CareerMoonshot

Application Security Specialist (regular/senior) (She/He/They)

Accenture

via workdayFirst listed here 2026-08-31
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Accenture.
WHO WE ARE: The Cyber Security team, part of Accenture Security, supports organizations in building secure, resilient, and scalable security capabilities across complex enterprise technology landscapes — integrating security into software development, cloud adoption, digital transformation, and technology modernization so that security by design and security by default are reflected in how systems are actually built and operated, not only in policy.   We act as trusted advisors to some of the world's leading organizations, helping them define pragmatic security operating models, improve security maturity, and align cybersecurity capabilities with their business and technology objectives. Working at the forefront of the industry means constant exposure to complex, high-stakes security challenges and the latest technologies — across banking, manufacturing, healthcare, retail, and public sector, each with its own regulatory context and technical scale.   As part of a global security leader, you work on engagements that span the full breadth of modern enterprise security — from securing AI-enabled systems and cloud-native architectures to embedding security into large-scale digital transformation programmed. The variety of clients, industries, and technology stacks means you are continuously challenged, and the depth of expertise around you means you are never navigating that alone. THE WORK: Assess where a client actually stands — against OWASP ASVS, OWASP Top 10, OWASP API Top 10, or CWE Top 25 — and turn the gaps into a prioritized roadmap their teams can work through.   Run threat modelling and secure design reviews with the client’s own architects and developers, across hybrid, distributed, cloud-native, containerized , microservices, event-driven, and monolithic systems.   Review code, APIs, Infrastructure as Code, and CI/CD pipelines from a security point of view — then help the teams fix what you find rather than just reporting it. That extends to building security into pipelines, build systems, and artefact repositories, and to software supply chain risk: dependencies, build integrity, SBOMs, third-party components.   Select, roll out, and tune AppSec tooling — SAST, DAST, SCA, secrets scanning — so that results are trusted and acted on rather than muted, and so security gates and automated testing hold up across the SSDLC.   Work on the security of AI-enabled systems : LLM-based applications, AI agents, model and data pipelines, and the risks that come with them — prompt injection, data poisoning, model and inference exposure, unsafe integration. That includes defining controls across the AI lifecycle, using AI-based tooling for code analysis and vulnerability triage, and supporting governance and compliance around responsible AI use.   Make it stick with the client’s people : secure coding standards and design guidance teams will actually use, guardrails for how developers use AI coding assistants, a security champions program , hands-on developer training, and presenting findings and recommendations from team leads up to CISO level.   Flexible: The work location for this role may include a mix of working remotely, onsite at a client or in an Accenture office - depending on specific project circumstances.   With all our roles, there is some in-person time for collaboration,   learning and building relationships with clients, peers, leaders,   and communities. As an employer, we will be as flexible as   possible to support your specific work/life needs.   WHAT’S IN IT FOR YOU:   Work on international cybersecurity transformation programs for some of the world's leading organizations, on security problems that are genuinely complex and unsolved at their end.   Breadth you cannot get in-house. In a single year you see how organizations across banking, manufacturing, healthcare, retail, and public sector approach the same challenges — and where they fail. That range, across Secure SDLC, Application Security, Cloud Security, Security Governance, and Enterprise Architecture, takes far longer to accumulate on a single internal team.   Constant exposure to emerging technologies, current tooling, and evolving practice — helping clients securely adopt what is new while managing risk across legacy, hybrid, and modern environments.   Room to set direction and grow as a trusted advisor. On most engagements you are the person defining what good looks like for a client — leading security discussions with technical, operational, and senior stakeholders, not implementing someone else's definition.   Collaborate with a diverse team of over 150 cybersecurity experts in Poland and thousands across the globe, in an environment focused on innovation, continuous learning, and practical business outcomes.   A wide catalogue of development opportunities: technical, soft-skills , and language training, e-learning platforms, GenAI training, and security certifications — open to everyone who wants to grow.   HERE’S WHAT YOU’LL NEED: We are looking for candidates with a solid foundation across the areas below. Hands-on experience and a working grasp of the core concepts is the baseline — specialization and depth can be developed from there. Engineering or IT background. A background in software development, architecture, or IT operations — with practical experience building, running, or designing software systems or infrastructure.   Foundational security knowledge. A sound understanding of core security principles — confidentiality, integrity, and availability — and how they apply to real systems. Familiarity with encryption, hashing, and key management at a conceptual and practical level, including common misuse patterns.   U nderstanding of the software development lifecycle. Sufficient knowledge of how software is specified, built, reviewed, tested, released, and maintained to engage credibly with development and engineering teams .   Fa

Browse all locations