3,092 Open roles
108 Companies
28 Posted today
Jobs / Growe / Application Security Engineer / Penetration Tester
Posted 2026-08-12

Application Security Engineer / Penetration Tester

Description

Growe is seeking an Application Security Engineer and Penetration Tester. This role focuses on identifying and mitigating security vulnerabilities within web applications, microservices, and APIs to ensure robust protection before code reaches production.

The successful candidate will work closely with engineering, product, and DevOps teams to triage security findings, conduct manual code reviews, and perform penetration testing. The position requires a strong technical background in application security and a proactive approach to identifying complex business logic flaws.

Responsibilities
  • Triage, validate, and prioritise security findings from SAST, SCA, and Secret scanning tools, filter out false positives, assess risks, and track issues through to remediation.
  • Conduct manual and tool-assisted code reviews to identify security vulnerabilities, logic flaws, and insecure implementation choices before code reaches production.
  • Perform hands-on penetration testing of web applications, microservices, and APIs to uncover security vulnerabilities and business logic flaws.
  • Audit REST and GraphQL APIs and web applications with a strong focus on core application security risks, authentication, authorisation, and business logic.
Requirements
  • 3 years of experience in Application Security, Product Security, or Penetration Testing (required).
  • Hands-on experience triaging and analysing findings from Semgrep / OpenGrep, Gitleaks, Trivy, and OSV-Scanner (required).
  • Experience with Burp Suite (Pro), Nuclei, Subfinder, SQLmap, Metasploit, and NetExec (required).
  • Deep understanding of classic OWASP Top 10 vulnerabilities, including Injection flaws (SQLi, Command Injection), Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Broken Access Control / Insecure Direct Object References (IDOR / BOLA), Security Misconfigurations, Cryptographic Failures, Insecure Deserialisation, and Mass Assignment (required).
  • Solid knowledge of OWASP API Security Top 10 for REST and GraphQL architectures (required).
  • Deep understanding of identity protocols and access control mechanics (OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC) (required).
  • Ability to identify complex authorisation bypasses, session management flaws, and business logic bugs (required).
  • Ability to read and analyse modern application code to spot security flaws (nice-to-have).
  • Basic understanding of cloud security principles in AWS environments and Kubernetes (K8s) security fundamentals (nice-to-have).
  • Intermediate level of English (spoken and written) (required).
  • Strong communication skills to effectively collaborate with engineering, product, and DevOps teams (required).
  • Result-oriented mindset (required).
  • Openness to learning (required).
Benefits
  • Health & Wellness Focus
  • Global Medical Coverage
  • Growth Opportunities
  • Benefits Programs (compensation for the gym/stomatology/psychological service & etc.)
  • Performance-Driven Rewards
  • Dynamic Work Environment
About Growe

Growe is a business advisory and services group operating in the iGaming and entertainment industries. Headquartered in Warsaw, it combines strategic vision with hands-on expertise to help businesses navigate the sector, enter new markets and achieve sustainable growth. Its capabilities span business and brand strategy, market research, marketing solutions, IT customisation, organisational structuring and talent management. The company focuses on launching new iGaming brands worldwide and turning challenges into competitive advantages for its clients.

Read more about Growe →

Apply on Growe →