Cyber Security Staff Engineer - Application Security

United States Digital Space LLC

Berlin

Vor Ort

EUR 85.000 - 110.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

Home office budget
Learning & development budget €1000/yr
Competitive salary with variable pay
Monthly meal allowance
Deutschland ticket subsidy
28 vacation days + increases
Opportunity to work abroad up to 12 w/

Zusammenfassung

Solaris is seeking a security-focused engineer to weave security into the SDLC and DevSecOps pipelines across cloud-native apps. You will perform threat modeling, manual and automated secure code reviews, and build secure internal libraries to eliminate classes of vulnerabilities.

You will own the vulnerability lifecycle, triaging and prioritizing issues from internal tests, pen tests, and bug bounty programs, while partnering with product and engineering to balance speed with security.

Qualifikationen

  • 6+ years in Application Security, DevSecOps, or secure software engineering in cloud environments.
  • Experience securing web apps, APIs, and microservices (OWASP Top 10, CWE).
  • Hands-on security tooling integrated into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
  • Ability to translate cryptographic and security risks to business decisions.

Aufgaben

  • Integrate security into SDLC and DevSecOps pipelines with automated gates (SAST, DAST, SCA, container scanning).
  • Conduct threat modeling and security reviews for complex apps, APIs, and microservices.
  • Perform deep secure code reviews across multiple codebases to find vulnerabilities.
  • Develop and maintain secure-by-default internal libraries and tools.
  • Own vulnerability lifecycle from triage to remediation across testing and bug bounty findings.
  • Advise product/engineering teams with pragmatic security mitigations balancing velocity and risk.
  • Deliver modern secure coding training and security awareness for engineers.

Kenntnisse

SDLC security
Threat modeling
Secure code reviews
CI/CD security tools
Cloud security
Security mentorship

Ausbildung

Degree in CS/IT/Cybersecurity

Tools

SAST
DAST
SCA
OWASP testing
Snyk
Semgrep
GitHub Actions
GitLab CI
Jenkins
Docker
Kubernetes

Jobbeschreibung

Solaris is Europe's leading embedded finance platform. Solaris’ full German banking license and proprietary modular B2B tech stack empowers its partners – from SMEs to large, multinational, non-financial companies – to offer compliant, customer-centric banking services, providing seamless experiences to customers across all industries. Founded in 2016, Solaris pioneered the Banking-as-a-Service market with an unparalleled combination of tech and banking. Solaris is headquartered in Berlin and employs 300 people in Europe.

Your Role
  • Integrate security seamlessly into the Software Development Lifecycle (SDLC) and DevSecOps pipelines by automating security gates (SAST, DAST, SCA, and container scanning).
  • Conduct thorough threat modeling and architectural security reviews for complex applications, APIs, and microservices prior to deployment.
  • Perform deep-dive manual and automated secure code reviews across various codebases to identify logic flaws and subtle implementation vulnerabilities.
  • Build and maintain "secure-by-default" internal libraries, frameworks, and developer tools to systematically eliminate entire classes of vulnerabilities.
  • Take ownership of the application vulnerability lifecycle, including triaging, validating, and prioritizing vulnerabilities originating from internal testing, penetration tests, and external bug bounty programs.
  • Act as a strategic partner to product and engineering teams, providing pragmatic mitigation guidance that balances product velocity with security assurance.
  • Design and deliver modern, hands‑on secure coding training and security awareness initiatives for engineering teams (e.g., addressing OWASP Top 10, LLM/AI security risks).
  • Support incident response and detection teams during application-level security incidents or potential data breaches, leading post‑mortem analysis for software flaws.
  • Ensure application security controls remain fully compliant with relevant financial data protection regulations, fintech standards, and internal tech policies.
  • Owners of this function make sure that they follow the defined Policies & Procedures for the institution (which includes explicit processes defined for Tech, which are properly defined in the respective confluence spaces).
  • Take ownership of the tech responsibilities as described in our Change Management Policies.
We'd love to see

Depending on your level of experience, your responsibilities and scope of role will range. We don’t care much about fancy titles, but rather about real personal and professional development, as laid out in our learning framework. Let’s figure together out how you can contribute to our team.

