Application Security Engineer
RemoteCracow, Małopolskie, PolandFull-time
- Posted
- today
- Source
- LinkedIn (remote, Europe)
- Field
- Engineering, Security
Skills
CommunicationJavaScriptSecurityPythonElixirNext.jsGo
Description
🚀 Join the Future of Commerce with Whatnot!
Whatnot is the largest live shopping platform in North America and Europe to buy, sell, and discover the things you love. Whether it's trading cards, fashion, electronics, or live plants, our sellers are building real businesses across hundreds of categories. We're building live commerce at a scale that's never been done in the West, and there's no playbook to copy. The people here are shaping how an entirely new industry develops.
As a remote co-located team, we're inspired by our values and anchored in hubs across the US, UK, Ireland, Poland, Germany, and Australia. We move fast, stay close to our users, and focus on the work that drives the most impact.
We're one of the fastest growing marketplaces and were recently named the #1 Best Startup Employer in America by Forbes. Check out the latest Whatnot updates on our news and engineering blogs and join us as we enable anyone to turn their passion into a business and bring people together through commerce.
💻 Role
The Application Security Team at Whatnot helps protect the products and systems that buyers and sellers rely on every day. We partner with product and engineering teams to identify risks, resolve vulnerabilities, and build security into how we develop software. Our work spans web and mobile applications, combining hands-on security reviews with reusable patterns and automated tooling that help teams ship securely.
As An Application Security Engineer, You Will
- Perform security-focused code reviews, identifying vulnerabilities and recommending practical fixes.
- Partner with product and engineering teams on threat modeling and application security reviews.
- Help teams reproduce, triage, and address security vulnerabilities in web and mobile applications.
- Support our bug bounty program by investigating reports and working with teams on remediation.
- Support the preparation of security releases.
- Help develop security patterns, processes, and automated tooling that prevent entire classes of security issues.
We offer flexibility to work from home or from one of our global office hubs, and we value in-person time for planning, problem-solving, and connection. Team members in this role must live within commuting distance of our Krakow hub.
👋 You
People who do well at Whatnot tend to be comfortable figuring things out as they go, biased toward action, and genuinely curious about what they're building. They care more about outcomes than credit and stay close to the product and the people using it.
As our next Application Security Engineer, you should have 5 years of relevant experience, plus:
- Software development experience in one or more of Python, Elixir, or JavaScript.
- The ability to review code for security vulnerabilities and work with engineers to implement effective fixes.
- An understanding of application security risks and how to identify them through threat modelling and security reviews.
- The ability to investigate, reproduce, and triage web and mobile application vulnerabilities.
- Strong communication and collaboration skills, with the ability to explain security risks and recommendations clearly to product and engineering teams.
- A practical approach to problem-solving and an interest in building reusable tools and processes that help prevent security issues.
Please note: Whatnot will only contact you through official @whatnot.com email addresses. If you see an email impersonating a Whatnot recruiter, please disregard and report it as spam.
💛 EOE
Whatnot is proud to be an Equal Opportunity Employer. We value diversity, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, parental status, disability status, or any other status protected by local law. We believe that our work is better and our company culture is improved when we encourage, support, and respect the different skills and experiences represented within our workforce.
JobMatch aggregates public listings. Always apply through the original posting.