Application Security Engineer (f/m/d)
Brak informacji o wynagrodzeniu
SeniorFull-time
#430893·Dodano 2 dni temu·4
Źródło: AwinTech Stack / Keywords
SecuritySDLCCI/CDArchitectureAILLMAgilePHP
Firma i stanowisko
Established in 2000, Awin is part of the Axel Springer group. The company promotes a diverse, inclusive culture and operates globally with offices in Berlin, Madrid, Milan, Warsaw, and Iasi. The role is within the Product, Research & Development department.
Wymagania
- 5+ years of experience in application security, product security, or related technical roles.
- Experience working directly with software engineers and product managers to secure web applications.
- Experience in Agile environments.
- Good working proficiency in spoken and written English.
- Excellent interpersonal and communication skills at all organizational levels.
- Skills in mentorship and training.
- Ability to work across two different departments with multiple touch points.
- Coding proficiency in JavaScript, PHP, and Python.
- Experience with Cloud Native environments, specifically AWS, containers, and Terraform.
- Hands-on experience with DAST, SAST, and Software Composition Analysis (SCA) tools, including reporting and dashboarding platforms.
Obowiązki
- Secure the SDLC by integrating security tooling such as SAST, DAST, and dependency scanning into CI/CD pipelines and IDEs, automating and optimizing checks.
- Conduct threat modelling sessions and pre-implementation security reviews with product and engineering teams.
- Guide developers on secure coding practices, perform targeted code and architecture reviews, and help resolve vulnerabilities.
- Manage vulnerability lifecycle: identify, triage, track, and report vulnerabilities across internal and external applications and systems.
- Collaborate with engineers to close security gaps efficiently and support the bug bounty process via finding validation.
- Present vulnerability management reports to leadership.
- Provide guidance on secure development of AI/ML and LLM-powered features, managing risks like prompt injection, model misuse, and data leakage.
- Lead threat modelling exercises for AI components and advise on secure integration patterns.
- Support incident response collaboration by assisting investigation and root cause analysis of application-layer incidents and contributing to post-incident reviews.
- Act as a security champion and advocate for application security across engineering and product teams.
- Nurture and report on the application security training program, including delivering workshops and technical deep-dives.
- Contribute to security playbooks, documentation, and internal standards.
- Stay ahead of industry threats and attack trends; propose and test innovative ideas to reduce risk.
- Showcase use of AI and AI-powered tools to enhance productivity and security posture.
Benefity
- Four-day Flexi-Week with one lighter or fully disconnected day per week at full pay and no reduction in annual holiday allowance.
- Hybrid/remote working flexibility promoting mutual trust and culture.
- Monthly allowance for work expenses and a remote working furniture package.
- Support for mental and physical health and wellbeing through various initiatives and sports offers.
- Access to extensive training programs via Awin Academy for professional and personal growth.
- Peer-to-peer recognition program with rewards in the form of vouchers.
- Additional country-specific benefits, including health and wellbeing offerings, discussed during interviews.
Elastyczne godziny
Opieka zdrowotna
Dofinansowanie szkoleń
Karta sportowa
Awin
11 aktywnych ofert