Мэтч & Сопровод
Покажет вашу совместимость и напишет письмо
Описание вакансии
Текст:
TL;DR
Application Security Engineer (AppSec) (SaaS/Cybersecurity): Securing Contentsquare’s global SaaS applications through automated audits, threat modeling, code reviews, vulnerability management, and incident response with an accent on cloud-native infrastructure, AI-driven security workflows, and developer-focused security automation. Focus on integrating security-as-code into CI/CD pipelines, coordinating bug bounty and penetration testing programs, and solving complex application vulnerabilities across AWS, Azure, Kubernetes, and modern web frameworks.
Location: Barcelona, Spain. The role works out of the Barcelona office, with hybrid and remote work policies available.
Company
Contentsquare provides a scalable SaaS experience intelligence platform that helps organizations understand their customers’ digital journeys.
What you will do
- Conduct continuous automated security audits of global SaaS applications and identify configuration issues and vulnerabilities.
- Partner with product and engineering teams on threat modeling, AppSec reviews, secure code reviews, and secure coding practices.
- Design and manage vulnerability triage, reporting, remediation tracking, and security automation across cloud and application layers.
- Build AI- and LLM-driven security workflows for vulnerability discovery and validation in CI/CD pipelines.
- Lead shift-left security initiatives and develop security-as-code tools for engineering teams.
- Manage bug bounty programs, external penetration tests, customer security assessments, and application-level incident response.
Requirements
- 3+ years of professional experience in Application Security Operations in a high-growth SaaS or cloud-native environment.
- Advanced experience securing NestJS, Vue.js, and Angular applications.
- Experience with Snyk, Datadog ASM/AppSec, Google SecOps, and CrowdStrike.
- Strong knowledge of AWS, Azure, Kubernetes, Docker, Terraform, web protocols, OWASP Top 10, MITRE ATT&CK, and NIST CSF.
- Proficiency in Python, Node.js, and Shell for security tooling and integrations, plus practical experience applying AI and LLM technologies to security tasks.
- Fluent English is mandatory. Experience in ethical hacking, CTF competitions, or bug bounty hunting is required.
Culture & Benefits
- Hybrid and remote work policies with virtual onboarding and annual hackathons.
- Career development, mentorship, social events, and philanthropic activities.
- Generous paid time off and a lifestyle allowance.
- Country-specific benefits and employee resource groups.
- Full-time employees receive stock options.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →