Application Security Engineer

PandaDoc Portugal
Remote
Apply
AI Summary

Shape and strengthen PandaDoc's security foundations by embedding security into every stage of development. Review, test, and monitor applications to identify and remediate security weaknesses while driving automation and tooling. Partner with engineering teams to implement proactive security practices across cloud, container, and AI environments.

Key Highlights
Own security initiatives across application lifecycle with engineering teams
Implement DevSecOps practices including SAST, DAST, SCA, secrets detection, and container security
Address AI security challenges as PandaDoc deploys AI in products and internally
Key Responsibilities
Review, test, and monitor applications to identify security weaknesses
Manage vulnerabilities from discovery through remediation with engineering teams
Respond to infrastructure security alerts and perform hardening including role and permission reviews
Participate in incident response and root cause analysis
Analyze and monitor security threats and prevention measures based on industry trends
Partner with product, development, and infrastructure teams to embed security requirements
Integrate and operate automated security testing across development lifecycle (SAST, DAST, SCA, secrets detection, container, supply chain security)
Develop security automation and tooling to scale security across engineering
Drive threat modeling and secure-by-design practices across services
Assess overall security posture and identify risks with recommendations
Assist in addressing emergent threats in AI security
Technical Skills Required
Application security tools (SAST/SCA/DAST/WAF) Cloud security (AWS) Web application security (OWASP Top 10, CWE Top 25) Security automation and tooling (Python/Bash)
Benefits & Perks
Competitive salary (222000-334000 PLN annually for Poland)
Work from anywhere - distributed worldwide
6 self care days

Job Description


As PandaDoc continues to scale, we’re expanding our security team and looking for an Application Security Engineer to help shape and strengthen our security foundations. In this role, you’ll take ownership of key security initiatives across our application, working closely with engineering to embed security into every stage of development. You’ll contribute to building a proactive, automation-driven security culture while addressing both current risks and emerging challenges, including AI security.

In this role, you will:
  • Review, test, and monitor our applications to identify security weaknesses
  • Manage vulnerabilities from discovery through remediation, working directly with engineering teams to resolve them
  • Respond to infrastructure security alerts and perform hardening, including reviewing roles and permissions across services and APIs
  • Participate in incident response and root cause analysis
  • Analyze and monitor relevant security threats and prevention measures based on industry trends and standards
  • Partner with product, development, and infrastructure teams to embed security requirements into how they build
  • Integrate and operate automated security testing across the development lifecycle, including SAST, DAST, SCA, secrets detection, container, and supply chain security
  • Develop security automation and tooling to scale security across engineering
  • Drive threat modeling and secure-by-design practices across our services
  • Assess our overall security posture and identify risks, providing recommendations to strengthen it
  • Assist in addressing emergent threats in AI security as PandaDoc deploys AI in its product and for internal use
Our stack:
  • Service-oriented architecture
  • Main development stacks: Java/Spring, Python/Django, JavaScript/React
  • Docker, Kubernetes
  • Amazon Web Services: EKS, RDS, S3, ElastiCache, etc.
  • Monitoring stack: Grafana, Loki, Tempo, Mimir
  • Source control & CI/CD: GitHub / GitHub Actions
  • A combination of AWS native and 3rd party security solutions for infrastructure and application security (WAF, CNAPP, SCA/SAST, DAST, IDS/IPS, etc.)
About you:
  • 3+ years of experience with application security tools such as SAST/SCA, DAST, WAF, CI/CD security, and penetration testing
  • 2+ years of cloud security experience implementing security controls and best practices in AWS, GCP, or Microsoft Azure
  • Strong background in web application security, including common vulnerability classes (OWASP Top 10, CWE Top 25), attack vectors, and mitigations
  • Good understanding of access control and identity management principles (SAML 2.0, OAuth, OIDC, JWT, etc.)
  • Practical skills building security automation and tooling with Python, Bash, or equivalent languages
  • Experience implementing DevSecOps practices across the SDLC
  • Familiarity with containerized, Kubernetes-based environments and their security
  • Solid interpersonal, written, and verbal communication skills
  • Upper-Intermediate English level (B2+)
Company Overview: 

PandaDoc empowers more than 60,000 growing organizations to thrive by taking the work out of document workflow. PandaDoc provides an all-in-one document workflow automation platform that helps fast scaling teams accelerate the ability to create, manage, and sign digital documents including proposals, quotes, contracts, and more.  For more information, please visit https://www.pandadoc.com.

Company Culture: 

We're known for our work-life balance, kind co-workers, & creative virtual team-bonding events. And although our Pandas are located across the globe, we stay connected with the help of technology and ensure that everyone on our team feels, well, like a team.

Pandas work best when they're happy. We retain our talent by upholding our values of integrity & transparency, and selling a product that changes the lives of our customers. 

Check out our LinkedIn to learn more.

Benefits:
  • A competitive salary. If you are located in Poland, the salary range is 222000 to 334000 PLN annually.
  • An honest, open culture that emphasizes feedback and promotes professional and personal development
  • An opportunity to work from anywhere — our team is distributed worldwide, from Lisbon to Manila, from Florida to California
  • 6 self care days
  • And much more!

PandaDoc is an Equal Opportunity Employer. We are committed to equal treatment of all employees without regard to race, national origin, religion, gender, age, sexual orientation, veteran status, physical or mental disability or other basis protected by law.

EXTERNAL RECRUITERS

Approval Requirement

The use of external recruiters/staffing agencies requires prior approval from our HR Team. The HR Team at PandaDoc requests that external recruiters/staffing agencies not to contact PandaDoc employees directly in an attempt to present candidates. Complying with this request will be a factor in determining future professional relationships with PandaDoc.


Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

bridge351

Portugal
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Not Applicable

Alignerr

United Kingdom
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

cyber focus ai

United State

Subscribe our newsletter

New Things Will Always Update Regularly