Lead Application Security Engineer (m/f/d)

Egym

München, Berlin

Hybrid

EUR 110.000 - 150.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Mach aus dieser Rolle ein Bewerbungsgespräch — ein Lebenslauf und ein Anschreiben, die genau auf das zugeschnitten sind, was dieser Arbeitgeber sucht.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Modern Tech Stack
Learning Time
International Team
Work-Life Balance
EGYM Wellpass
Flex Budget
Mentoring Program
Discounts
Bike Leasing

Zusammenfassung

EGYM in Munich seeks an experienced Application Security professional to drive secure-by-design initiatives, lead security reviews, and advance tooling for SAST/DAST across our cloud-native stack.

You will partner with engineering, SRE, and DevOps to harden our apps, provide pragmatic remediation guidance, and mentor teams while staying current with threats and compliance needs.

Qualifikationen

  • 5+ years in Application Security or related role.
  • Strong knowledge of OWASP Top 10 and secure coding.
  • Read/write code in Go/Java/Python to support reviews.
  • Familiar with cloud-native architectures and DevSecOps.
  • Professional proficiency in English.

Aufgaben

  • Secure-by-Design enablement with software teams.
  • Perform security reviews for features, services, APIs, and apps.
  • Design, introduce, and improve SAST/DAST tooling with CI/CD integration.
  • Identify, validate, and prioritize vulnerabilities across apps and cloud environments.
  • Act as a trusted security advisor translating findings into practical guidance.
  • Collaborate with SRE/DevOps to improve cloud-native security.
  • Improve security awareness via documentation and hands-on support.
  • Stay up to date with threats and DevSecOps best practices.
  • Lead readiness for SOC 2 and ISO 27001 and other standards.
  • Provide accurate responses to security questionnaires for prospects.

Kenntnisse

OWASP Top 10
Secure coding
Threat modeling
SAST/DAST
Go/Java/Python

Tools

SAST
DAST
CI/CD tooling

Jobbeschreibung

Your daily workout
  • Secure-by-Design Enablement: You work closely with software engineering teams to integrate application security into design, development, and deployment processes

  • Security Reviews: You perform and manage security reviews for major features, services, APIs, and critical applications

  • Tooling & Automation: You design, introduce, and continuously improve application security tooling such as SAST and DAST, including CI/CD integration

  • Vulnerability Management: You identify, validate, and help prioritize vulnerabilities across applications, APIs, and cloud-native environments, supporting teams with pragmatic remediation guidance

  • Advisory & Consulting Role: You act as a trusted security advisor, translating security requirements and findings into practical, developer-friendly solutions

  • Cloud & Platform Security: You collaborate with SRE, DevOps, and platform teams to improve security in containerized and cloud-native setups (e.g. Kubernetes, Docker, GCP/AWS)

  • Security Awareness: You contribute to improving security awareness and knowledge across engineering teams through documentation, guidance, and hands-on support

  • Continuous Improvement: You stay up to date with emerging threats, application security trends, and DevSecOps best practices

  • Compliance & Certification Leadership: You lead technical readiness and evidence collection for security certifications (e.g., SOC 2, ISO 27001) and emerging regulatory requirements, ensuring the product ecosystem meets global security Standards

  • Trust & Sales Enablement: You serve as the technical authority for security questionnaires, providing accurate and timely responses to prospects and clients to streamline the sales process and demonstrate compliance with customer security requirements

Your fitness level
  • Professional Experience: You have 5+ years of experience in Application Security, Software Security Engineering, or a closely related role

  • Application Security Know-how: You have strong knowledge of OWASP Top 10, secure coding principles, threat modeling, and security testing approaches such as SAST and DAST

  • Technical Skills: You are comfortable working with modern software stacks and can read or write code (e.g. Go, Java, Python, or similar) to support reviews, PoCs, or tooling

  • Cloud & DevSecOps Understanding: You are familiar with cloud-native architectures, APIs, CI/CD pipelines, and containerized environments

  • Mindset: You enjoy working with engineers rather than acting as a gatekeeper

  • Working Style: You work in a structured, pragmatic, and collaborative way and feel comfortable shaping processes in a greenfield environment

  • Language Skills: You have professional proficiency in English

Your training goal for your first 6 months
  • Understanding: You gain a deep understanding of our tech stack, development processes, and teams

  • Planning: You create and align a plan to continuously improve the application security posture across the organization

  • Execution: You collaborate with engineering teams on concrete AppSec initiatives such as security tooling rollout and process improvements

  • Impact: You drive and deliver individual application security projects derived from the aligned plan

