Hiring.Camp

Application Security Specialist (regular/senior) (She/He/They)

Accenture

·

Today

Location
Warsaw, Sienna 39, Poland · Lodz · Krakow · Wroclaw · Katowice
Workplace
Remote
Type
Full-time
Department
Security
Seniority
Senior
Source
Workday

Description

WHO WE ARE:

The Cyber Security team, part of Accenture Security, supports organizations in building secure, resilient, and scalable security capabilities across complex enterprise technology landscapes — integrating security into software development, cloud adoption, digital transformation, and technology modernization so that security by design and security by default are reflected in how systems are actually built and operated, not only in policy. 

We act as trusted advisors to some of the world's leading organizations, helping them define pragmatic security operating models, improve security maturity, and align cybersecurity capabilities with their business and technology objectives. Working at the forefront of the industry means constant exposure to complex, high-stakes security challenges and the latest technologies — across banking, manufacturing, healthcare, retail, and public sector, each with its own regulatory context and technical scale. 

As part of a global security leader, you work on engagements that span the full breadth of modern enterprise security — from securing AI-enabled systems and cloud-native architectures to embedding security into large-scale digital transformation programmed. The variety of clients, industries, and technology stacks means you are continuously challenged, and the depth of expertise around you means you are never navigating that alone.

THE WORK:

  • Assess where a client actually stands — against OWASP ASVS, OWASP Top 10, OWASP API Top 10, or CWE Top 25 — and turn the gaps into a prioritized roadmap their teams can work through. 

  • Run threat modelling and secure design reviews with the client’s own architects and developers, across hybrid, distributed, cloud-native, containerized, microservices, event-driven, and monolithic systems. 

  • Review code, APIs, Infrastructure as Code, and CI/CD pipelines from a security point of view — then help the teams fix what you find rather than just reporting it. That extends to building security into pipelines, build systems, and artefact repositories, and to software supply chain risk: dependencies, build integrity, SBOMs, third-party components. 

  • Select, roll out, and tune AppSec tooling — SAST, DAST, SCA, secrets scanning — so that results are trusted and acted on rather than muted, and so security gates and automated testing hold up across the SSDLC. 

  • Work on the security of AI-enabled systems: LLM-based applications, AI agents, model and data pipelines, and the risks that come with them — prompt injection, data poisoning, model and inference exposure, unsafe integration. That includes defining controls across the AI lifecycle, using AI-based tooling for code analysis and vulnerability triage, and supporting governance and compliance around responsible AI use. 

  • Make it stick with the client’s people: secure coding standards and design guidance teams will actually use, guardrails for how developers use AI coding assistants, a security champions program, hands-on developer training, and presenting findings and recommendations from team leads up to CISO level. 

Flexible: The work location for this role may include a mix of working remotely, onsite at a client or in an Accenture office - depending on specific project circumstances. 

With all our roles, there is some in-person time for collaboration, learning and building relationships with clients, peers, leaders, and communities. As an employer, we will be as flexible as possible to support your specific work/life needs. 

WHAT’S IN IT FOR YOU: 

  • Work on international cybersecurity transformation programs for some of the world's leading organizations, on security problems that are genuinely complex and unsolved at their end. 

  • Breadth you cannot get in-house. In a single year you see how organizations across banking, manufacturing, healthcare, retail, and public sector approach the same challenges — and where they fail. That range, across Secure SDLC, Application Security, Cloud Security, Security Governance, and Enterprise Architecture, takes far longer to accumulate on a single internal team. 

  • Constant exposure to emerging technologies, current tooling, and evolving practice — helping clients securely adopt what is new while managing risk across legacy, hybrid, and modern environments. 

  • Room to set direction and grow as a trusted advisor. On most engagements you are the person defining what good looks like for a client — leading security discussions with technical, operational, and senior stakeholders, not implementing someone else's definition. 

  • Collaborate with a diverse team of over 150 cybersecurity experts in Poland and thousands across the globe, in an environment focused on innovation, continuous learning, and practical business outcomes. 

  • A wide catalogue of development opportunities: technical, soft-skills, and language training, e-learning platforms, GenAI training, and security certifications — open to everyone who wants to grow. 

HERE’S WHAT YOU’LL NEED:
 

We are looking for candidates with a solid foundation across the areas below. Hands-on experience and a working grasp of the core concepts is the baseline — specialization and depth can be developed from there.

  • Engineering or IT background. A background in software development, architecture, or IT operations — with practical experience building, running, or designing software systems or infrastructure. 

