- Location
- Warszawa, PL
- Type
- Full-time
- Department
- IT
- Closing date
- Today
- Source
- iCIMS
Description
Overview
PepsiCo’s Global Application Security Program partners with development teams to identify and reduce security risk across enterprise applications and APIs.
Approximately 80% of this role focuses on SAST/SCA/Secrets/DAST and API security scanning technology. The engineer will support the operation and tuning of tools, manually triage security findings, perform targeted reviews using established procedures, assist developers with remediation, and manage findings through centralized vulnerability-management workflows.
The engineer will also help develop and maintain backend automation that initiates scans, monitors scan status, processes results, handles common failures, and integrates security tools into CI/CD and developer workflows.
The remaining capacity will support mobile application-security tooling and integrations as needed. Working knowledge of mobile security reviews is preferred but not required. This may include assisting with specific mobile-application security tooling scanning automation and CI/CD integrations under the guidance of senior engineers.
Responsibilities
Qualifications
Years of Experience
- Bachelor’s degree in Computer Science, Engineering, or a related technical field, with 1-3 years of relevant professional experience in application security, security engineering, secure software development, or vulnerability management.
Mandatory Technical Skills
- Foundational understanding of web application, mobile application, and API security concepts.
- Experience with or exposure to SAST/SCA and Secret, including rules, policies, findings, exclusions, and CI/CD integrations.
- Experience with or exposure to DAST and API scanning platforms, including scan configuration, scope management, authenticated scanning, and finding review.
- Experience manually reviewing and triaging SAST/SCA/Secret, DAST, Mobile, and API-security findings.
- Ability to reproduce common findings, recognize likely false positives, gather supporting evidence, and document remediation recommendations.
- Familiarity with web, mobile and API testing tools such as Burp Suite, Postman, MobSF, curl, browser developer tools, or comparable technologies.
- Familiarity with the OWASP Top 10 and common web vulnerabilities, including injection, cross-site scripting, broken access control, authentication weaknesses, SSRF, security misconfiguration, and sensitive-data exposure.
- Familiarity with the OWASP API Security Top 10, including BOLA/IDOR, broken authentication, authorization failures, resource-consumption issues, mass assignment, and API inventory weaknesses.
- Basic understanding of API authentication and authorization, including OAuth 2.0, OpenID Connect, JWT, API keys, service accounts, and role-based access control.
- Ability to read and understand application code written in at least one language such as Java, JavaScript, TypeScript, Python, Go, or C#.
- Experience working with centralized findings-management, ASPM, or vulnerability-management platforms.
- Familiarity with finding ingestion, normalization, deduplication, ownership assignment, remediation status, suppressions, exceptions, and SLA tracking.
- Exposure to GitHub, GitLab, Azure DevOps, Jenkins, or comparable source-control and CI/CD workflows.
- Basic scripting experience with Python, Go, PowerShell, or a comparable language.
- Familiarity with REST APIs, webhooks, JSON, command-line tools, and basic integration concepts.
- Familiarity with backend automation concepts such as scheduled jobs, workers, queues, polling, retries, timeouts, and result processing.
- Basic understanding of SAST, DAST, SCA, secrets detection, API security, Mobile security, SBOM, and related software supply-chain controls.
- Familiarity with cloud or container technologies such as AWS, Azure, GCP, Docker, or Kubernetes.
- Understanding of secure credential handling, service accounts, access controls, encryption, certificates, and audit logging.
- Ability to create clear technical documentation, findings summaries, remediation guidance, troubleshooting notes, and operational procedures.
Non-technical Skills
- Strong written and verbal communication skills.
- High integrity with sound judgment and accountability.
- Excellent analytical, problem-solving, and critical thinking abilities.
- Self-motivated, curious, and committed to continuous learning, including willingness to skill up in mobile application security.
- Strong collaboration, relationship-building, and influencing skills.
- Comfortable working in a fast-paced, global environment with changing priorities and ambiguity.
- Ability to perform effectively under pressure.
Differentiating Behaviors
- Demonstrates curiosity, innovation, and a continuous improvement mindset, including a willingness to develop mobile application security expertise.
- Makes sound decisions by balancing technical, business, and operational trade-offs.
- Remains calm, organized, and methodical in high-pressure situations.
- Effectively prioritizes work and manages competing commitments.