Назад
Company hidden
2 дня назад

Senior Application Security Engineer (Spain Only) (Cybersecurity)

Формат работы
remote (только Spain)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer (Cybersecurity): Elevating and maturing an Application Security program across a modern cloud-native SaaS environment with an accent on secure SDLC practices, DevSecOps, vulnerability management, and security-by-design. Focus on integrating SAST, DAST, dependency, container, secrets, and IaC security into CI/CD pipelines, prioritizing vulnerabilities by business risk, and influencing cross-functional engineering teams.

Location: Remote, Spain only; listed location: León, Spain

Company

hirify.global develops modern cloud-native SaaS software.

What you will do

  • Lead the evolution of the Application Security program and secure SDLC roadmap across engineering teams.
  • Establish security-by-design practices, including secure coding standards, threat modeling, and security architecture reviews.
  • Optimize GitLab and GitHub security capabilities covering SAST, DAST, dependency scanning, container scanning, secrets detection, and IaC security.
  • Embed security controls and risk-based gates into CI/CD pipelines in collaboration with DevOps and Engineering.
  • Manage vulnerability triage, prioritization, remediation SLAs, closure tracking, and executive reporting.
  • Drive cross-functional AppSec initiatives, security workshops, mentoring, documentation, and communication with technical and non-technical stakeholders.

Requirements

  • Minimum 10 years of experience in Application Security, S-SDLC/DevSecOps, Software Engineering, or Security Engineering.
  • Experience leading AppSec programs in medium or large organizations with modern SDLC, cloud-native, and SaaS environments.
  • Strong knowledge of OWASP Top 10, API security, multi-tenant application security, threat modeling, and security architecture reviews.
  • Hands-on experience with CI/CD security, SAST/DAST, SCA, secrets management, container and Kubernetes security, and IaC security; Terraform preferred.
  • Ability to understand, read, and review production-grade code and work with modern development frameworks and APIs.
  • Strong project management, executive reporting, documentation, business-risk prioritization, communication, and coordination skills.

Nice to have

  • Penetration testing, red teaming, or offensive security experience.
  • Experience with vulnerability management programs, security automation, and scripting.
  • Practical use of AI/ML tools in development or cybersecurity, including ChatGPT, Claude, or GitHub Copilot.
  • Specialized experience with GitLab or GitHub Security features.
  • CSSLP, CISSP, OSCP, GIAC, Azure, or AWS certifications.

Culture & Benefits

  • Remote work options with flexible working hours.
  • Private health insurance.
  • Flexible benefits plan for tailoring part of the compensation package.
  • Annual performance and company-results bonus.
  • Inclusive environment that values diverse experiences and perspectives.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →