Application Security Engineer (relocation to Barcelona)

Commit

Barcelona

Presencial

EUR 65.000 - 100.000

Jornada completa

14 días+
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca la empresa.

Supera los filtros ATS

Descripción de la vacante

Commit is seeking an experienced security researcher to join our offensive security team in Barcelona. You will work with researchers and ethical hackers to test web, API, cloud-native, and backend systems, focusing on offensive security, code exploitation, automation, and innovation.

You will plan campaigns, develop tools, and contribute to security research publications, reporting findings and helping scale secure-by-design principles across our products.

Formación

  • 4+ years of experience in research and penetration testing.
  • Strong coding skills and deep understanding of web, API, cloud-native, and backend tech.
  • AI/LLM penetration testing experience.
  • Experience with Burp Suite, Metasploit, and custom tools.
  • Familiar with cloud, microservices, containers, Kubernetes.
  • Knowledge of secure software architecture and attack vectors.
  • Ability to report technical findings effectively.
  • Experience building automated PT or fuzzing pipelines is a plus.

Responsabilidades

  • Reshape JFrog Product Security.
  • Plan and execute advanced penetration testing campaigns.
  • Develop tools and frameworks for scalable security testing and fuzzing.
  • Lead Security innovation by building and managing penetration testing tools & AI Agents.
  • Analyze vulnerabilities, perform root-cause analysis, and develop proofs of concept.
  • Identify systemic product weaknesses and help define long-term mitigations.
  • Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.
  • Contribute to security research publications and CVE submissions.
  • Evolve internal testing capabilities with modern tooling and AI-assisted approaches.

Conocimientos

Penetration testing
Code security
Cloud-native systems
Kubernetes
Burp Suite

Herramientas

Burp Suite
Metasploit
Fuzzing frameworks

Descripción del empleo

We’re running the software that runs the world – and we want you along for the ride. The company is a special place with a unique combination of brilliance, spirit, and great people. Here, if you’re willing to do more, your career can take off. And since software plays a central role in everyone’s lives, you’ll be part of a critical mission.

In this role, you will work with a team of researchers and ethical hackers focused on offensive security testing, automated exploit discovery, and advanced application security research. Your work will directly influence the security posture of the company's products and help scale secure‑by‑design principles.

This is a hands‑on technical role with a strong emphasis on offensive security, code exploitation, automation, and innovation.

Responsibilities
  • Help to reshape JFrog Product Security
  • Plan and execute advanced penetration testing campaigns.
  • Develop tools and frameworks for scalable security testing and fuzzing.
  • Lead Security innovation by building and managing penetration testing tools \ AI Agents
  • Analyze vulnerabilities, perform root cause analysis, and develop proofs of concept.
  • Identify systemic product weaknesses and help define long‑term mitigations.
  • Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.
  • Contribute to security research publications, CVE submissions, and industry knowledge sharing.
  • Continuously evolve internal testing capabilities using modern tooling and AI‑assisted approaches.
Requirements
  • 4+ year experience in Research and penetration testing.
  • Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies.
  • AI and LLM Penetration testing knowldge and Experience
  • Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and Custom Security Tools development.
  • Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes).
  • Familiarity with secure software architecture and typical attack vectors.
  • Demonstrated ability to do security testing engagements and report technical findings effectively.
  • Experience building or integrating automated PT or fuzzing pipelines is a strong advantage.
  • Knowledge and hands‑on experience with SSDLC tools and CI/CD pipelines,
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Offensive Security Engineer - App Security & AI Tools
Offensive Security Engineer - App Security & AI Tools

Commit • Barcelona

Presencial
EUR 65.000 - 100.000
Product Security Engineer
Product Security Engineer

Gomining • España

Presencial
EUR 65.000 - 90.000
Professional development
Flexible work arrangement
Paid time off
+2
Senior Solutions Engineer
Senior Solutions Engineer

JFrog • Madrid

Presencial
EUR 55.000 - 85.000
Employee Stock Purchase Plan
Retirement, wellness and much more!
Medical, dental & vision
Offensive Security Engineer
Offensive Security Engineer

Lever, Inc. • España

A distancia
EUR 110.000 - 150.000
Senior Security Engineer - Barcelona
Senior Security Engineer - Barcelona

SQUAD - Cabinet de conseils et d’expertises • Barcelona

Presencial
EUR 70.000 - 100.000
Training & certification plan
CTF sessions
Conference exposure
Lead IT Security AI-Redteamer
Lead IT Security AI-Redteamer

Dkbcodefactory • España

Presencial
EUR 90.000 - 150.000
Benefits package
Pentester Senior
Pentester Senior

GMV Spain • Tres Cantos

Híbrido
EUR 65.000 - 93.000
Hybrid working model
Teleworking up to 8 weeks/year
Relocation package
+2
Senior Aws Security Engineer
Senior Aws Security Engineer

Squad Conseil Et Expertises • Barcelona

Presencial
EUR 75.000 - 100.000
Hybrid App Security Engineer | Proactive Pentesting
Hybrid App Security Engineer | Proactive Pentesting

Factorial HR • Barcelona

Híbrido
EUR 40.000 - 55.000
Health insurance
Gym access
Cobee benefits
+5
Arquitecto de Seguridad de Aplicaciones
Arquitecto de Seguridad de Aplicaciones

Itequia • Barcelona

Presencial
EUR 90.000 - 120.000
Flexible hybrid model
Continuous learning opportunities
Low bureaucracy culture