12 часов назад
Application Security Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Engineer (AI) (SaaS security): Securing global SaaS applications through automated audits, threat modeling, code reviews, and vulnerability lifecycle management with an accent on cloud-native infrastructure, secure development, and AI-driven security workflows. Focus on building security-as-code tools, validating vulnerabilities with LLMs and autonomous agents, coordinating bug bounty and penetration testing programs, and responding to application-level incidents.
Location: Barcelona, Spain; hybrid work from the Barcelona office
Company
provides a global SaaS service and maintains ISO 27001 and ISO 27701 certifications, a SOC 2 Type 2 report, a private bug bounty program, SIEM, and security awareness initiatives.
What you will do
- Conduct continuous automated security audits of SaaS applications and identify misconfigurations against security benchmarks.
- Advise product and engineering teams through threat modeling, AppSec reviews, and secure coding mentorship.
- Manage the vulnerability lifecycle across application and cloud infrastructure layers, including triage, reporting, remediation tracking, and automation.
- Integrate security checkpoints and custom security-as-code tools into CI/CD pipelines, including AI-driven workflows using LLMs and autonomous agents.
- Direct bug bounty programs, coordinate external penetration tests and customer security assessments, and act as a technical contact for complex inquiries.
- Lead technical response to application security incidents and conduct root-cause analysis.
Requirements
- 3+ years of professional Application Security Operations experience in a high-growth SaaS or cloud-native environment.
- Advanced experience securing NestJS, Vue.js, and Angular applications.
- Hands-on experience with Snyk, Datadog ASM/AppSec, Google SecOps, and CrowdStrike.
- Strong knowledge of AWS, Azure, Kubernetes, Docker, Terraform, web protocols, OWASP Top 10, MITRE ATT&CK, and NIST CSF.
- Programming and scripting experience with Python, Node.js, and Shell, including custom security tooling and integrations.
- Fluent English is mandatory.
Nice to have
- Experience with ethical hacking, CTF competitions, or bug bounty hunting.
- Experience applying AI and LLM technologies to automated vulnerability validation or code analysis.
Culture & Benefits
- Work alongside cybersecurity experts and collaborate with development teams, product managers, external researchers, and other third parties.
- Contribute to initiatives designed to protect users and customers.
- is an equal opportunity employer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
52 минуты назад
Senior Infrastructure Security Engineer (Cybersecurity)
60 500 - 85 800€
2 дня назад
DevSecOps Engineer (AI Security)
3 часа назад
Cybersecurity Engineer - Internal Security (Cloud/ISO 27001)
2 часа назад
HQ - Senior Application Security Engineer (Remote)
11 часов назад
DevSecOps Engineer (AI Security)
80 000 - 100 000€
2 часа назад