T-Mobile Poland is a leader in telecommunication, dedicated to providing innovative solutions that drive growth and efficiency for our clients. Our commitment to security and integrity is at the forefront of our operations, and we are seeking a talented Application Security Expert to join our team.
As an Application Security Expert at T-Mobile you will play a crucial role in safeguarding our systems and data. You will work closely with our IT, Cloud and development teams to ensure robust security measures are in place and that our applications and infrastructure are secure against current and emerging threats. Your broad knowledge of security topics, combined with your understanding of application security and cloud security, will be essential in this role.
responsibilities :
Identify opportunities to automate and standardize application security controls and cooperate with the CICD team
Analyze source code to mitigate identified weaknesses and vulnerabilities
Create guidelines and application security standards
Review and check automated security testing results
Perform software architecture design reviews for both on-prem and cloud deployments
Work with engineering teams to help architect and implement solutions that are secure by design
Define, document, and supervise implementation of security guidelines and standards
Build frameworks and libraries to provide security by default
requirements-expected :
4+ years of full-time commercial application security experience
4+ years of experience in software development, preferably in cloud environment
Experience in architecting and building application security on modern tech stacks across multiple platforms (web, mobile, desktop)
Prior experience in performing threat modelling and secure design reviews
Familiarity with cloud services and their security best practices and secure design patterns - AWS especially
Kubernetes and containerization security know-how
Knowledge of common appsec vulnerabilities like OWASP Top 10 and cloud security gaps
Knowledge of standards like OWASP Testing Guide, OWASP ASVS, NIST and SANS top 20
Proficiency in modern and common web stack technologies (HTTP, HTML5, AJAX, REST, ...)
Understanding of basic cryptography (encryption, hashing, MACs, digital signatures, TLS, password storage) and how they are applied in web applications
Knowledge of protocols (OAuth, SAML, OIDC), flows and best practices
At least basic know-how in networks
offered :
Współpraca w oparciu o umowę direct B2B
Pakiet medyczny, sportowy i ubezpieczenie na życie na preferencyjnych warunkach
Dostęp do platformy szkoleniowej RoDoS
Brak dress codeu - u nas możesz być sobą
Znam Talent – szkolenia lub pieniądze za polecenie znajomych do pracy ?!
Poza tym możesz u nas liczyć na dostęp do naszych produktów i usług na preferencyjnych warunkach