Application Security Engineer (relocation to Barcelona)

Commit

Barcelona

Presencial

EUR 65.000 - 100.000

Jornada completa

Hace 8 días

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Commit is seeking an experienced security researcher to join our offensive security team in Barcelona. You will work with researchers and ethical hackers to test web, API, cloud-native, and backend systems, focusing on offensive security, code exploitation, automation, and innovation.

You will plan campaigns, develop tools, and contribute to security research publications, reporting findings and helping scale secure-by-design principles across our products.

Formación

  • 4+ years of experience in research and penetration testing.
  • Strong coding skills and deep understanding of web, API, cloud-native, and backend tech.
  • AI/LLM penetration testing experience.
  • Experience with Burp Suite, Metasploit, and custom tools.
  • Familiar with cloud, microservices, containers, Kubernetes.
  • Knowledge of secure software architecture and attack vectors.
  • Ability to report technical findings effectively.
  • Experience building automated PT or fuzzing pipelines is a plus.

Responsabilidades

  • Reshape JFrog Product Security.
  • Plan and execute advanced penetration testing campaigns.
  • Develop tools and frameworks for scalable security testing and fuzzing.
  • Lead Security innovation by building and managing penetration testing tools & AI Agents.
  • Analyze vulnerabilities, perform root-cause analysis, and develop proofs of concept.
  • Identify systemic product weaknesses and help define long-term mitigations.
  • Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.
  • Contribute to security research publications and CVE submissions.
  • Evolve internal testing capabilities with modern tooling and AI-assisted approaches.

Conocimientos

Penetration testing
Code security
Cloud-native systems
Kubernetes
Burp Suite

Herramientas

Burp Suite
Metasploit
Fuzzing frameworks

Descripción del empleo

We’re running the software that runs the world – and we want you along for the ride. The company is a special place with a unique combination of brilliance, spirit, and great people. Here, if you’re willing to do more, your career can take off. And since software plays a central role in everyone’s lives, you’ll be part of a critical mission.

In this role, you will work with a team of researchers and ethical hackers focused on offensive security testing, automated exploit discovery, and advanced application security research. Your work will directly influence the security posture of the company's products and help scale secure‑by‑design principles.

This is a hands‑on technical role with a strong emphasis on offensive security, code exploitation, automation, and innovation.

Responsibilities
  • Help to reshape JFrog Product Security
  • Plan and execute advanced penetration testing campaigns.
  • Develop tools and frameworks for scalable security testing and fuzzing.
  • Lead Security innovation by building and managing penetration testing tools \ AI Agents
  • Analyze vulnerabilities, perform root cause analysis, and develop proofs of concept.
  • Identify systemic product weaknesses and help define long‑term mitigations.
  • Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.
  • Contribute to security research publications, CVE submissions, and industry knowledge sharing.
  • Continuously evolve internal testing capabilities using modern tooling and AI‑assisted approaches.
Requirements
  • 4+ year experience in Research and penetration testing.
  • Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies.
  • AI and LLM Penetration testing knowldge and Experience
  • Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and Custom Security Tools development.
  • Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes).
  • Familiarity with secure software architecture and typical attack vectors.
  • Demonstrated ability to do security testing engagements and report technical findings effectively.
  • Experience building or integrating automated PT or fuzzing pipelines is a strong advantage.
  • Knowledge and hands‑on experience with SSDLC tools and CI/CD pipelines,
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Application Security Research Engineer
Application Security Research Engineer

Commit • Barcelona

Presencial
EUR 90.000 - 120.000
Offensive Security Engineer - App Security & AI Tools
Offensive Security Engineer - App Security & AI Tools

Commit • Barcelona

Presencial
EUR 65.000 - 100.000
Senior Offensive Security Research Engineer
Senior Offensive Security Research Engineer

Commit • Barcelona

Presencial
EUR 90.000 - 120.000
Product Security Engineer
Product Security Engineer

Gomining • España

Híbrido
EUR 65.000 - 90.000
Professional development
Flexible work arrangement
Paid time off
+2
Lead IT Security AI-Redteamer
Lead IT Security AI-Redteamer

Dkbcodefactory • España

Presencial
EUR 90.000 - 150.000
Benefits package
Vulnerability Management Engineer – Application Security
Vulnerability Management Engineer – Application Security

Optiwisers • Comunidad Valenciana

Presencial
EUR 55.000 - 75.000
Senior Application Security Engineer
Senior Application Security Engineer

LeoVegas Group • Málaga

Híbrido
EUR 70.000 - 100.000
Hybrid work policy
Workation benefits
Wellness contribution
+7
Vulnerability Engineer
Vulnerability Engineer

Amaris Consulting • Barcelona

Híbrido
EUR 45.000 - 60.000
Application Security Engineer (m/f/d)
Application Security Engineer (m/f/d)

Tamarind Intelligence • Madrid

Híbrido
EUR 45.000 - 65.000
Flexible and hybrid working
Meal voucher
Life and accident insurance
+2
Mobile Security Evaluator
Mobile Security Evaluator

Applus+ Laboratories • Cerdanyola del Vallés

Presencial
EUR 28.000 - 38.000
23 vacation days
Employee parking
Wellness activities
+1