  • Foundational security knowledge. A sound understanding of core security principles — confidentiality, integrity, and availability — and how they apply to real systems. Familiarity with encryption, hashing, and key management at a conceptual and practical level, including common misuse patterns. 

  • Understanding of the software development lifecycle. Sufficient knowledge of how software is specified, built, reviewed, tested, released, and maintained to engage credibly with development and engineering teams. 

  • Familiarity with DevOps and CI/CD pipelines. Hands-on experience with at least one platform — GitHub, GitLab, Azure DevOps, Bitbucket, Jenkins, or equivalent — with an understanding of build processes and pipeline configuration. 

  • Experience with at least one public cloud platform. Practical, hands-on experience with AWS, Azure, or GCP, including their core services and security controls. 

  • Ability to read code and identify common security vulnerabilities. Capability to identify and clearly articulate issues such as SQL injection, XSS, command injection, and CSRF within a codebase, in any one language — Java, C#/.NET, JavaScript, Go, Python, or equivalent. 

  • Language requirements. Professional proficiency in both English and Polish is required. English is the primary language for client-facing work — including findings communication, workshop facilitation, and presentations to senior stakeholders up to CISO level. Polish is the language of day-to-day team operations. Proficiency in both is a non-negotiable requirement for this role. 

  • Ways of working. Strong communication skills, including the ability to translate complex technical findings into clear, actionable recommendations for non-technical audiences. A proactive, ownership-oriented mindset — with the ability to define and drive security improvements independently within a client environment. Adaptability and a commitment to continuous learning, given the pace of change in the security landscape. 

Seniority levels 

Regular (approximately 2–5 years of relevant experience). Candidates at this level are expected to independently deliver defined workstreams — including threat modelling sessions, pipeline and IaC reviews, and findings reporting to client technical teams. A working knowledge of the OWASP Top 10 and secure coding principles is expected, with continued development across the broader requirements list. 

Senior (approximately 5+ years of relevant experience). Candidates at this level are expected to lead workstreams, provide technical direction, and mentor junior colleagues. This requires demonstrated depth in at least one domain — cloud security, software supply chain, AppSec tooling, secure design and threat modelling, or AI security — alongside sufficient breadth to engage credibly across all areas and present confidently to senior client stakeholders up to CISO level. 

If you are moving across from development, platform engineering, or an in-house security role, tell us what you have built and we will work out where you fit. That conversation happens in the interview, not in the CV screen.
 

Research indicates that some candidates, especially the most diverse ones, may hesitate to apply for positions if they don't meet all requirements. If you believe you possess the necessary skills, even if not meeting every requirement, we wholeheartedly encourage you to submit your application.

BONUS POINTS IF YOU HAVE:
 

Any one of these is a plus, and we value the individual experience you bring over the number of lines you tick. For a Regular role none of them is required. For a Senior role we expect real depth in at least one. 

  • Application security fundamentals in practice: OWASP Top 10, OWASP ASVS, OWASP API Top 10, CWE Top 25, secure coding best practice, and common vulnerability classes and exploitation techniques. 

  • Threat modelling experience, taking business logic, architecture, and deployment model into account. 

  • Authentication, authorization, and session management: OAuth 2.0, OpenID Connect, SAML, SSO, and modern identity-centric security models. 

  • SAST, DAST, and SCA tooling — including experience running, tuning, or fixing deployments that had lost developer trust. 

  • Securing CI/CD pipelines, Infrastructure as Code, container platforms, and software supply chain: dependency scanning, SBOM, SLSA, artefact signing. 

  • Hands-on experience with additional cloud platforms — AWS, Azure, or GCP — and their native security services. 

  • Experience with, or strong interest in, securing AI-enabled applications and LLM-based systems — including prompt injection, data poisoning, model exposure, and AI agent abuse — and defining security controls across AI pipelines. 

  • Using AI-powered security tooling for code analysis, vulnerability detection, or security automation. 

  • Governance, risk, and compliance around the secure and responsible use of AI. 

  • Prior consulting or client-facing experience. 

  • Security certifications — we care about what you can do, and we co-finance certifications once you are here.

WHAT WE OFFER:

  • Permanent employment contract.

  • Individual support of a People Lead and a specific path of professional development, as well as the possibility of a session with a Coach.

  • A wide training package (soft, technical, and language training offer, access to the e-learning platforms, Gallup test, GenAI training, possibility of co-financing courses, and certification).

  • Employee Assistance Program - legal, financial, and psychological consultations.

  • Accenture employees eligible for the Employee share purchase plan automatically become eligible for quarterly dividends if they own company shares.

  • Paid employee referral program.

  • Private medical care, life insurance.

  • Access to the Worksmile platform (possibility of using a wide range of products and services, including the Multisport card).

