Senior Application Security Engineer (Spain Only)

Technosylva

España

Presencial

EUR 90.000 - 140.000

Jornada completa

hace 5 horas
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Remote work options
Competitive annual salary
Private health insurance
Annual bonus
Flexible benefits plan

Descripción de la vacante

Technosylva seeks a Senior Application Security Engineer to elevate our AppSec program across a cloud-native software environment. You will drive secure SDLC processes, champion secure coding standards, and partner with Engineering, Product, Platform, and Security leadership.

In this role you will define metrics and risk-based gates, integrate security into CI/CD, mentor engineers, and transform AppSec from tooling to a strategic, measurable security capability across the organization.

Formación

  • Minimum 10 years of experience in AppSec or related field.
  • Proven track record driving AppSec programs in medium/large orgs.
  • Strong technical expertise in OWASP Top 10, API security, threat modeling, and security reviews.
  • Hands-on DevSecOps: CI/CD security, SAST/DAST, SCA, secrets management, container/Kubernetes security, IaC (Terraform preferred).
  • Strong understanding of software engineering practices and ability to read production-grade code.
  • Strong business and operational capabilities: project management, executive reporting, risk prioritization.

Responsabilidades

  • Lead the evolution of AppSec program and roadmap across engineering teams.
  • Establish secure-by-design practices integrated into development workflows.
  • Build AppSec KPIs and executive reporting.
  • Improve GitLab/GitHub security capabilities and integrations.

Conocimientos

Strong communication
Executive reporting
Ownership/autonomy
Problem solving

Herramientas

Terraform
GitLab security
GitHub security

Descripción del empleo

Technosylva is seeking a highly experienced Senior Application Security Engineer to elevate and mature our Application Security (AppSec) program across a modern cloud-native software environment.

This role is not limited to technical execution. We are looking for a security professional who combines deep hands‑on AppSec expertise with strong business, communication, coordination, and program execution skills. The ideal candidate will partner closely with Engineering, Product, Platform, Infrastructure, and Security leadership to drive scalable security improvements across the software development lifecycle (S-SDLC).

This position will play a key role in transforming AppSec from a primarily tooling‑focused function into a strategic, measurable, and business‑aligned security capability.

RESPONSIBILITIES
  • Lead the evolution of Technosylva's Application Security program and roadmap, defining and improving secure SDLC processes across all engineering teams.
  • Establish scalable security‑by‑design practices integrated into development workflows, driving adoption of secure coding standards, threat modeling, and security architecture reviews.
  • Build practical and measurable AppSec KPIs and reporting for leadership.
  • Improve and optimize GitLab/GitHub security capabilities and integrations (SAST, DAST, dependency scanning, container scanning, secrets detection, and IaC security workflows).
  • Work closely with DevOps and Engineering teams to embed security into CI/CD pipelines, defining risk‑based security gates and exception processes while reducing developer friction.
  • Partner directly with developers, architects, and technical leads to remediate vulnerabilities, translate security requirements into actionable tasks, and conduct code reviews.
  • Establish mature application vulnerability management processes: improve triage, prioritization based on business risk, SLAs, tracking through closure, and executive reporting.
  • Own and drive AppSec initiatives from planning through execution across cross‑functional teams (Engineering, Infrastructure, Product, Security), producing clear documentation and implementation plans.
  • Help improve security culture within engineering teams by delivering secure coding guidance, workshops, awareness sessions, and mentoring junior engineers.
  • Act as a trusted advisor rather than only an enforcement function, adapting communication effectively for both technical and non‑technical stakeholders.
REQUIREMENTS
  • Minimum 10 years of experience across Application Security, S-SDLC/DevSecOps, or Software Engineering/Security Engineering.
  • Proven track record driving AppSec programs in medium or large organizations within modern SDLC, cloud‑native, and SaaS environments.
  • Strong technical expertise in AppSec fundamentals: OWASP Top 10, API security, multi‑tenant application security, threat modeling, and security architecture reviews.
  • Hands‑on DevSecOps experience: CI/CD pipeline security, SAST/DAST, SCA, secrets management, container/Kubernetes security, and IaC security (Terraform preferred).
  • Strong understanding of software engineering practices, experience with modern development frameworks/APIs, and the ability to read and review production‑grade code.
  • Strong business and operational capabilities: project management, executive‑level reporting, documentation practices, and prioritizing work based on business risk.
  • Excellent communication, coordination, and interpersonal skills, with the ability to influence engineering teams without direct authority.
  • High level of ownership, autonomy, maturity, and proactive problem‑solving.
PREFERRED QUALIFICATIONS
  • Penetration testing experience, red teaming, or an offensive security background.
  • Experience leading vulnerability management programs, security automation, and scripting.
  • Practical experience applying AI/ML tools in development and cybersecurity (e.g., ChatGPT, Claude, GitHub Copilot).
  • Specialized experience with GitLab / GitHub Security features.
  • Security certifications such as CSSLP, CISSP, OSCP, GIAC, or Azure/AWS certifications.
BENEFITS
  • Competitive annual salary.
  • Private health insurance and a flexible benefits plan, allowing you to tailor part of your compensation package to your personal needs.
  • Annual bonus based on individual performance and company results.
  • Remote work options.