  • A degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or equivalent professional experience.
  • 6+ years of experience in dedicated Application Security, DevSecOps, or Software Engineering roles with a strong focus on security in high‑growth cloud environments (Fintech or highly regulated environment is a plus).
  • Proven experience analyzing and securing code written in our core tech stack/modern languages (e.g., Java, Go, Python, TypeScript, or Rust).
  • Deep understanding of web application vulnerabilities, API security, and exploitation techniques (OWASP Top 10, CWE).
  • Hands‑on experience integrating security testing tools into modern CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins, Snyk, Semgrep).
  • Experience with cloud computing infrastructure (AWS, GCP, or Azure), containerization (Docker), and orchestration (Kubernetes).
  • Experience managing or triaging external penetration testing reports and crowdsourced bug bounty programs.
  • Understands agile workflows and lean principles.
  • Experience by doing threat modeling.
  • Individual Contributor, technical mentorship focus.
  • Business proficient written and spoken English. German is a plus.
  • Ability to translate complex cryptographic or technical security vulnerabilities into business risk for non‑technical stakeholders and actionable fixes for developers.
  • Empathic collaborator who builds bridges between security goals and engineering targets, avoiding the "department of No" stereotype.
  • Strong analytical mindset capable of finding creative ways to secure cutting‑edge application architectures.
  • Ability to thrive in a fast‑paced environment and adapt security strategies to evolving product frameworks.
  • Proactive peer that helps the growth of the team.
  • Curious, constant learner that is willing to share learning with others
Benefits
  • Home office budget.
  • Learning & development budget of €1000 per year and a transparent growth framework to support your career goals.
  • Competitive salary and a variable remuneration program.
  • Monthly meal allowance.
  • Deutschland ticket subsidy.
  • 28 vacation days, increasing by 2 days after 2 years and 3 days after 3 years with Solaris.
  • Opportunity to work abroad for up to 12 weeks per year.

*While job ads usually paint an ideal picture of a candidate, studies show that most applicants meet an average of 60% of the criteria. Unfortunately, many promising candidates tend to apply only if they meet all the criteria. So if you think you have what it takes, but don't necessarily meet every single item in the job description, please contact us anyway. We'd love to talk with you and find out if you might be a good fit for us.*

At Solaris, we are committed to nurturing an inclusive environment, where all Solarians feel valued, respected and supported. We are dedicated to building a diverse workforce that reflects the diversity of our communities. We are committed to equal employment opportunity regardless of color, ethnicity, religion, sex, origin, disability, marital status, citizenship, or gender identity. We are proud to be an equal opportunity workplace. If you have a disability or special need that requires accommodation, please let us know.

Information on data processing:

DE: https://www.solarisgroup.com/gdpr_notice_de

EN: https://www.solarisgroup.com/gdpr_notice_en

The annual gross salary range for this position is:

€85.000 - €110.000 EUR

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cyber Security Staff Engineer - Application Security
Cyber Security Staff Engineer - Application Security

Solaris • Berlin

Vor Ort
EUR 85.000 - 110.000
Home office budget
Learning budget €1000
Meal allowance
+3
Cyber Security Engineer (Vulnerability Management & SecOperations)
Cyber Security Engineer (Vulnerability Management & SecOperations)

United States Digital Space LLC • Berlin

Vor Ort
EUR 60.000 - 80.000
Home office budget
Learning budget €1000/year
Meal allowance
+3
Cyber Security Engineer (Vulnerability Management & SecOperations)
Cyber Security Engineer (Vulnerability Management & SecOperations)

Solaris • Berlin

Vor Ort
EUR 65.000 - 95.000
Home office budget
Learning budget
Meal allowance
+2
Principal Engineer
Principal Engineer

Solaris SE • Berlin

Vor Ort
EUR 100.000 - 125.000
Home office budget
Learning & development budget
Competitive salary
+3
Cyber Security Staff Engineer - AWS Cloud
Cyber Security Staff Engineer - AWS Cloud

Solaris • Berlin

Vor Ort
EUR 85.000 - 110.000
Home office budget
Learning budget €1000 per year
Competitive salary and variable pay
+4
Principal Engineer
Principal Engineer

United States Digital Space LLC • Berlin

Vor Ort
EUR 100.000 - 125.000
Home office budget
Learning & development budget
Competitive salary
+4
Senior Site Reliability Engineer
Senior Site Reliability Engineer

United States Digital Space LLC • Berlin

Vor Ort
EUR 75.000 - 95.000
Home office budget
Learning budget €1000 per year
Competitive salary + variable pay
+4
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Solaris SE • Berlin

Vor Ort
EUR 75.000 - 95.000
Home office budget
Learning budget €1000/yr
Monthly meal allowance
+2
Senior Software Engineer (f/m/d)
Senior Software Engineer (f/m/d)

Solaris SE • Berlin

Vor Ort
EUR 70.000 - 90.000
Home office budget
Learning & development budget
Competitive salary
+3
Director of Technology (f/m/d)
Director of Technology (f/m/d)

Solaris SE • Berlin

Hybrid
EUR 90.000 - 130.000
Home office budget
Learning & development budget of €1000
Competitive salary
+3