Application Security Engineer (F/M/D)

Awin

Milano

In loco

EUR 90.000 - 120.000

Tempo pieno

5 giorni fa
Candidati tra i primi
Generatore di candidature

Ottieni una risposta da questo datore di lavoro — un curriculum e una lettera di presentazione personalizzati, che corrispondono esattamente a ciò che stanno cercando.

Supera i filtri ATS

Vantaggi offerti da questo lavoro

Flexi-Week
Flexi-office
Remote work furniture allowance
Health and wellbeing
Development: Awin Academy
Peer recognition

Descrizione del lavoro

Awin in Milan, Lombardy, Italy is seeking an Application Security Engineer to establish and lead a comprehensive AppSec program within the Product and Technology department. You will evangelize AppSec, assess design proposals, and drive secure development practices across engineers and managers.

Responsibilities include integrating security tooling into CI/CD, threat modelling, secure coding guidance, vulnerability lifecycle management, and leading a Security Champions initiative to scale

Competenze

  • 5+ years in application security or related roles.
  • Experience securing web applications with engineers/product managers.
  • Experience in Agile environments.
  • Proficient in English (spoken and written).
  • Mentorship and training abilities.
  • Ability to work across two departments with multiple touchpoints.

Mansioni

  • Secure the SDLC: Integrate security tooling into CI/CD pipelines and IDEs.
  • Threat modelling secure design: Collaborate with product and engineering teams during the design phase.
  • Code architecture reviews: Guide developers on secure coding practices and remediation support.
  • Vulnerability lifecycle management: Identify, triage, track and report vulnerabilities across apps and systems.
  • Support the bug bounty process with finding validation.
  • Present vulnerability management reports to heads of department.
  • AI/ML security: Guidance on secure development of AI/LLM-powered features and risk management.
  • Incident response collaboration: Support investigation and post-incident reviews.
  • Security culture enablement: Act as a security champion and deliver trainings.
  • Research innovation: Propose and test ideas to reduce risk in software supply chain.

Conoscenze

JavaScript
Python
PHP
Mentorship
Interpersonal skills
English proficiency
Agile experience

Strumenti

SAST
DAST
SCA tools
CI/CD tooling
Dashboards
AWS
Containers
Terraform

Descrizione del lavoro

Purpose of PositionYour role is to establish and lead an AppSec program within the Product and Technology department, acting as an evangelist for AppSec, trusted by engineers and managers alike.As a member of the core security team, you will engage in assessing application design proposals, to identify improvements to enable our engineers to create secure products.You will own the existing training program, redesign it to better equip engineers with the knowledge needed to develop secure applications, and create a Security Champions program to scale and embed a DevSecOps mindset across PT.

