MENU
  • Remote Jobs
  • Companies
  • Go Premium
  • Job Alerts
  • Post a Job
  • Log in
  • Sign up
Working Nomads logo Working Nomads
  • Remote Jobs
  • Companies
  • Post Jobs
  • Go Premium
  • Get Free Job Alerts
  • Log in

Security Engineer - Application Security

Dropbox

Full-time
Poland
zł 212k-zł 288k per year
security
engineer
Apply for this position

Role Description

As part of the Application Security team, you’ll focus on reducing risk at scale by building the security infrastructure, automation, and tooling that empowers engineers to ship secure products with confidence. We work closely with engineering and product teams throughout the software development lifecycle (SDLC), embedding secure-by-default practices and delivering scalable solutions.

Application Security Engineers create impact by designing and implementing security tooling, writing custom security rules, and building frameworks that address broad classes of vulnerabilities. In addition to proactive development, we support teams through design consultations, threat modeling, documentation, and education to uplift security culture across Dropbox.

Our Engineering Career Framework is viewable by anyone outside the company and describes what’s expected for our engineers at each of our career levels. Check out our blog post on this topic and more here.

Responsibilities

  • Build and maintain security tools, automation, and libraries to enable secure-by-default development across engineering teams.

  • Design and implement custom security rules (e.g., Semgrep, CodeQL) to detect and prevent common and emerging vulnerability patterns.

  • Act as a subject matter expert on application security across web, mobile, and desktop environments.

  • Conduct security consultations and threat modeling sessions, and clearly communicate risk and mitigation strategies to technical and non-technical stakeholders.

  • Improve and scale the Secure Development Lifecycle (SDLC) by integrating tools, checks, and processes into engineering workflows.

  • Perform targeted code and design reviews, and develop follow-up tooling or controls to prevent regressions.

  • Collaborate cross-functionally with engineering, product, GRC, and AI/ML teams to proactively address security risks, especially in fast-moving and emerging tech areas.

On-call work may be necessary occasionally to help address bugs, outages, or other operational issues, with the goal of maintaining a stable and high-quality experience for our customers.

Requirements

  • 3+ years of experience in application security or security engineering roles.

  • Hands-on experience building or using security automation tools to improve developer workflows and product security.

  • Demonstrated ability to work across the SDLC, including supporting and interpreting findings from penetration tests and bug bounty reports.

  • Familiarity with modern tech stacks, including microservices, CI/CD pipelines, and cloud-native environments.

  • Solid understanding of common vulnerability classes (e.g., injection, XSS, authN/authZ issues) and practical mitigation strategies.

  • Comfortable working in cross-functional environments and supporting multiple product and engineering teamssimultaneously.

  • Experience participating in or supporting incident response or security on-call rotations is a plus

Preferred Qualifications

  • Experience in application security engineering, with a strong focus on security tooling and automation.

  • Demonstrated ability to write and maintain custom security rules and integrate them into developer workflows.

  • Experience with machine learning systems, particularly generative AI, and the ability to support secure development in AI-driven products.

  • Experience developing internal libraries or frameworks that reduce or eliminate entire classes of vulnerabilities.

  • Proficient in software development, with experience contributing production-level code in one or more modern languages.

  • Familiarity with securing diverse application types, including web, mobile, and native platforms.

  • Experience with data security, including tooling for data protection, access control, and encryption.

  • Strong communication skills and ability to build trusted partnerships with cross-functional teams.

Compensation

Poland Pay Range

212 500 zł—287 500 zł PLN

Apply for this position
Bookmark Report

About the job

Full-time
Poland
zł 212k-zł 288k per year
Posted 3 hours ago
security
engineer

Apply for this position

Bookmark
Report
Enhancv advertisement

30,000+
REMOTE JOBS

Unlock access to our database and
kickstart your remote career
Join Premium

Security Engineer - Application Security

Dropbox

Role Description

As part of the Application Security team, you’ll focus on reducing risk at scale by building the security infrastructure, automation, and tooling that empowers engineers to ship secure products with confidence. We work closely with engineering and product teams throughout the software development lifecycle (SDLC), embedding secure-by-default practices and delivering scalable solutions.

Application Security Engineers create impact by designing and implementing security tooling, writing custom security rules, and building frameworks that address broad classes of vulnerabilities. In addition to proactive development, we support teams through design consultations, threat modeling, documentation, and education to uplift security culture across Dropbox.

