- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- vor 18 Stunden
- Work mode
- In office
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
This isn't just a maintenance role – it is a blank canvas to build, scale, and architect a state-of-the-art AppSec program from the ground up. We are currently operating at a fraction of our ultimate potential, which means you have an immense, blank-canvas opportunity to fundamentally shape our security culture, processes, and tooling across the entire global engineering organization.
You will drive the entire AppSec lifecycle: from offensive red teaming and threat modeling to risk-based vulnerability management and pioneering a true shift-left culture.
What Makes This Role Challenging and Engaging:
-
High-Impact Technical Environment: You won't just follow blueprints; you will holistically influence a shift-left architecture across both application and platform layers.
-
Modern Technology Stack: Dive into securing a massive TypeScript monolith alongside Go supporting services, giving you hands-on experience in modern language security and advanced GitHub CI/CD pipeline hardening.
-
Web and API: secure the application of the vivenu platform which provides customers with an out-of-the-box ticketing software as well as the underlying API structure
-
Complex Multi-Cloud Architecture: Challenge your skills against a sophisticated multi-tenant, multi-region environment spanning k8s, GCP (our primary compute) and and separate database services
-
Cutting-Edge Deployment: Secure a next-gen Kubernetes "satellite architecture" utilizing hardened private compute nodes, VPC peering, and Argo CD for GitOps—a true, modern cloud-native security mandate.
As a Senior Security Engineer - AppSec (d/f/m) your responsibilities will include:
Be a Trusted Advisor: Partner closely with engineering teams to champion security-by-design and elevate our overall security posture. Offensive & Defensive Testing: Coordinate and execute threat modeling and advanced security tests across our product and underlying infrastructure. Lead Next-Gen Vulnerability Management: Drive triage and remediation using modern, risk-based principles like EPSS, while leveraging AI technologies to accelerate security testing at scale. Pioneer Security-as-Code: Design, implement, and automate security checks and guardrails (SAST, DAST, and secret scanning) directly into CI/CD pipelines. Review & Refine: Perform deep-dive code and configuration reviews, advocating for secure coding practices that support a proactive shift-left strategy.
What you will need to succeed in this role:
Experience: 5+ years of dedicated Security Engineering experience, ideally within a high-growth SaaS, E-commerce, or Fintech environment. SaaS Deep-Dive: The ability to dive deep into the business logic of a complex SaaS application to uncover and verify elusive attack vectors. Web and API Security Mastery: a deep understanding of web/API attack vectors and scalable best practices and how to run workloads securely in a cloud environment (k8s, AWS/GCP/Azure) Ownership: A proven track record of autonomously driving security initiatives from conception to completion. Automation Mindset: Proficiency in at least one programming language for scripting and security tool development (bonus points for automating GRC evidence collection). Education: A Bachelor’s or Master’s degree in Computer Science, Cybersecurity, IT, or a related technical field (or equivalent practical experience).