Senior Information Security Engineer - Application Security

Camunda

St. Pölten

Remote

EUR 143.800 - 231.900

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

Flexible time off
Home office budget
Professional growth allowance

Zusammenfassung

Camunda is seeking a Senior Information Security Engineer (AppSec) to enhance security across our development lifecycle. This role involves close collaboration with engineering teams to embed security by design, lead vulnerability management, and support application security incidents.

The ideal candidate has extensive Java experience and a solid understanding of secure SDLC, architecture, and coding practices. Join our innovative team in transforming how security is integrated into modern cloud applications.

Qualifikationen

  • Substantial hands-on experience building Java services in CI/CD.
  • Experience with secure design reviews and threat modeling.
  • Comfortable managing security incidents and escalations.

Aufgaben

  • Partner with engineering teams to embed security by design.
  • Lead and evolve AppSec tooling and workflows.
  • Drive vulnerability management for applications and supply chain.

Kenntnisse

Strong Software engineering and secure coding background
Vulnerability management & security tooling expertise
Cross‑team collaboration & communication skills
Developer‑centric, incident‑savvy mindset

Tools

Java
Python
JavaScript
TypeScript
Kubernetes

Jobbeschreibung

About the Role

As a Senior Information Security Engineer (AppSec) at Camunda, you’ll join a small, senior, and highly collaborative InfoSec team that lives our FAITH values – Focus, Ambition, Integrity, Talent and Humor – every day. You’ll work hand‑in‑hand with our product and engineering teams across the entire SDLC to ensure our platform is designed, built, and shipped securely as we continue to grow. This is a technical, hands‑on, developer‑centric role where you’ll shape how we build secure Java services in a modern CI/CD, SaaS environment, strengthen our AppSec tooling and practices, and directly influence how customers trust and adopt Camunda. You can be based anywhere that allows you to collaborate effectively within CET to Eastern Time working hours.

What You’ll Be Doing
  • Partner with engineering teams throughout the SDLC – from early design and architecture discussions, through implementation and testing, to deployment – to embed security by design in our products.
  • Lead and evolve our AppSec tooling and workflows by implementing, tuning, and integrating SAST, DAST, SCA, and container/image scanning into CI/CD pipelines, and making sure findings are actionable for developers.
  • Drive vulnerability management for our applications and supply chain, including triaging and prioritizing issues, coordinating with teams on fix/mitigate/accept decisions, and ensuring we continuously improve our security posture.
  • Perform secure design and architecture reviews and threat modeling for distributed, API‑ and microservices‑based systems, helping teams understand security trade‑offs and make sound, risk‑based decisions.
  • Support and help coordinate application‑layer security incidents and escalations, working closely with Engineering, Support, and other stakeholders to investigate, contain, and learn from issues.
  • Together with the rest of the InfoSec team, help with security audits, customer assurance, and other processes.
What You Bring
  • Ability and/or willingness to use our product.
  • Strong Software engineering and secure coding background, with substantial recent hands‑on experience building and reviewing Java services, working in CI/CD environments, and shipping SaaS or other cloud‑based applications securely.
  • Secure SDLC, architecture & risk assessment experience, including secure design reviews, threat modeling for distributed/API/microservices systems, and performing risk assessments on product changes or new features.
  • Vulnerability management & security tooling expertise, with a proven track record of implementing and tuning SAST/DAST/SCA and container/image scanning, evaluating and triaging findings (including false positives), and driving fix/mitigate/accept decisions with engineering teams.
  • Cross‑team collaboration & communication skills, enabling you to work effectively with Engineering, Support, Sales, and other stakeholders while explaining complex security issues and trade‑offs in a clear, pragmatic way to both technical and non‑technical audiences.
  • Developer‑centric, incident‑savvy mindset, meaning you are comfortable managing and supporting security incidents and escalations, you see yourself as an enabler (not a gatekeeper), and you influence teams toward risk‑based, practical security improvements.
Nice‑to‑haves
  • Experience developing in Python, JavaScript, or TypeScript in addition to Java.
  • Hands‑on experience securing Kubernetes‑ or container‑based workloads and modern cloud environments.
  • Prior work in a B2B software company, especially in high‑availability or multi‑tenant contexts.
  • Experience running security training, talks, or workshops for engineering teams.
Compensation

We offer competitive, fair, and transparent compensation. Salary ranges are location‑based, with Standard and Major markets (global tech hubs) reflecting local competition.

The Annual Total Target Cash (base salary + 100% variable target, where applicable) shown below spans from the minimum in a Standard market to the maximum in a Major market. Final offers depend on skills, experience, and location, and we typically hire in the first half of the range to allow room for growth.

  • United States: $143,800.00 to $231,900.00
  • United Kingdom: £90,300.00 to £148,500.00
  • Singapore: S$178,600.00 to S$267,900.00

If you’re based elsewhere, you’ll be hired via Remote.com (our global employer partner), and your Talent Acquisition Partner will provide a personalized Total Rewards Calculator after your first interview.

Equity: We also offer equity (where applicable) through our Virtual Stock Option Plan (VSOP).

Benefits & Perks
  • Remote & Flexible: Work from anywhere with the setup that suits you, home office budget, co‑working space support, and flexible time off to recharge when you need it.
  • In Person Connection: We invest in meaningful face time through our Annual Kickoff (Vienna in 2025, Madrid in 2026!), team offsites, and Camundi Connection Budgets, including contributing to meetups while travelling, and local gatherings with fellow Camundi.
  • Health & Wellbeing: Access locally tailored healthcare, Modern Health for global mental wellbeing, and our Live Well Lifestyle Spending Account (LSA), a flexible, global benefit that puts you in control of your whole life, not just work, from staying active, to caring for family, exploring personal passions, meaningful experiences, and investing in your financial wellbeing. The Live Well program launches in 2026 and scales to €1,000 annually from 2027.
  • Financial Security: Retirement and pension plans (often with company contributions), plus life and disability insurance where relevant.
  • Professional Growth: Up to €1,000 per year for self‑driven learning: courses, certifications, books, you decide!

Everyone is welcome at Camunda — it’s a celebrated component of our culture. We strive to create an inclusive environment that empowers our people. At Camunda, we honour diverse cultures and backgrounds and are proud to be an equal opportunity employer. All qualified applicants will receive consideration without regard to gender, race, ethnicity, religion, belief, sexual orientation, age, disability or any other protected characteristics under applicable law. We are looking forward to your application!

AI in our hiring process

Camunda may use AI tools to aid the screening of applications and during the interview process. You can learn more here.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Corporate Account Executive - Public Sector DACH
Corporate Account Executive - Public Sector DACH

Camunda • Österreich

Vor Ort
EUR 119.000 - 198.000
Remote & Flexible Work
Health & Wellbeing Support
Professional Growth Budget
+2
Senior AppSec Engineer - Secure Java & CI/CD
Senior AppSec Engineer - Secure Java & CI/CD

Camunda • St. Pölten

Remote
EUR 143.000 - 232.000
Flexible time off
Home office budget
Professional growth allowance
Corporate Account Executive - Public Sector DACH
Corporate Account Executive - Public Sector DACH

Camunda Services GmbH • Österreich

Remote
EUR 119.000 - 198.000
Remote & Flexible work arrangements
Annual Kickoff events in different cities
Healthcare and wellness benefits
+1
Senior Cyber Security Analyst - EMEA
Senior Cyber Security Analyst - EMEA

Intuition Machines • Österreich

Remote
EUR 60.000 - 90.000
Fully remote position
Flexible working hours
Inspiring global team
+3
Security Engineer, IAM
Security Engineer, IAM

Sentry • Österreich

Vor Ort
EUR 81.000
Group health insurance
Paid time off
Equity grants
DevSecOps Engineer - Deployment Team
DevSecOps Engineer - Deployment Team

Blackshark.ai GmbH • Graz

Vor Ort
EUR 60.000 - 80.000
Learning opportunities
Mental well-being programs
Healthcare benefits
+2
AI Framework Developer, Software Engineer Advanced
AI Framework Developer, Software Engineer Advanced

Siemens • Wien

Vor Ort
EUR 71.000 - 120.000
DevSecOps Engineer
DevSecOps Engineer

Ketryx • Österreich

Hybrid
EUR 90.000 - 110.000
Competitive compensation
Generous stock options possible
Generous PTO for full-time
Senior Software Engineer, Java (EVERGREEN)
Senior Software Engineer, Java (EVERGREEN)

Bitpanda LA • Wien

Hybrid
EUR 100.000 - 140.000
Hybrid working model
Stock option plan
OpenUP coaching
+4
Software Engineer, Java (Asset Systems)
Software Engineer, Java (Asset Systems)

Bitpanda LA • Wien

Hybrid
EUR 90.000 - 130.000
Hybrid work model
Stock option plan
OpenUP mental health support
+2