Skip to main content
Accenture
Scraped fromWorkToday
Frontend

Application Security Specialist (regular/senior) (She/He/They)

OWASP ASVSOWASPOWASP API Top 10CWE Top 25SASTDASTSCASecrets scanningDependency scanningArtefact signingSBOMSLSAInfrastructure as CodeGitHubGitLabAzure DevOpsBitbucketJenkinsAWSAzureGCPJavaC#/.NETJavaScriptGoPythonOAuthOpenID ConnectSAMLSSOLLMThreat ModelingSecure design reviewsCode reviewCI/CDDevOpsCryptographyHashingKey managementSQL injectionXSSCommand injectionCSRFAuthenticationAuthorizationSession managementAI agentsModel pipelinesData PipelinesAI lifecycleResponsible AISecurity champions programCISO
Work Type
-
Job Type
-
Location
Worldwide
Salary
Not specified

About the Position

Accenture's Cyber Security team is hiring an Application Security Specialist to assess client security posture, run threat modelling, review code and CI/CD pipelines, select AppSec tooling, and work on AI security. The role involves working with clients across industries to embed security into development and operations.

Responsibilities

  • Assess where a client actually stands — against OWASP ASVS, OWASP Top 10, OWASP API Top 10, or CWE Top 25 — and turn the gaps into a prioritized roadmap their teams can work through.
  • Run threat modelling and secure design reviews with the client’s own architects and developers, across hybrid, distributed, cloud-native, containerized, microservices, event-driven, and monolithic systems.
  • Review code, APIs, Infrastructure as Code, and CI/CD pipelines from a security point of view — then help the teams fix what you find rather than just reporting it. That extends to building security into pipelines, build systems, and artefact repositories, and to software supply chain risk: dependencies, build integrity, SBOMs, third-party components.
  • Select, roll out, and tune AppSec tooling — SAST, DAST, SCA, secrets scanning — so that results are trusted and acted on rather than muted, and so security gates and automated testing hold up across the SSDLC.
  • Work on the security of AI-enabled systems: LLM-based applications, AI agents, model and data pipelines, and the risks that come with them — prompt injection, data poisoning, model and inference exposure, unsafe integration. That includes defining controls across the AI lifecycle, using AI-based tooling for code analysis and vulnerability triage, and supporting governance and compliance around responsible AI use.
  • Make it stick with the client’s people: secure coding standards and design guidance teams will actually use, guardrails for how developers use AI coding assistants, a security champions program, hands-on developer training, and presenting findings and recommendations from team leads up to CISO level.

Requirements

  • Engineering or IT background.
  • Foundational security knowledge: understanding of confidentiality, integrity, availability, encryption, hashing, key management.
  • Understanding of the software development lifecycle.
  • Familiarity with DevOps and CI/CD pipelines: hands-on experience with at least one platform — GitHub, GitLab, Azure DevOps, Bitbucket, Jenkins, or equivalent.
  • Experience with at least one public cloud platform: AWS, Azure, or GCP.
  • Ability to read code and identify common security vulnerabilities: SQL injection, XSS, command injection, CSRF in any one language — Java, C#/.NET, JavaScript, Go, Python, or equivalent.
  • Language requirements: Professional proficiency in both English and Polish.
  • Strong communication skills.
  • Proactive, ownership-oriented mindset.
  • Adaptability and commitment to continuous learning.
  • Regular: approximately 2–5 years of relevant experience, independently deliver defined workstreams, working knowledge of OWASP Top 10 and secure coding principles.
  • Senior: approximately 5+ years of relevant experience, lead workstreams, provide technical direction, mentor junior colleagues, demonstrated depth in at least one domain.

Benefits

  • Permanent employment contract.
  • Individual support of a People Lead and a specific path of professional development, as well as the possibility of a session with a Coach.
  • A wide training package (soft, technical, and language training offer, access to the e-learning platforms, Gallup test, GenAI training, possibility of co-financing courses, and certification).
  • Employee Assistance Program - legal, financial, and psychological consultations.
  • Accenture employees eligible for the Employee share purchase plan automatically become eligible for quarterly dividends if they own company shares.
  • Paid employee referral program.
  • Private medical care, life insurance.
  • Access to the Worksmile platform (possibility of using a wide range of products and services, including the Multisport card).
Application Security Specialist (regular/senior) (She/He/They)
View Original