Skip to content
Papaya Global

Application Security Engineer

Papaya Global Show all offers
Kraków
25 days ago

In short

Application Security Engineer at Papaya Global in Kraków. Focus on embedding security in the app lifecycle, threat modeling, architecture reviews, and vulnerability validation. Requires experience in secure development & cloud services.

AI-written summary based on the listing content.

Papaya Global is a rapidly growing, award-winning B2B tech unicorn with an ambitious mission to revolutionize the payroll & payments industry. With over $400M raised from multiple tier-one investors, our innovative technology provides a comprehensive solution for managing global workforces, encompassing everything from hiring and onboarding to managing and paying employees in over 160 countries.

We are looking for an Application Security / Security Architect to help embed security across the application lifecycle. In this role, you will partner with R& D, DevOps/Cloud, product, and the cybersecurity team to improve the security of applications, APIs, repositories, data stores, and application-facing cloud services.

You will combine architecture, threat modeling, secure software development, vulnerability validation, and practical engineering partnership. You will review designs and high-risk changes, define security requirements and reusable patterns, validate findings from vulnerability-management and security-assessment tooling, penetration tests, and bug-bounty activity, and turn those findings into clear, prioritized remediation work for engineering teams.

This role is ideal for someone who can move comfortably between architecture discussions, code and configuration reviews, security testing, and executive-level risk communication. The goal is to help the company build secure applications by design while making application-security decisions faster, clearer, and more measurable.

Responsibilities

  • Own and mature the application-security and security-architecture program across product and internal applications, APIs & services, and data stores.
  • Conduct threat modeling, architecture reviews, security design reviews, and risk assessments for new systems and materially changed services.
  • Define application-security requirements, review triggers, and practical security patterns for authentication, authorization, secrets, data protection, input handling, APIs, service-to-service communication, and security logging.
  • Review source code, high-risk configurations, CI/CD security checks, and application integrations with engineering teams; provide actionable guidance to enhance security posture.
  • Validate and prioritize findings from vulnerability-management and security-assessment tooling, penetration tests, and other security assessments - distinguish true risk from noise, and translate findings into clear engineering tasks and track their status.
  • Own the operating process for penetration testing and bug bounty programs, including scope, intake, triage, communication, remediation tracking, and verification of fixes.
  • Identify recurring vulnerability themes and root causes, then drive preventive improvements in engineering practices, tooling, architecture, and developer enablement.
  • Partner with Security Operations to provide application context, logging requirements, detection opportunities, and context relevant to monitoring and incident response.
Published 2026-08-26
Source