Назад
Company hidden
15 минут назад

Senior Security Engineer - AppSec (d/f/m)

Формат работы
remote (только Germany)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Germany
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer - AppSec (d/f/m) (SaaS and live entertainment technology): Building and scaling an application security program for an API-first ticketing platform with an accent on threat modeling, vulnerability management, and shift-left security. Focus on securing TypeScript and Go services, hardening Kubernetes and CI/CD infrastructure, and designing automated SAST, DAST, and secret-scanning guardrails across a multi-cloud environment.

Location: Remote Germany

Company

hirify.global provides an API-first ticketing platform for live entertainment brands, supporting more than 10 million end users and over 1 billion requests per month.

What you will do

  • Build, scale, and architect the AppSec program across the global engineering organization.
  • Partner with engineering teams to promote security-by-design and a shift-left architecture across application and platform layers.
  • Coordinate threat modeling, red teaming, penetration testing, and other security tests across products and infrastructure.
  • Lead risk-based vulnerability triage and remediation using approaches such as EPSS and AI-assisted security testing.
  • Design and automate SAST, DAST, and secret-scanning checks and guardrails in CI/CD pipelines.
  • Perform detailed code and configuration reviews and promote secure coding practices.

Requirements

  • 5+ years of dedicated Security Engineering experience, ideally in a high-growth SaaS, e-commerce, or fintech environment.
  • Strong understanding of web and API attack vectors and secure cloud workloads, including Kubernetes and AWS, GCP, or Azure.
  • Experience analyzing complex SaaS business logic to identify and validate attack vectors.
  • Proficiency in at least one programming language for scripting and security tool development.
  • Experience independently driving security initiatives from conception to completion.
  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, IT, or a related technical field, or equivalent practical experience.

Nice to have

  • Experience with PCI DSS script security.
  • Red Team or Purple Team operations and advanced penetration testing.
  • Hands-on Terraform experience for securing infrastructure as code.
  • Familiarity with GCP, Golang, and TypeScript.
  • Experience automating GRC evidence collection.

Culture & Benefits

  • Remote work from Germany within a fast-growing live entertainment technology company.
  • Opportunity to shape security culture, processes, and tooling from the ground up.
  • Work with a multi-tenant, multi-region cloud architecture using Kubernetes and GCP.
  • Exposure to a modern Kubernetes satellite architecture with private compute nodes, VPC peering, and Argo CD GitOps.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →