Application Security Engineer (f/m/d)

Meyandy LLC

Berlin

Hybrid

EUR 85.000 - 110.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine komplette Bewerbung in einer Minute — maßgeschneiderter Lebenslauf und Anschreiben, versandbereit.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Meyandy LLC in Berlin is seeking an experienced AppSec leader to establish and drive an integrated application security program within the Product and Technology department. You will evangelize security, partner with engineers and product managers, and lead threat modelling, secure SDLC work, and vulnerability lifecycle management.

As part of the core security team, you will redesign the training program, create a Security Champions program, and scale a DevSecOps mindset across the organization

Qualifikationen

  • 5+ years in application security, product security or related technical roles.
  • Experience working directly with software engineers and product managers to secure web applications.
  • Experience in working within an Agile environment.
  • Good working proficiency in spoken and written English.
  • Excellent interpersonal skills and ability to clearly communicate at every level of the organisation.
  • Mentorship and training skills.
  • Ability to work across two different departments with multiple touch points.

Aufgaben

  • Secure the SDLC: Integrate security tooling into CI/CD pipelines and IDEs; automate checks to fix issues early.
  • Threat modelling & secure design: Conduct design-phase threat modelling sessions and reviews.
  • Code & architecture reviews: Guide developers on secure coding and remediation.
  • Vulnerability lifecycle management: Identify, triage, track, and report vulnerabilities; support bug bounty.
  • AI/ML & LLM security: Guide secure development and manage prompt injection risks.
  • Incident response collaboration: Support investigations and post-incident reviews.
  • Security culture & enablement: Act as a security champion and deliver trainings and workshops.
  • Research & innovation: Stay ahead of threats and prototype AI-driven security improvements.

Kenntnisse

AppSec
Team leadership
Threat modelling
Secure coding
CI/CD security
Mentorship
English proficiency

Tools

SAST
DAST
Dependency scanning
CI/CD tooling

Jobbeschreibung

Purpose of Position

Your role is to establish and lead an AppSec program within the Product and Technology department, acting as an evangelist for AppSec, trusted by engineers and managers alike.

As a member of the core security team, you will engage in assessing application design proposals, to identify improvements to enable our engineers to create secure products.

You will own the existing training program, redesign it to better equip engineers with the knowledge needed to develop secure applications, and create a Security Champions program to scale and embed a DevSecOps mindset across P&T.

What you'll be responsible for

  • Secure the SDLC: Integrate security tooling (e.g. SAST, DAST, dependency scanning) into CI/CD pipelines and IDEs. Automate and optimise checks so teams can identify and fix issues early and efficiently.
  • Threat modelling & secure design: Collaborate with product and engineering teams during the design phase to conduct threat modelling sessions and pre-implementation security reviews.
  • Code & architecture reviews: Guide developers on secure coding practices, perform targeted code reviews, and help resolve vulnerabilities with actionable remediation support.
  • Vulnerability lifecycle management:
    • Identify, triage, track and report on vulnerabilities across internal and external apps and systems.
    • Collaborate with engineers to close gaps efficiently.
    • Support the bug bounty process with finding validation.
    • Present vulnerability management reports to our heads of department.
  • AI/ML & LLM security:
    • Provide guidance on secure development of AI/LLM-powered features.
    • Help teams manage risks such as prompt injection, model misuse, and data leakage.
    • Lead threat modelling exercises for AI components and advise on secure integration patterns.
  • Incident response collaboration: Support investigation and root cause analysis of application-layer incidents. Contribute to post-incident reviews and longer-term mitigation strategies.
  • Security culture & enablement:
    • Act as a security champion for development teams.
    • Be an enthusiastic and vocal advocate for application security across all engineering and product teams.
    • Nurture and report on our application security training program for our code contributors.
    • Deliver workshops and technical deep-dives on secure development practices.
    • Contribute to playbooks, documentation, and internal standards.
  • Research & innovation:
    • Stay ahead of industry threats and attack trends. Propose and test innovative ideas to reduce risk across our software supply chain and platforms.
    • Showcase how to use AI and AI-powered tools to enhance productivity and improve our security posture.

Your skills

  • 5+ years in application security, product security or related technical roles.
  • Experience working directly with software engineer and product managers to secure web applications.
  • Experience in working within an Agile environment.
  • Good working proficiency in spoken and written English.
  • Excellent interpersonal skills and ability to clearly communicate at every level of the organisation.
  • Mentorship and training skills.
  • Ability to work across two different departments with multiple touch points.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Application Security Engineer (w/d/m)
Application Security Engineer (w/d/m)

Diamant Software GmbH & Co. KG • Bielefeld

Hybrid
EUR 70.000 - 110.000
Application Security Engineer (m/w/d)
Application Security Engineer (m/w/d)

Bundesdruckerei Gruppe GmbH • Berlin

Vor Ort
EUR 70.000 - 100.000
Senior IT Security Consultant (m/f/d) new
Senior IT Security Consultant (m/f/d) new

beON consult GmbH • Kiel

Vor Ort
EUR 60.000 - 90.000
Attractive financial compensation
Comprehensive development opportunities
Healthy work-life balance
+2
Application Security Engineer (m/f/d) in Konstanz or Berlin
Application Security Engineer (m/f/d) in Konstanz or Berlin

KNIME AG • Berlin

Hybrid
EUR 65.000 - 85.000
Subsidized gym memberships
Flexible working hours
Continuous learning opportunities
Application Security Engineer (all genders)
Application Security Engineer (all genders)

JobCubby • Hamburg

Hybrid
EUR 65.000 - 75.000
Senior Application Security Engineer (all genders)
Senior Application Security Engineer (all genders)

Meyandy LLC • Berlin

Hybrid
EUR 90.000 - 130.000
Remote-friendly policy
International opportunities
Office Berlin HQ
Senior Application Security Engineer (all genders)
Senior Application Security Engineer (all genders)

Jackalope Digital LLC • Berlin

Hybrid
EUR 90.000 - 130.000
Remote-first
HQ Berlin office
Flexible work policy
+1
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

EPAM • Deutschland

Hybrid
EUR 70.000 - 90.000
Application Security Engineer (all genders)
Application Security Engineer (all genders)

ABOUT YOU SE & Co. KG • Berlin

Vor Ort
EUR 65.000 - 75.000
Application Security Engineer (f/m/d)
Application Security Engineer (f/m/d)

JobCubby • Berlin

Hybrid
EUR 85.000 - 110.000
Flexi-Week
Hybrid/Remote work
Work expense contribution
+4