
Senior Application Security Engineer
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in Spain.
• Serve as the Application Security Subject Matter Expert, collaborating with Engineering and Product teams to integrate security throughout the Software Development Life Cycle (SDLC).
• Oversee application security assessments, threat modeling, code evaluations, and penetration testing initiatives.
• Design, implement, and automate security controls within CI/CD pipelines, incorporating SAST, SCA, and various AppSec tools.
• Steer the technical direction of the Application Security program.
• Enhance and manage application security controls, including Web Application Firewalls (WAF), Kubernetes security, and vulnerability management processes.
• Provide mentorship to Security Champions and junior engineers.
• Establish and convey Application Security metrics to evaluate risk mitigation and program efficacy.
• 3–4 years of experience in Information Security, with a minimum of 2 years focused on Application Security.
• Extensive experience with Secure SDLC, threat modeling, application security assessments, and secure code evaluations.
• Practical experience with SAST, SCA, and automated security testing integrated into CI/CD workflows.
• Strong familiarity with OWASP Top 10, OWASP ASVS, API Security, and best practices for secure coding.
• Experience in implementing and managing WAF solutions.
• Background in conducting internal penetration testing, including APIs with Burp Suite.
• Comprehensive understanding of Kubernetes security, cloud-native applications, and networking fundamentals (HTTP, HTTPS, TCP/IP).
• Basic scripting or programming knowledge, preferably in Python.
• Exceptional communication skills with the ability to influence both technical and non-technical stakeholders.
• Competitive pay
• Meaningful benefits
• Equal Opportunity Employer
Avnet
Teradyne
Intetics
New Charter Technologies
Get handpicked remote jobs straight to your inbox weekly.