Application Security - Vulnerability Discovery

Jobgether

Deutschland

Vor Ort

EUR 85.000 - 110.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

Fully remote work
Large-scale security initiatives
Flexible work environment
Collaboration with distributed teams
Competitive compensation

Zusammenfassung

Remotely in Germany seeks an Application Security – Vulnerability Discovery Engineer to identify, analyze, and reduce vulnerabilities across modern software environments. You will collaborate with engineering and product teams to strengthen security across the software development lifecycle.

The role emphasizes automation, security research, and guiding remediation with a proactive mindset. You will work with AI-powered tools, review code changes, and help scale secure development practices

Qualifikationen

  • 3 years of experience in application security engineering or related security role.
  • Availability to work until 11:00AM PST.
  • Strong understanding of application security principles and secure SDLC practices.
  • Experience building and scaling SDLC security programs.
  • Hands-on with vulnerability reports, bug bounty findings, and security assessments.
  • Experience partnering with engineering and product teams to drive security improvements.
  • Experience triaging vulnerabilities from SAST/DAST/SCA and related assessments.
  • Knowledge of OWASP Top10, API security, auth, authorization, secrets management, and cryptography.
  • Experience reviewing source code across modern languages and frameworks.
  • Familiarity with SAST/DAST/SCA, IaC scanning, secrets detection, and vuln management platforms.
  • Experience with AWS or other public clouds.
  • Strong communication and collaboration skills.
  • Familiarity with AI-assisted development or LLM-based security tools is a plus.

Aufgaben

  • Triage, validate, prioritize, and manage vulnerabilities from manual and automated sources.
  • Drive remediation with engineering and product teams, providing actionable guidance.
  • Review security-related PRs and secure coding practices.
  • Analyze findings from AI-powered tools, reduce false positives, improve workflows.
  • Participate in security incident response, investigations, and root cause analysis.
  • Support and enhance secure SDLC practices across engineering orgs.
  • Develop tooling, automation, and workflows to improve detection and coverage.
  • Configure, optimize, and maintain vulnerability scanning platforms.
  • Track remediation progress and risk reduction metrics for stakeholders.
  • Collaborate with security architecture and development teams on strategies.
  • Create security documentation, best practices, and educational resources.
  • Participate in on-call rotation for security triage and reviews.

Kenntnisse

Vulnerability management
Application security
SDLC security
Threat modeling
Security automation
AI-powered security tools
Cloud security (AWS)
Bug bounty collaboration

Tools

SAST
DAST
SCA
IaC scanners
Secrets detection tooling
Vulnerability management platforms

Jobbeschreibung

Overview

Application Security – Vulnerability Discovery Engineer based in Germany. This role focuses on strengthening application security by identifying, analyzing, and reducing vulnerabilities across modern software environments. You will collaborate with engineering and product teams to improve security practices throughout the software development lifecycle. The position combines vulnerability management, secure coding expertise, automation, and security research to protect critical applications. You will play a key role in validating security findings, guiding remediation efforts, and improving security processes at scale. The ideal candidate will bring strong technical skills, a proactive mindset, and the ability to partner effectively with development teams. This is an opportunity to contribute to impactful security initiatives while helping build safer, more resilient products.

