Назад
1 день назад

Application Security Engineer (AppSec)

Формат работы
remote (только Spain)/hybrid
Тип работы
fulltime
Грейд
middle
Английский
c1
Страна
Spain

Мэтч & Сопровод

Покажет вашу совместимость и напишет письмо

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (AppSec) (SaaS/Cybersecurity): Securing Contentsquare’s global SaaS applications through automated audits, threat modeling, code reviews, vulnerability management, and incident response with an accent on cloud-native infrastructure, AI-driven security workflows, and developer-focused security automation. Focus on integrating security-as-code into CI/CD pipelines, coordinating bug bounty and penetration testing programs, and solving complex application vulnerabilities across AWS, Azure, Kubernetes, and modern web frameworks.

Location: Barcelona, Spain. The role works out of the Barcelona office, with hybrid and remote work policies available.

Company

Contentsquare provides a scalable SaaS experience intelligence platform that helps organizations understand their customers’ digital journeys.

What you will do

  • Conduct continuous automated security audits of global SaaS applications and identify configuration issues and vulnerabilities.
  • Partner with product and engineering teams on threat modeling, AppSec reviews, secure code reviews, and secure coding practices.
  • Design and manage vulnerability triage, reporting, remediation tracking, and security automation across cloud and application layers.
  • Build AI- and LLM-driven security workflows for vulnerability discovery and validation in CI/CD pipelines.
  • Lead shift-left security initiatives and develop security-as-code tools for engineering teams.
  • Manage bug bounty programs, external penetration tests, customer security assessments, and application-level incident response.

Requirements

  • 3+ years of professional experience in Application Security Operations in a high-growth SaaS or cloud-native environment.
  • Advanced experience securing NestJS, Vue.js, and Angular applications.
  • Experience with Snyk, Datadog ASM/AppSec, Google SecOps, and CrowdStrike.
  • Strong knowledge of AWS, Azure, Kubernetes, Docker, Terraform, web protocols, OWASP Top 10, MITRE ATT&CK, and NIST CSF.
  • Proficiency in Python, Node.js, and Shell for security tooling and integrations, plus practical experience applying AI and LLM technologies to security tasks.
  • Fluent English is mandatory. Experience in ethical hacking, CTF competitions, or bug bounty hunting is required.

Culture & Benefits

  • Hybrid and remote work policies with virtual onboarding and annual hackathons.
  • Career development, mentorship, social events, and philanthropic activities.
  • Generous paid time off and a lifestyle allowance.
  • Country-specific benefits and employee resource groups.
  • Full-time employees receive stock options.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →