Senior Application Security Engineer (SaaS)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Application Security Engineer (SaaS): Embedding security into the design, build, and operation of a subscription commerce platform with an accent on secure SDLC, threat modeling, and automated security testing. Focus on identifying vulnerabilities early in the development lifecycle and implementing secure-by-design principles across cloud-native architectures.
Location: Must be based in Spain (Remote)
Company
is a global leader in subscription commerce, providing a platform that automates and unifies subscription workflows for IT distributors and MSPs.
What you will do
- Integrate security activities across all SDLC phases, partnering closely with engineering teams to ensure secure development practices.
- Lead threat modeling sessions using STRIDE to identify attack paths, misconfigurations, and insecure design patterns.
- Perform security-focused code and architecture reviews to provide actionable guidance on secure coding patterns.
- Operate and optimize AppSec tooling (SAST, DAST, SCA, secrets scanning) and automate checks within CI/CD pipelines.
- Support incident response by contributing to triage, impact assessment, and root cause analysis for application vulnerabilities.
- Enable engineering teams through the creation of secure coding guidelines and hands-on training.
Requirements
- Strong understanding of secure software development principles and common vulnerability classes (OWASP Top 10, CWE).
- Hands-on experience with application security tools (SAST, DAST, SCA) and their integration into CI/CD pipelines.
- Proven experience in web application security testing.
- Ability to pragmatically assess risk and prioritize remediation efforts.
- Knowledge of cloud-native architectures, APIs, and microservices.
- Must be based in Spain.
Nice to have
- Exposure to security metrics, maturity models, or building AppSec programs.
Culture & Benefits
- Fully remote work with flexible working hours.
- Work-from-anywhere scheme allowing for travel and work.
- Comprehensive health and life insurance program.
- Dedicated budget for learning and professional development.
- Collaborative, tech-driven team with an international mindset.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →