Application Security Engineer - Pentester

veeamsoftware· VDC - Engineering 1009422
Apply Now ↗
📍 Warsaw, Poland

About this role

Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.

About the Role

As an Application Security Engineer (Offensive Testing), you will lead and perform penetration testing and DAST for Veeam Data Cloud products. You’ll use Burp Suite and modern web/API testing techniques to find real, exploitable issues, help prioritize risk, and work with engineering teams to drive fixes to completion.

You will also improve testing tools and processes, make testing more repeatable, and help teams prevent recurring vulnerabilities—especially around authentication, authorization, session management, and tenant isolation.

What You’ll Do

  • Own offensive testing: plan what to test, how deep to go, and how often; create clear, consistent reports and reusable playbooks
  • Perform manual pentesting (main focus): test web apps and APIs, especially authentication/authorization, multi-tenant boundaries, and critical workflows; chain issues into realistic attack paths
  • Use Burp Suite daily: validate and reproduce findings with advanced Burp features; build and maintain repeatable scopes, macros, and authenticated flows
  • Run and improve DAST: execute and tune authenticated scans, reduce false positives, and work with CI/platform teams to scale scanning and manage credentials
  • Drive remediation: deliver high-quality write-ups, partner with engineers to fix and retest, and help prevent regressions; ensure findings are tracked with the right severity and SLAs
  • Improve security long-term: spot recurring patterns and help teams prevent them through standards, libraries, platform controls, and input to threat modeling/design reviews

What You’ll Bring

  • Strong web and API pentesting experience, especially in authorization (IDOR/BOLA, privilege escalation, role/tenant boundaries), authentication/session flows (tokens, identity integrations), and common vulnerabilities (injection, SSRF, deserialization, misconfigurations) with practical exploitation skills
  • Advanced Burp Suite skills: manual validation, targeted fuzzing, authenticated testing, and workflow automation (extensions/macros)
  • Experience writing Semgrep rules to detect insecure patterns and improve secure-by-default development
  • DAST experience at scale: running or supporting authenticated scans, tuning coverage, and reducing false positives
  • Clear written communication: concise PoCs and actionable remediation guidance for engineers

Bonus Skills

  • SaaS multi-tenant security testing experience; OAuth2/OIDC/SAML depth; bug bounty triage; writing custom tooling or Burp extensions

What You’ll Get 

  • 26 paid days off annually, plus 4 extra global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
  • Paid parental, maternity, and paternity leave
  • Fully covered family medical plan, dental, rehab, and vaccinations
  • Life, critical illness, and disability insurance
  • Employer pension contribution via PPK
  • Monthly Edenred allowance of 450 PLN for meals
  • MultiSport card fully covered by Veeam, giving access to sports facilities nationwide
  • Up to 12 free therapy sessions annually, plus legal and financial advice
  • Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops and learning events like our annual Global Day of Learning

Please note: If the applicant is permanently present outside of Poland, Veeam reserves the right to refuse to consider the application for a job. Remote job is only possible in case the employee is located in Poland.

#LI-GD1
#Hybrid

Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.

Personal data collected during the recruitment process will be processed in accordance with our Recruiting Privacy Notice, which explains how your information is collected, used, and handled in connection with hiring activities. By applying for this position, you consent to this processing. 

By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.

Frequently Asked Questions

Is the salary disclosed for the Application Security Engineer - Pentester position at veeamsoftware?
The salary for this Application Security Engineer - Pentester role at veeamsoftware is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Application Security Engineer - Pentester position at veeamsoftware located?
This Application Security Engineer - Pentester role at veeamsoftware is based in Warsaw, Poland. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Which team or department does the Application Security Engineer - Pentester at veeamsoftware belong to?
This Application Security Engineer - Pentester position is part of the VDC - Engineering 1009422 department at veeamsoftware. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Application Security Engineer - Pentester position at veeamsoftware?
Click the "Apply Now" button on this page. You will be redirected to veeamsoftware's official application portal hosted on greenhouse where you can submit your application directly.
When was the Application Security Engineer - Pentester job at veeamsoftware posted?
This Application Security Engineer - Pentester position at veeamsoftware was posted on Apr 1, 2026. Apply as soon as possible — early applications are often reviewed first.
Application Security Engineer - Pentester
veeamsoftware
Apply for this role ↗

You'll be redirected to veeamsoftware's official application page on Greenhouse.