Our Engineering Career Framework is viewable by anyone outside the company and describes what’s expected for our engineers at each of our career levels. Check out our blog post on this topic and more here.

Responsibilities

  • Build and maintain security tools, automation, and libraries to enable secure-by-default development across engineering teams.

  • Design and implement custom security rules (e.g., Semgrep, CodeQL) to detect and prevent common and emerging vulnerability patterns.

  • Act as a subject matter expert on application security across web, mobile, and desktop environments.

  • Conduct security consultations and threat modeling sessions, and clearly communicate risk and mitigation strategies to technical and non-technical stakeholders.

  • Improve and scale the Secure Development Lifecycle (SDLC) by integrating tools, checks, and processes into engineering workflows.

  • Perform targeted code and design reviews, and develop follow-up tooling or controls to prevent regressions.

  • Collaborate cross-functionally with engineering, product, GRC, and AI/ML teams to proactively address security risks, especially in fast-moving and emerging tech areas.

On-call work may be necessary occasionally to help address bugs, outages, or other operational issues, with the goal of maintaining a stable and high-quality experience for our customers.

Requirements

  • 3+ years of experience in application security or security engineering roles.

  • Hands-on experience building or using security automation tools to improve developer workflows and product security.

  • Demonstrated ability to work across the SDLC, including supporting and interpreting findings from penetration tests and bug bounty reports.

  • Familiarity with modern tech stacks, including microservices, CI/CD pipelines, and cloud-native environments.

  • Solid understanding of common vulnerability classes (e.g., injection, XSS, authN/authZ issues) and practical mitigation strategies.

  • Comfortable working in cross-functional environments and supporting multiple product and engineering teamssimultaneously.

  • Experience participating in or supporting incident response or security on-call rotations is a plus

Preferred Qualifications

  • Experience in application security engineering, with a strong focus on security tooling and automation.

  • Demonstrated ability to write and maintain custom security rules and integrate them into developer workflows.

  • Experience with machine learning systems, particularly generative AI, and the ability to support secure development in AI-driven products.

  • Experience developing internal libraries or frameworks that reduce or eliminate entire classes of vulnerabilities.

  • Proficient in software development, with experience contributing production-level code in one or more modern languages.

  • Familiarity with securing diverse application types, including web, mobile, and native platforms.

  • Experience with data security, including tooling for data protection, access control, and encryption.

  • Strong communication skills and ability to build trusted partnerships with cross-functional teams.

Compensation

Poland Pay Range

212 500 zł—287 500 zł PLN

Working Nomads

Post Jobs
Premium Subscription
Sponsorship
Free Job Alerts

Job Skills
API
FAQ
Privacy policy
Terms and conditions
Contact us
About us

Jobs by Category

Remote Administration jobs
Remote Consulting jobs
Remote Customer Success jobs
Remote Development jobs
Remote Design jobs
Remote Education jobs
Remote Finance jobs
Remote Legal jobs
Remote Healthcare jobs
Remote Human Resources jobs
Remote Management jobs
Remote Marketing jobs
Remote Sales jobs
Remote System Administration jobs
Remote Writing jobs

Jobs by Position Type

Remote Full-time jobs
Remote Part-time jobs
Remote Contract jobs

Jobs by Region

Remote jobs Anywhere
Remote jobs North America
Remote jobs Latin America
Remote jobs Europe
Remote jobs Middle East
Remote jobs Africa
Remote jobs APAC

Jobs by Skill

Remote Accounting jobs
Remote Assistant jobs
Remote Copywriting jobs
Remote Cyber Security jobs
Remote Data Analyst jobs
Remote Data Entry jobs
Remote English jobs
Remote Spanish jobs
Remote Project Management jobs
Remote QA jobs
Remote SEO jobs

Jobs by Country

Remote jobs Australia
Remote jobs Argentina
Remote jobs Brazil
Remote jobs Canada
Remote jobs Colombia
Remote jobs France
Remote jobs Germany
Remote jobs Ireland
Remote jobs India
Remote jobs Japan
Remote jobs Mexico
Remote jobs Netherlands
Remote jobs New Zealand
Remote jobs Philippines
Remote jobs Poland
Remote jobs Portugal
Remote jobs Singapore
Remote jobs Spain
Remote jobs UK
Remote jobs USA


Working Nomads curates remote digital jobs from around the web.

© 2025 Working Nomads.