Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Growe

Application Security Engineer – Penetration Tester

Growe

Application Security Engineer conducting penetration tests and code reviews for GROWE. Auditing web applications, microservices, and REST/GraphQL APIs for vulnerabilities and business logic flaws.

Posted 8/11/2026full-timeWarsaw • 🇵🇱 PolandJuniorMid-LevelWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Application Security and Penetration Testing, with a strong focus on identifying and remediating vulnerabilities in web applications and APIs. Proficient in using security tools and frameworks to assess risks and ensure compliance with security standards.

Highest-signal resume keywords
Application SecurityPenetration TestingOWASP Top 10 VulnerabilitiesBurp Suite (Pro)Semgrep / OpenGrep

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security Findings TriageCode ReviewVulnerability AssessmentRisk AnalysisPenetration TestingAPI SecurityOAuth 2.0JWTSQL InjectionBusiness Logic Bugs
Soft Skills
Strong Communication SkillsResult-Oriented MindsetOpenness to Learning
Tools & Technologies
Burp Suite (Pro)NucleiSQLmapMetasploitTrivyGitleaksOSV-ScannerKubernetes SecurityAWS Cloud Security
Industry Keywords
Application SecurityProduct SecuritySASTSCAREST APIsGraphQL APIsAccess ControlAuthenticationAuthorization

Tech Stack

Tools & technologies
AWSCloudGraphQLKubernetesMicroservicesSQL

About the role

Key responsibilities & impact
  • Triage, validate, and prioritize security findings from SAST, SCA, and secret scanning tools; filter false positives, assess risks, and track issues through remediation
  • Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before production
  • Perform hands-on penetration testing of web applications, microservices, and APIs
  • Audit REST and GraphQL APIs and web applications, focusing on application security risks, authentication, authorization, and business logic

Requirements

What you’ll need
  • 2–4 years of experience in Application Security, Product Security, or Penetration Testing
  • Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner
  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec
  • Deep understanding of OWASP Top 10 vulnerabilities, including SQL injection, command injection, SSRF, XSS, CSRF, broken access control, IDOR/BOLA, security misconfigurations, cryptographic failures, insecure deserialization, and mass assignment
  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures
  • Deep understanding of OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC, and access control mechanics
  • Ability to identify authorization bypasses, session management flaws, and business logic bugs
  • Intermediate level of spoken and written English
  • Ability to read and analyze modern application code to spot security flaws (a plus)
  • Understanding of AWS cloud security principles and Kubernetes security fundamentals (a plus)
  • Strong communication skills for collaboration with engineering, product, and DevOps teams
  • Result-oriented mindset
  • Openness to learning

Benefits

Comp & perks
  • 🌐 Worldwide ❌ Jobs You've Hidden ⭐️ Saved Jobs ✅ Applied Jobs ✉️ Email Alerts 👤 Account Growe Website LinkedIn All Job Openings 501 - 1000 employees Founded 2019 🎮 Gaming 🤝 B2B Gaming
  • B2B
  • Entertainment Growe is a dynamic company that boldly operates in the iGaming and Entertainment industries. Its mission is to unlock potential and create opportunities by launching new iGaming brands across Asia and Latin America. Gathered expertise from diverse markets allows Growe to unite brands globally and enhance the gaming experience, making it a key player in the growth of the industry. Application Security Engineer – Penetration Tester Job not on LinkedIn 🔥 2 minutes ago 🏢 Warsaw – Onsite ⏰ Full Time 🟢 Junior 🟡 Mid-level 💻 Application Engineer 🚫👨‍🎓 No degree required AWS Cloud GraphQL Kubernetes Microservices SQL Apply Now Customize resume + cover letter Report problem ☆ Save ☑️ Mark as applied ❌ Hide 📋 Description
  • Triage, validate, and prioritize security findings from SAST, SCA, and secret scanning tools; filter false positives, assess risks, and track issues through remediation
  • Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before production
  • Perform hands-on penetration testing of web applications, microservices, and APIs
  • Audit REST and GraphQL APIs and web applications, focusing on application security risks, authentication, authorization, and business logic 🎯 Requirements
  • 2–4 years of experience in Application Security, Product Security, or Penetration Testing
  • Hands-on experience triaging and analyzing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner
  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec
  • Deep understanding of OWASP Top 10 vulnerabilities, including SQL injection, command injection, SSRF, XSS, CSRF, broken access control, IDOR/BOLA, security misconfigurations, cryptographic failures, insecure deserialization, and mass assignment
  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures
  • Deep understanding of OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC, and access control mechanics
  • Ability to identify authorization bypasses, session management flaws, and business logic bugs
  • Intermediate level of spoken and written English
  • Ability to read and analyze modern application code to spot security flaws (a plus)
  • Understanding of AWS cloud security principles and Kubernetes security fundamentals (a plus)
  • Strong communication skills for collaboration with engineering, product, and DevOps teams
  • Result-oriented mindset
  • Openness to learning Apply Now 📊 Check your resume score for this job Improve your chances of getting an interview by checking your resume score before you apply. Check Resume Score 🌐 Worldwide Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or support@remoterocketship.com Search Search Jobs by country Search jobs by city Search jobs by job title Search entry-level jobs Search junior-level jobs Search senior-level jobs Search jobs by tech stack Search jobs by contract type Search remote internships Search remote part-time jobs Remote jobs Anywhere in the World Companies Hiring Anywhere in the World Companies Hiring Sales People Anywhere in the World Companies Hiring Software Engineers Anywhere in the World Resources Advice Tips for finding remote jobs Interview questions and answers Resume examples Cover letter examples Post a job Affiliates About us Is Remote Rocketship legit? Privacy policy Terms of service Job board SEO course Remote Job Search MasterClass AI Apply Copilot OpenClaw job finder Find jobs using your resume Jobs by Country Remote jobs anywhere in the world (Worldwide remote jobs) Remote jobs United States Remote jobs Australia Remote jobs Brazil Remote jobs Canada Remote jobs France Remote jobs Ireland Remote jobs Germany Remote jobs Netherlands Remote jobs Spain Remote jobs UK Popular Jobs Remote data analyst jobs Remote customer support jobs Remote executive assistant jobs Remote marketing jobs Remote product designer jobs Remote product manager jobs Remote project manager jobs Remote recruiter jobs Remote sales jobs Remote software engineer jobs Jobs by Type Remote full-time jobs Remote part-time jobs Remote contract jobs Remote internship jobs Remote entry-level jobs Remote jobs with no experience required Remote junior jobs (1-3 years of experience) Digital nomad jobs Remote jobs with no degree required Freelance remote jobs Temporary remote jobs Remote jobs hiring now Stay at home mom jobs