At Technosylva, we value diverse experiences and skills, and we understand that every career path is unique. We encourage anyone who believes they meet most of the requirements and is interested in growing and contributing in this role to apply.

DISCLAIMER

Final salary and benefits will depend on a variety of factors, including location, experience, training, qualifications, and market conditions.

EQUAL OPPORTUNITY STATEMENT

Technosylva is an Equal Opportunity Employer. We are committed to fostering an inclusive environment where diverse perspectives lead to better solutions.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Application Security Engineer (Spain Only)
Senior Application Security Engineer (Spain Only)

Tecnosylva • León

Presencial
EUR 90.000 - 130.000
Competitive salary
Private health insurance
Annual bonus
+2
Senior Application Security Engineer (Spain Only)
Senior Application Security Engineer (Spain Only)

Technosylva • León

Presencial
EUR 90.000 - 130.000
Private health insurance
Flexible benefits plan
Annual bonus
+2
Senior AppSec Engineer - Remote, Flexible Hours, Bonus
Senior AppSec Engineer - Remote, Flexible Hours, Bonus

Tecnosylva • León

Presencial
EUR 90.000 - 130.000
Competitive salary
Private health insurance
Annual bonus
+2
Senior AppSec Engineer: Remote & Cloud SDLC Security
Senior AppSec Engineer: Remote & Cloud SDLC Security

Technosylva • España

Presencial
EUR 90.000 - 140.000
Remote work options
Competitive annual salary
Private health insurance
+2
Senior AppSec Engineer: Cloud-Native SDLC Leader
Senior AppSec Engineer: Cloud-Native SDLC Leader

Technosylva • León

Presencial
EUR 90.000 - 130.000
Private health insurance
Flexible benefits plan
Annual bonus
+2
Senior Application Security Engineer
Senior Application Security Engineer

Maisa • España

Presencial
USD 100.000 - 130.000
Lead Application Security Engineer ID71664
Lead Application Security Engineer ID71664

AgileEngine, LLC. • Madrid

Presencial
EUR 90.000 - 120.000
Remote work
Flexible hours
Learning budget
Senior/Lead AppSec Engineer ID71672
Senior/Lead AppSec Engineer ID71672

AgileEngine, LLC. • Madrid

A distancia
EUR 70.000 - 90.000
Growth without limits
Competitive compensation
Flexibility: remote work
+3
Application Security Engineer (m/f/d)
Application Security Engineer (m/f/d)

Liebherr Group • Madrid

Híbrido
EUR 55.000 - 75.000
Attractive salary and social benefits
Flexible and hybrid working
Freedom for creative work
+1
Product Security Engineer
Product Security Engineer

Gomining • España

Híbrido
EUR 65.000 - 90.000
Professional development
Flexible work arrangement
Paid time off
+2