A
Accenture
Frontend
Application Security Specialist (regular/senior) (She/He/They)
OWASP ASVSOWASPOWASP API Top 10CWE Top 25SASTDASTSCAsecrets scanningSBOMLLMJavaC#/.NETJavaScriptGoPythonAWSAzureGCPGitHubGitLabAzure DevOpsBitbucketJenkinsOAuthOpenID ConnectSAMLSSOSLSA
About the Position
Accenture's Cyber Security team is hiring an Application Security Specialist to assess and improve clients' security posture. The role involves threat modeling, secure code review, AppSec tooling, and securing AI-enabled systems. You will work with leading organizations across industries, helping integrate security into development and operations.
Responsibilities
- Assess where a client actually stands — against OWASP ASVS, OWASP Top 10, OWASP API Top 10, or CWE Top 25 — and turn the gaps into a prioritized roadmap their teams can work through.
- Run threat modelling and secure design reviews with the client’s own architects and developers, across hybrid, distributed, cloud-native, containerized, microservices, event-driven, and monolithic systems.
- Review code, APIs, Infrastructure as Code, and CI/CD pipelines from a security point of view — then help the teams fix what you find rather than just reporting it.
- Build security into pipelines, build systems, and artefact repositories, and manage software supply chain risk: dependencies, build integrity, SBOMs, third-party components.
- Select, roll out, and tune AppSec tooling — SAST, DAST, SCA, secrets scanning — so that results are trusted and acted on rather than muted, and so security gates and automated testing hold up across the SSDLC.
- Work on the security of AI-enabled systems: LLM-based applications, AI agents, model and data pipelines, and the risks that come with them — prompt injection, data poisoning, model and inference exposure, unsafe integration.
- Define controls across the AI lifecycle, use AI-based tooling for code analysis and vulnerability triage, and support governance and compliance around responsible AI use.
- Make it stick with the client’s people: secure coding standards and design guidance teams will actually use, guardrails for how developers use AI coding assistants, a security champions program, hands-on developer training, and presenting findings and recommendations from team leads up to CISO level.
Requirements
- Engineering or IT background. A background in software development, architecture, or IT operations — with practical experience building, running, or designing software systems or infrastructure.
- Foundational security knowledge. A sound understanding of core security principles — confidentiality, integrity, and availability — and how they apply to real systems. Familiarity with encryption, hashing, and key management at a conceptual and practical level, including common misuse patterns.
- Understanding of the software development lifecycle. Sufficient knowledge of how software is specified, built, reviewed, tested, released, and maintained to engage credibly with development and engineering teams.
- Familiarity with DevOps and CI/CD pipelines. Hands-on experience with at least one platform — GitHub, GitLab, Azure DevOps, Bitbucket, Jenkins, or equivalent — with an understanding of build processes and pipeline configuration.
- Experience with at least one public cloud platform. Practical, hands-on experience with AWS, Azure, or GCP, including their core services and security controls.
- Ability to read code and identify common security vulnerabilities. Capability to identify and clearly articulate issues such as SQL injection, XSS, command injection, and CSRF within a codebase, in any one language — Java, C#/.NET, JavaScript, Go, Python, or equivalent.
- Language requirements. Professional proficiency in both English and Polish is required. English is the primary language for client-facing work — including findings communication, workshop facilitation, and presentations to senior stakeholders up to CISO level. Polish is the language of day-to-day team operations. Proficiency in both is a non-negotiable requirement for this role.
- Ways of working. Strong communication skills, including the ability to translate complex technical findings into clear, actionable recommendations for non-technical audiences. A proactive, ownership-oriented mindset — with the ability to define and drive security improvements independently within a client environment. Adaptability and a commitment to continuous learning, given the pace of change in the security landscape.
Benefits
- Permanent employment contract.
- Individual support of a People Lead and a specific path of professional development, as well as the possibility of a session with a Coach.
- A wide training package (soft, technical, and language training offer, access to the e-learning platforms, Gallup test, GenAI training, possibility of co-financing courses, and certification).
- Employee Assistance Program - legal, financial, and psychological consultations.
- Accenture employees eligible for the Employee share purchase plan automatically become eligible for quarterly dividends if they own company shares.
- Paid employee referral program.
- Private medical care, life insurance.
- Access to the Worksmile platform (possibility of using a wide range of products and services, including the Multisport card).
Application Security Specialist (regular/senior) (She/He/They)
View Original