Whatnot logo

Application Security Engineer

Whatnot

Kraków, Lesser Poland Voivodeship, Poland · HybridFull-timeSeen 2 days agoStill listed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Kraków, Lesser Poland Voivodeship, PolandHybrid
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

Whatnot’s Application Security Team partners with product and engineering teams to identify risks, resolve vulnerabilities, and build security into software development. The role spans web and mobile applications, including hands-on security reviews, bug bounty investigations, security releases, and reusable patterns and automated tooling. Team members must live within commuting distance of the Krakow hub, with flexibility to work from home or a global office hub.

Skills & qualifications

RequiredNice to have

Skills

Software DevelopmentPythonElixirJavaScriptSecurity Code ReviewVulnerability RemediationApplication SecurityThreat ModelingSecurity ReviewsVulnerability InvestigationVulnerability TriageCommunicationCollaborationProblem Solving

Qualifications

5 Years Relevant Experience

Full job description

🚀 Join the Future of Commerce with Whatnot! Whatnot is the largest live shopping platform in North America and Europe to buy, sell, and discover the things you love. Whether it's trading cards, fashion, electronics, or live plants, our sellers are building real businesses across hundreds of categories. We're building live commerce at a scale that's never been done in the West, and there's no playbook to copy. The people here are shaping how an entirely new industry develops. As a remote co-located team, we're inspired by our values and anchored in hubs across the US, UK, Ireland, Poland, Germany, and Australia. We move fast, stay close to our users, and focus on the work that drives the most impact. We're one of the fastest growing marketplaces and were recently named the #1 Best Startup Employer in America by Forbes. Check out the latest Whatnot updates on our news and engineering blogs and join us as we enable anyone to turn their passion into a business and bring people together through commerce. 💻 Role The Application Security Team at Whatnot helps protect the products and systems that buyers and sellers rely on every day. We partner with product and engineering teams to identify risks, resolve vulnerabilities, and build security into how we develop software. Our work spans web and mobile applications, combining hands-on security reviews with reusable patterns and automated tooling that help teams ship securely. As an Application Security Engineer, you will:

  • Perform security-focused code reviews, identifying vulnerabilities and recommending practical fixes.

  • Partner with product and engineering teams on threat modeling and application security reviews.

  • Help teams reproduce, triage, and address security vulnerabilities in web and mobile applications.

  • Support our bug bounty program by investigating reports and working with teams on remediation.

  • Support the preparation of security releases.

  • Help develop security patterns, processes, and automated tooling that prevent entire classes of security issues.

We offer flexibility to work from home or from one of our global office hubs, and we value in-person time for planning, problem-solving, and connection. Team members in this role must live within commuting distance of our Krakow hub.

👋 You People who do well at Whatnot tend to be comfortable figuring things out as they go, biased toward action, and genuinely curious about what they're building. They care more about outcomes than credit and stay close to the product and the people using it. As our next Application Security Engineer, you should have 5 years of relevant experience, plus:

  • Software development experience in one or more of Python, Elixir, or JavaScript.

  • The ability to review code for security vulnerabilities and work with engineers to implement effective fixes.

  • An understanding of application security risks and how to identify them through threat modelling and security reviews.

  • The ability to investigate, reproduce, and triage web and mobile application vulnerabilities.

  • Strong communication and collaboration skills, with the ability to explain security risks and recommendations clearly to product and engineering teams.

  • A practical approach to problem-solving and an interest in building reusable tools and processes that help prevent security issues.

Please note: Whatnot will only contact you through official @whatnot.com email addresses. If you see an email impersonating a Whatnot recruiter, please disregard and report it as spam. 💛 EOE Whatnot is proud to be an Equal Opportunity Employer. We value diversity, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, parental status, disability status, or any other status protected by local law. We believe that our work is better and our company culture is improved when we encourage, support, and respect the different skills and experiences represented within our workforce.

You've read the whole posting — now see how you match it.