The equipment we provide
  • Modern Tech Stack & AI Evolution: We don't just maintain; we evolve. Explore our Tech Radar to see our stack, and join us in building an AI-agentic, iterative, and incremental product culture where AI is a core accelerator of our development lifecycle

  • Learning Time: Use 10% of your time on learning topics of your choice (conferences, hackathons, internal and external events, videos, books or innovation projects)

  • International Team: Join our diverse and international team to collaborate with talented professionals from around the world

  • Work-Life-Balance: Benefit from flexible working hours, home office possibilities and 30 days of vacation per year

  • Fit & Healthy: Train for free with EGYM Wellpass in several thousand sports and health facilities across Germany and/or alternatively use our in-house gym with EGYM products

  • Flex Budget: Use €60 per month flexibly for public transportation and a meal subsidy

  • Mentoring Program: Exchange knowledge and grow together across teams and locations through our self-organized mentoring platform

  • Discounts: Get a variety of great discounted offers, from fashion to leisure, through our employee benefits portal

  • Bike Leasing: Stay active and use our leasing bike offer for your way to work or in your spare time

#LI-DNI
About EGYM

Warning regarding phishing emails: Please be aware that all official EGYM recruitment communication is sent exclusively from jobs@egym.com. If you receive a suspicious message from any other domain, please ignore it and do not share personal information if in doubt.
EGYM is a global fitness technology leader, providing fitness and health facilities with intelligent workout solutions. EGYM makes exercising smarter and more efficient with its comprehensive suite of connected gym equipment and digital products that integrate seamlessly with 3rd-party-hard- and software. The result is a fully connected training experience that drives measurable business and health outcomes on and off the training floor.
EGYM also offers subscription-based corporate fitness- and wellness solutions built on a combination of gym-access and EGYM fitness programs that directly target costly chronic conditions and boost employee health, leading to higher productivity and well-being.
EGYM's global headquarters are in Munich, Germany, with North American offices in Denver, Colorado.
EGYM is an equal opportunity employer. All aspects of employment including the decision to hire, promote, discipline, or discharge, will be based on merit, competence, performance, and business needs, regardless of race, gender, religion, sexual orientation, age or any other aspect of an individual's identity.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Lead Application Security Engineer (m/f/d)
Lead Application Security Engineer (m/f/d)

Zoomcar • Berlin

Vor Ort
EUR 80.000 - 120.000
Learning Time
Flexible hours
Home office options
+2
Fullstack Engineer (m/f/d)
Fullstack Engineer (m/f/d)

Egym • München, Berlin

Hybrid
EUR 70.000 - 110.000
Learning time
Modern Tech Stack & AI evolution
Choose Your Equipment
+3
Technical Project Manager - Hardware Engineering (m/f/d)
Technical Project Manager - Hardware Engineering (m/f/d)

Egym • München

Hybrid
EUR 85.000 - 120.000
Flexible working hours
Hybrid workplace model
30 days vacation per year
+5
Team Lead – C++ UI (m/f/d)
Team Lead – C++ UI (m/f/d)

Egym • München

Hybrid
EUR 110.000 - 150.000
Flexible working hours
30 days vacation per year
Home office possibilities
+2
OS Engineer (m/f/d)
OS Engineer (m/f/d)

Egym • München

Hybrid
EUR 90.000 - 130.000
Modern Tech Stack
Learning Time
Choose Your Equipment
+7
Software Engineer - Golang (m/f/d)
Software Engineer - Golang (m/f/d)

Egym • München

Hybrid
EUR 80.000 - 120.000
Learning time
Flexible working hours
Home office possibilities
+6
Senior Entwicklungsingenieur Konstruktion (m/w/d)
Senior Entwicklungsingenieur Konstruktion (m/w/d)

Zoomcar • München

Vor Ort
EUR 100.000 - 140.000
Hybrides Arbeiten
Betriebliche Altersvorsorge
Kaffee & Obst
+1
Team Lead Corporate Sales - Niedersachsen (m/w/d)
Team Lead Corporate Sales - Niedersachsen (m/w/d)

Egym • Oldenburg

Hybrid
EUR 90.000 - 120.000
Firmenwagen
30 Urlaubstage pro Jahr
Flexibilität & Remote-Arbeit
+3
(Senior) Enterprise Customer Success Manager (m/f/d)
(Senior) Enterprise Customer Success Manager (m/f/d)

Egym • München

Hybrid
EUR 85.000 - 120.000
Hybrid work model
30 days vacation per year
Wellness access
+4
Senior C++ UI Software Engineer (m/f/d)
Senior C++ UI Software Engineer (m/f/d)

Egym • München

Hybrid
EUR 90.000 - 130.000
Flexible working hours
Home office possibilities
30 days vacation per year
+6