Accountabilities
  • Triage, validate, prioritize, and manage security vulnerabilities discovered through manual reviews, automated security tools, bug bounty programs, and AI‑assisted security platforms.
  • Partner with software engineering and product teams to drive remediation efforts, provide actionable security guidance, and ensure timely resolution of findings based on risk and severity.
  • Review security‑related pull requests, source code changes, and development workflows to identify vulnerabilities and recommend secure implementation approaches.
  • Analyze findings generated by AI‑powered security tools and automation platforms, reduce false positives, and improve vulnerability detection workflows.
  • Participate in security incident response activities, investigations, and root cause analysis related to application security issues.
  • Support and enhance secure software development lifecycle (SDLC) practices across engineering organizations.
  • Develop security tooling, automation, and workflows to improve vulnerability detection, security coverage, and operational efficiency.
  • Configure, optimize, and maintain vulnerability scanning platforms, including policies, schedules, and reporting processes.
  • Track remediation progress, security metrics, and risk reduction initiatives while providing visibility to stakeholders.
  • Collaborate with security architecture and development teams to improve vulnerability discovery, prioritization, and remediation strategies.
  • Create security documentation, best practices, and educational resources to promote secure coding practices across teams.
  • Participate in an on‑call rotation to support security triage, code reviews, and application security requests.
Requirements
  • 3years of experience in application security engineering or a related security role.
  • Availability to work until 11:00AM Pacific Standard Time (PST).
  • Strong understanding of application security principles, vulnerability management, and secure software development practices.
  • Experience building and scaling Secure Development Lifecycle (SDLC) programs.
  • Hands‑on experience handling vulnerability reports, bug bounty findings, and security assessments.
  • Experience partnering with engineering and product teams to drive security improvements and remediation initiatives.
  • Experience triaging and prioritizing vulnerabilities from SAST, DAST, SCA, dependency scanning, penetration testing, and similar security assessments.
  • Strong knowledge of common application security risks, including OWASP Top10, API security, authentication, authorization, secrets management, and cryptography.
  • Experience reviewing source code and identifying vulnerabilities across modern programming languages and frameworks.
  • Familiarity with security tools such as SAST, DAST, SCA, infrastructure‑as‑code scanning, secrets detection, and vulnerability management platforms.
  • Experience working with cloud‑native architectures and public cloud environments, preferably AWS.
  • Ability to evaluate security findings, identify meaningful risks, and communicate clear remediation recommendations.
  • Strong communication, collaboration, and relationship‑building skills.
  • Familiarity with AI‑assisted development workflows, AI‑powered security tools, or LLM‑based security applications is a plus.
Benefits
  • Fully remote work opportunity.
  • Opportunity to contribute to large‑scale application security initiatives.
  • Flexible work environment supporting collaboration with distributed teams.
  • Ability to work on modern security challenges involving cloud, automation, and AI‑powered security technologies.
  • Opportunity to influence secure development practices across engineering organizations.
  • Exposure to advanced vulnerability management processes and security tooling.
  • Professional growth opportunities within a technology‑focused environment.
  • Opportunity to collaborate with experienced security, engineering, and product professionals.
  • Competitive compensation package based on experience and expertise.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Application Security Engineer (m/f/d) in Konstanz or Berlin
Application Security Engineer (m/f/d) in Konstanz or Berlin

KNIME AG • Berlin

Hybrid
EUR 65.000 - 85.000
Subsidized gym memberships
Flexible working hours
Continuous learning opportunities
Senior Product Security Engineer
Senior Product Security Engineer

United States Digital Space LLC • Dresden

Hybrid
EUR 90.000 - 130.000
Competitive LTIP
Hybrid work option
Vacation days + float holiday
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

EPAM • Deutschland

Hybrid
EUR 70.000 - 90.000
Application Security Engineer (Berlin/hybrid)
Application Security Engineer (Berlin/hybrid)

United States Digital Space LLC • Berlin

Hybrid
EUR 60.000 - 85.000
Competitive salary
Company pension with 20% top-up
Monthly budget for benefits
+2
Security Engineer, Application Security
Security Engineer, Application Security

Openai • Deutschland

Hybrid
EUR 70.000 - 100.000
Relocation assistance
Hybrid work model
Senior Product Security Engineer
Senior Product Security Engineer

United States Digital Space LLC • Chemnitz

Hybrid
EUR 80.000 - 110.000
LTIP (unit-based Long Term Incentive  
Hybrid work option
Yearly flex work allowance €1560
+4
Application Security Engineer (all genders)
Application Security Engineer (all genders)

ABOUT YOU SE & Co. KG • Berlin

Vor Ort
EUR 65.000 - 75.000
Application Security Developer – AppSec - Berlin – €90,000–100,000
Application Security Developer – AppSec - Berlin – €90,000–100,000

Findr • Berlin

Vor Ort
EUR 90.000 - 100.000
Real influence on product security
Freedom to innovate
Supportive leadership
+1
Senior Product Security Engineer
Senior Product Security Engineer

United States Digital Space LLC • Berlin

Hybrid
EUR 70.000 - 95.000
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

EPAM Systems • Berlin

Hybrid
EUR 90.000 - 130.000
30 days holiday
Company Pension Scheme
Regular performance assessments
+5