 

WHAT WE BELIEVE:

Accenture does not discriminate employment candidates on the basis of race, religion, color, sex, age, disability, national origin, political beliefs, trade union membership, ethnicity, denomination, sexual orientation or any other basis impermissible under Polish law.

 

All our leaders are committed to building a better, stronger and more durable company for future generations to create positive, long-lasting change. Inclusion and diversity are fundamental to our culture and core values. Our rich diversity makes us more innovative and creative, which helps us better serve our clients and our communities.

 

Our position as partner to many of the world’s leading businesses, organizations and governments affords us both an extraordinary opportunity and a tremendous responsibility to make a difference. Sustainability is one of our greatest responsibilities, which we embed it into everything we do and for everyone we work with.

 

Clicking apply I hereby express my consent to process my personal data included in my job offer by Accenture Sp. z o.o. or any other entity of the Accenture group for recruitment purposes, and that it is a data controller within the meaning of GDPR. More information about Accenture (and if necessary also its representative) can be found here: https://www.accenture.com/pl-pl/privacy-policy

#LI-EU

#PLSEC

About Accenture

Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.

Visit us at www.accenture.com 

Equal Employment Opportunity Statement

We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, sexual orientation, gender identity or expression, marital status, citizenship status or any other basis as protected by applicable law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities.

Skills

PythonJavaScriptJavaAWSAzureGCPJenkinsCI/CDSQLGitHubGitLabCybersecurityOAuthDevOpsMicroservicesComplianceGDPRGo

Similar Jobs

26

Application security specialist

Asml · Veldhoven, Building 07, Netherlands

4 weeks ago

Specialist, Application Security

Pearson · Bangalore, Karnataka, India · Hybrid

1 month ago

Application Security Specialist

Barclays · Knutsford, Radbroke Hall, United Kingdom

3 months ago

Specialist, Application Security

Pru · Wash, 213 Washington St., Newark, NJ, United States of America

1+ year ago

GRC Application Security Specialist (Contract)

Sggovterp · MAS: MAS Building, Singapore

3 days ago

Junior Application Security Specialist

Xsolla · Baku · Onsite

1 month ago

SAP Application Security Specialist

Accenturefederalservices · Washington, DC +1 · Hybrid

3 months ago

Network & Application Security Specialist

Lottomaticagroup · Roma - Via degli Aldobrandeschi, Italy

3 months ago

Senior Application Security Specialist

Swift · Kuala Lumpur, Malaysia

3 months ago

Junior Application Security Specialist

Xsolla · Baku · Onsite

4 months ago

Senior Application Security Specialist

IntouchCX · Clark Freeport, Pampanga, Philippines

4 months ago

Senior Application Security Specialist

IntouchCX · Cairo, Cairo Governorate, Egypt

4 months ago

Senior Application Security Specialist

IntouchCX · Metro Manila, Philippines

4 months ago

Senior Application Security Specialist

IntouchCX · Hyderabad, Telangana, India

4 months ago

Senior Application Security Specialist

IntouchCX · Cebu City, 6000 Cebu, Philippines

4 months ago

Senior Application Security Specialist

IntouchCX · Bengaluru, Karnataka, India

4 months ago

Application Security Specialist Engineer - InfoSec

Waters · Bangalore, IN

4 months ago

Application Security Specialist Engineer - InfoSec

International Waters · Bangalore, IN

4 months ago

CS - Infrastructure, Architecture & Security (IAS) Application Specialist - Hsinchu

Asml · Hsinchu ASML Office, Taiwan

2 months ago

Principle Specialist - Application Data Security Compliance

RTX · IN-KA-BENGALURU-NORTHGATE ~ Sy No 2/2 Venkatala Village ~ SY NO 2/2 VENKATALA VILLAGE, Yelahanka Hobli, India · Onsite

6 months ago

Application & Web Security Specialist

Dillards · Little Rock, AR +1

1+ year ago

Security Sales Specialist, Enterprise Application Migration and Modernization

Amazon

6 days ago

Application and Infrastructure Security Specialist - Assistant Vice President

Morgan Stanley · Harrison, NY,US, US

1 month ago

Application and Infrastructure Security Specialist - Assistant Vice President

Ms · NY - 2000 Westchester Ave, United States of America

1 month ago

Assistant Vice President / Vice President, Information Security Threat Management Specialist (Application Monitoring & Response), Global Information Security, Sydney, Australia

Ghr · Sydney, Australia · Onsite

1 month ago

Application Security Engineer (Code & Refactoring Specialist)

Codvo.ai · Hybrid

6 months ago