HomeSearchSecurity Engineer Jobs › Senior Application Security Engineer

Senior Application Security Engineer

www.pepsicojobs.com

Warszawa, Poland · senior
More Security Engineer jobs: Security Engineer jobsSecurity Engineer salary

Overview PepsiCo’s Global Application Security Program integrates security into software development at enterprise scale. Our mission is to make application security risks visible, actionable, and measurable so they can be remediated efficiently. Approximately 80% of this role focuses on web application and API security. The engineer will configure, tune, validate, and operate security tools such as SAST/SCA/Secret/DAST scanners; manually triage findings; perform targeted security reviews; integrate scanning into developer workflows through custom development; and manage results through centralized findings-management processes.

The engineer will also support the development and operation of backend automation that initiates scans, monitors scan status, ingests and normalizes results, manages failures and retries, and routes findings into enterprise vulnerability-management workflows. The remaining capacity may support mobile application security tooling and integrations as needed. Working knowledge of mobile security reviews and relevant tooling is preferred but not required.

This may include supporting backend automation and CI/CD integrations. Responsibilities Responsibilities Configure, tune, administer, and maintain SAST/SCA/Secret/DAST and API scanning security tools. Manually triage security findings, reproduce representative issues, determine exploitability, identify false positives, assess business impact, and provide actionable remediation guidance. Perform targeted manual security reviews of web applications and APIs, including authentication, authorization, session management, input validation, data exposure, business logic, and access-control testing.

Develop, test, tune, and maintain SAST rules, policies, rule packs, severity mappings, exclusions, and quality gates aligned with organizational standards. Configure and optimize DAST scanning profiles, authentication workflows, crawl settings, scan scopes, schedules, policies, and integrations to improve coverage and finding quality. Integrate security scanning into source-control, pull-request, build, CI/CD, release, ticketing, and developer workflows using reusable pipeline components, APIs, webhooks, and automation.

Develop and support backend automated scanning systems that onboard applications, initiate scans, track scan state, manage queues and retries, ingest results, normalize findings, and route data to downstream systems. Integrate findings into centralized application-security, vulnerability-management, or ASPM platforms, including normalization, correlation, deduplication, enrichment, ownership mapping, suppression, exception handling, and state synchronization.

Establish risk-based prioritization and remediation workflows that account for exploitability, application exposure, data sensitivity, asset criticality, compensating controls, and business impact. Partner with developers, product teams, DevOps engineers, platform owners, and security stakeholders to resolve findings, improve developer experience, and implement practical security guardrails. Monitor scanner and integration health, including scan success rates, job queues, runners, connectivity, authentication, timeouts, capacity, licensing, logs, and service reliability.

Evaluate emerging application-security tools and capabilities through proofs of concept, comparative testing, technical scorecards, detection-quality analysis, integration assessment, and operational-fit reviews. Develop and maintain security-testing standards, integration patterns, technical documentation, onboarding guides, operational runbooks, troubleshooting procedures, and developer-facing remediation guidance.

Develop metrics and KPIs for application onboarding, scan coverage, workflow adoption, scan success, execution time, finding quality, false-positive rates, remediation performance, and platform reliability. As needed, support mobile application-security tooling and integrations, including limited finding triage and b

Search all live jobs — free, no account →