Application Security Engineer | Mid-Senior | Low-level
Full Time
remote
Cybersecurity
Warsaw
The world’s most advanced VPN, and a whole lot more.
If you’re a curious problem-solver who carves their own path, join the team behind Threat Protection Pro, the NordLynx protocol, and the fastest VPN on the planet—tools that put privacy, security, and control back in people’s hands.
Your impact? Helping millions take back control of their online security, privacy, and data.
Risk Department plays a vital role in protecting the organization, ensuring resilience and security across all operations. By assessing risks, ensuring compliance, and managing security audits, this team helps build a strong and trustworthy foundation.
Main Responsibilities
- Conduct security reviews of application designs, source code, and third-party libraries;
- Perform regular application vulnerability assessments using both automated tools and manual testing techniques (e.g., SAST, DAST, SCA, penetration testing);
- Help maintain security tools, scripts, and processes to support secure development;
- Stay current with industry trends, zero-day vulnerabilities, and best practices in application security;
- Develop scripts and security automation tools to enhance application security testing processes;
- Design and deliver training for security engineering awareness & adoption;
- Actively look for internal security gaps within the product or organization overall;
- Ensure custom-built libraries/protocols are sufficiently tested and support internal and external audits;
Core Requirements
- Proven experience in mobile/desktop application security assessment planning, testing, methodologies, and vulnerability reporting;
- Strong understanding of secure coding practices;
- Ability to perform manual security code audit;
- Familiarity with at least one low-level programming language (e.g. C, C++, Rust, Go);
- Familiarity with of networking protocols such as TCP, UDP and the HTTP protocol;
- Familiarity with debuggers (e.g. GDB, LLDB, WinDbg) and reverse engineering tools (e.g. Ghidra, IDA);
- Familiarity with memory corruption issues, buffer overflows and related vulnerability classes;
- Familiarity with common authentication and authorization protocols (OAuth, SAML, JWT, etc.);
- Ability to work with networking tools such as Wireshark and tcpdump;
- Ability to quickly assimilate new technologies and tools;
- Sense of ownership with strong problem-solving and investigation skills;
- Ability to build and maintain relationships, influence key stakeholders across the business;
- Bonus points for community contributions like public CVEs, bug bounty recognition, open-source tools, blogs, etc.
Salary range
- Gross Salary 22900 - 32900 PLN/Month
Perks we offer
Our global mission fuels our drive. But when you need that extra push - here’s a list of things to look forward to.
Apply for this job
Cybersecurity
Warsaw
Our values
Our values are rooted in the actions of our people. They describe how we solve problems, make decisions, and ultimately - reach our goals as a team.