← All verified jobs

HQ - Senior Application Security Engineer (Remote)

jobandtalent Madrid HQ, ESRemote

See all open roles at jobandtalent

Ghost-risk verdict

Likely real

  • 41 open roles at this company in 30 days (mass-hiring blitz)
  • no salary disclosed (correlates with ghost postings)

How we score ghost risk →

See your fit for this role and apply with a truthfully tailored résumé.

See my fit, free

About the role

Responsibilities

Act as the Application Security Subject Matter Expert (SME), partnering with Engineering and Product teams to embed security throughout the SDLC.

Lead application security reviews, threat modelling, code reviews and penetration testing to identify and mitigate security risks.

Design, implement and automate security controls across CI/CD pipelines, including SAST, SCA and other AppSec tooling.

Drive the technical roadmap of the Application Security program, improving secure development practices and scaling security initiatives across the organisation.

Improve and manage application security controls, including WAF, Kubernetes security and vulnerability management.

Mentor Security Champions and junior engineers, promoting a strong security culture across development teams.

Define and communicate meaningful Application Security metrics to measure risk reduction and program effectiveness.

A successful candidate will have

3-4 years of experience in Information Security, including at least 2 years in Application Security.

Strong experience with Secure SDLC, threat modelling, application security reviews and secure code reviews.

Hands-on experience with SAST, SCA and automated security testing integrated into CI/CD pipelines.

Strong knowledge of OWASP Top 10, OWASP ASVS, API Security and secure coding best practices.

Experience implementing and managing WAF solutions, as well as conducting internal penetration testing (including APIs using Burp Suite).

Solid understanding of Kubernetes security, cloud-native applications and networking fundamentals (HTTP, HTTPS, TCP/IP).

Basic scripting or development experience, preferably in Python.

Excellent communication skills, with the ability to influence engineering teams and explain complex security concepts to technical and non-technical stakeholders.

Stop applying to ghosts.

OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.