Application / Product Security Engineer
Miejsce pracy : Kraków
Technologies we use
Expected
- Java
- Python
- JavaScript
- SonarQube
- OWASP ZAP
- Nessus
- Invicti
- Azure
- Google Cloud
About the project
We are an international pioneering technology leader that is writing the future of industrial digitalization. At the forefront is our Corporate Technology Center which provides industry leading software and deep domain expertise to help the world’s most asset-intensive industries solve their biggest challenges.
To strengthen our team in IIoT Platform and Applications stream, we are looking for a Application / Product Security Engineer, who is an effective team player with excellent communication skills. As an IIoT P&A stream we are developing unified approach for software which consists of set of services and apps with individual lifecycles hosted on top of ABB common platforms for on-prem execution and cloud. Seize this unique opportunity and see your work transformed into a hive of tangible products.
As an Application / Product Security Engineer you will be working with cross-functional and agile teams which operates in an international environment.
Your responsibilities
Security Assessments : Conduct regular security assessments, including threat modeling, At-tack Surface Analysis, Critical Analysis.Security Architecture : Design and implement security architecture and controls for new and existing products.Code Review : Review source code for security vulnerabilities and provide actionable feedback to development teams.Secure Coding Practices : Educate and advocate for secure coding practices among development teams through workshops, training sessions, and documentation.Tool Implementation : Evaluate and implement application security tools (e.g., static and dynamic analysis tools) to automate security testing processes.Incident Response : Assist in incident response activities related to application security breaches, including root cause analysis and remediation strategies.Collaboration : Work closely with cross-functional teams, including software developers, DevOps, and IT security, to ensure security considerations are integrated into the development process.Monitoring and Reporting : Monitor application security metrics and provide regular reports to management on security posture and compliance.Our requirements
University degree in Computer Science or similar fieldUnderstanding of programming languages such as Java, C#, Python, or JavaScript.Strong understanding of application security principles and secure coding practices.Strong understanding of application security principles like network security, encryption, access management and their best practicesExperience with security tools and processes such as SAST, DAST, SCA, and vulnerability scanners (e.g., SonarQube, OWASP ZAP, Nessus, Invicti)Knowledge of security frameworks (e.g., OWASP Top Ten, NIST, ISO 27001), cloud platforms (e.g., AWS, Azure, Google Cloud) and their security featuresHands on experience with containerization and orchestration tools such as Docker and KubernetesFluency in EnglishCertifications : Relevant certifications such as Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), or Offensive Security Certified Professional (OSCP) are a plusBenefits
sharing the costs of sports activitiesprivate medical caresharing the costs of foreign language classessharing the costs of professional training & courseslife insuranceremote work opportunitiesflexible working timecorporate products and services at discounted pricesintegration eventscorporate sports teamsaving & investment schemecorporate librarycoffee / teaemployee referral programcharity initiativesfamily picnicsRecruitment stages
Phone ScreeningInterview with Recruiter and / or ManagerAdditional technical / language checkCongrats!ABB Business Services
Take your next career step at ABB with a global team that is energizing the transformation of society and industry to achieve a more productive, sustainable future.
At ABB, we have the clear goal of driving diversity and inclusion across all dimensions : gender, LGBTQ+, abilities, ethnicity and generations. Together, we are embarking on a journey where each and every one of us, individually and collectively, welcomes and celebrates individual differences.