSWE, CEH, GIAC certifications, Azure / AWS / GCP Security certifications or AI Security / AI Risk certifications.
What we offer:
- Hybrid working model (2 days in the office and 3 days working remotely)
- Stable employment with an employment contract, private medical care, and a benefits package including MultiSport and a benefits platform
- Opportunity to work in an international environment and collaborate with experienced Grant Thornton experts and professionals from around the world
- A culture based on teamwork, trust, and knowledge sharing
- A well-structured onboarding program to support a smooth start and successful integration into your new role
- Clear career development paths and access to learning and certification programs
- Access to training platforms and tools that support professional growth
- An inclusive workplace that welcomes people with disabilities
- A modern office in Poznań, located in Malta Office Park
Jak przebiega rekrutacja?
-
Wybierz interesującą Cię ofertęZnajdź stanowisko, które Cię interesuje, na liście poszukiwanych przez nas profili:
-
ZaaplikujWyślij swoje CV w języku polskim w odpowiedzi na interesującą Cię ofertę.
-
Daj się poznać!Jeżeli pasujesz do profilu osoby, której poszukujemy, zaprosimy Cię na spotkanie online. W rozmowie weźmie udział rekruter oraz Twój przyszły menedżer. Porozmawiamy o Twoich dotyczasowych doświadczeniach i obecnej sytuacji zawodowej, a także o aspiracjach na przyszłość. Spodziewaj się pytań z obszarów merytorycznych, a jeśli stanowisko tego wymaga – to również krótkiej rozmowy po angielsku.
-
Wypatruj odpowiedziJeśli wszystko poszło dobrze, otrzymasz od nas ofertę współpracy. Jeśli nie – powiemy, co miało wpływ na naszą decyzję.
-
Witamy na pokładzie!Ustalimy dogodny dla obu stron termin i formę rozpoczęcia współpracy.
-
Is it possible to work remotely?We work in a hybrid model that combines the flexibility of remote work with the benefits of in-person collaboration. Regular presence in our Poznań office is important to us, typically 2-3 days per week. For more details about the working model, feel free to ask during the recruitment process.
-
What is the dress code at Grant Thornton?We ask that you follow specific guidelines depending on the business situation. When working independently—and provided there are no scheduled meetings with clients or business partners—a casual dress code applies; you can wear whatever is comfortable, such as a T-shirt, jeans, or a casual shirt. After all, hardly anyone sits at home in a suit and tie or a formal business suit unless they have to. However, if meetings are scheduled, your attire should be more formal and appropriate for the client. You will certainly receive detailed information about these guidelines before you start at GT, so you know what to expect.
-
Will I always receive feedback after a job interview?We always get back to candidates with feedback—regardless of the recruitment outcome—within a maximum of two weeks following the interview. This contact may be via phone or email. We also inform candidates if the recruitment process takes longer than expected. We strive to ensure our candidates always know the current status of their application.
-
What are the possible forms of cooperation?We offer employment based on a contract of employment (Umowa o Pracę). Details regarding the employment terms are discussed during the recruitment process.