What you'll be responsible for
  • Secure the SDLC: Integrate security tooling (e.g. SAST, DAST, dependency scanning) into CI/CD pipelines and IDEs. Automate and optimise checks so teams can identify and fix issues early and efficiently.
  • Threat modelling secure design: Collaborate with product and engineering teams during the design phase to conduct threat modelling sessions and pre-implementation security reviews.
  • Code architecture reviews: Guide developers on secure coding practices, perform targeted code reviews, and help resolve vulnerabilities with actionable remediation support.
  • Vulnerability lifecycle management:Identify, triage, track and report on vulnerabilities across internal and external apps and systems.Collaborate with engineers to close gaps efficiently.
  • Support the bug bounty process with finding validation.
  • Present vulnerability management reports to our heads of department.
  • AI/ML LLM security:Provide guidance on secure development of AI/LLM-powered features.Help teams manage risks such as prompt injection, model misuse, and data leakage.Lead threat modelling exercises for AI components and advise on secure integration patterns.
  • Incident response collaboration: Support investigation and root cause analysis of application-layer incidents. Contribute to post-incident reviews and longer-term mitigation strategies.
  • Security culture enablement:Act as a security champion for development teams.Be an enthusiastic and vocal advocate for application security across all engineering and product teams.Nurture and report on our application security training program for our code contributors.Deliver workshops and technical deep-dives on secure development practices.Contribute to playbooks, documentation, and internal standards.
  • Research innovation:Stay ahead of industry threats and attack trends. Propose and test innovative ideas to reduce risk across our software supply chain and platforms.Showcase how to use AI and AI-powered tools to enhance productivity and improve our security posture.
Your skills
  • 5+ years in application security, product security or related technical roles.
  • Experience working directly with software engineer and product managers to secure web applications.
  • Experience in working within an Agile environment.
  • Good working proficiency in spoken and written English.
  • Excellent interpersonal skills and ability to clearly communicate at every level of the organisation.
  • Mentorship and training skills.
  • Ability to work across two different departments with multiple touch points.
  • Coding proficiency in languages such as JS, PHP, Python.
  • Experience with Cloud Native environments (AWS), Containers and Terraform.
  • Hands on experience with DAST, SAST, SCA tools, reporting and dashboarding platforms.
Our Offer
  • Flexi-Week: We prioritise your mental health and wellbeing by offering you a four-day Flexi-Week (with one lighter or completely disconnected day per week) at full pay, with no reduction to your annual holiday allowance.
  • Flexi-office: We offer an international culture and flexibility through our hybrid/remote working scheme which is designed to foster a culture of mutual trust and working flexibility.
  • Work Expense Contribution Remote Working Furniture: You will receive a monthly allowance to cover part of your running costs, as well as a furniture package to support you in setting up a comfortable workspace when working from home.
  • Health and Wellbeing: With our support and access to various initiatives and sports offers, you can focus on your mental and physical wellbeing.
  • Development: We’ve built our extensive training suite, Awin Academy, to cover a wide range of skills that support your professional and personal growth, with trainings conveniently packaged to help your overall development.
  • Appreciation: Thank and reward colleagues by sending them a voucher through our peer-to-peer recognition programme.

We are hiring in multiple countries for this role. Additional benefits, including health and wellbeing offerings, will be discussed during the initial interview.

Established in 2000, Awin is proud of our dynamic, social and inclusive culture.

Like all businesses, we’ve had to adapt and nurture our culture in a virtual environment. Our virtual ‘Life @ Awin’ hub brings our colleagues from across the globe together for various social activities.

Diversity Inclusion are paramount to us, and we proudly pursue and hire diverse team members.

We champion uniqueness and authenticity; this is who we are at our core.

Our network of affiliate partnerships are diverse and transparent, as are the employees powering our vision to build the world’s leading open partner ecosystem.

We welcome all backgrounds, identities, and experiences.

If you need support at any point in the application or interview process, please let us know.

Awin is part of the Axel Springer group.

Learn more at axelspringer.com/en/, and explore the Axel Springer Essentials here:axelspringer.com/en/inside/the-essentials-what-we-have-adapted-and-why

Application Security Engineer (f/m/d) • milan, lombardy, Italy
Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Application Support Analyst - German speaker (f/m/d)
Application Support Analyst - German speaker (f/m/d)

Awin • Milano

Ibrido
EUR 45.000 - 65.000
Flexi-Week
Flexi-office
Work Expense Contribution & RemoteW …
+3
Sales Manager - Italy (f/m/d)
Sales Manager - Italy (f/m/d)

Awin • Milano

In loco
EUR 90.000 - 130.000
Flexi-Week
Flexi-Office
Work expense contribution
+4
Cyber Security Engineer
Cyber Security Engineer

Yoox Group • Bologna

Ibrido
EUR 50.000 - 70.000
Sales Manager - Italy (f/m/d)
Sales Manager - Italy (f/m/d)

Awin Global • Milano

Ibrido
EUR 70.000 - 110.000
Flexi-Week
Flexi-Office
Work Expense Contribution
+3
Senior Product Manager, Purchase Paths & Industry Relations (m/f/d)
Senior Product Manager, Purchase Paths & Industry Relations (m/f/d)

Awin Global • Turbigo

Ibrido
EUR 60.000 - 80.000
FlexiWeek and Work-Life Balance
Flexi-Office with hybrid/remote work possibilities
Health & Well Being initiatives
+3
Account Manager (f/m/d)
Account Manager (f/m/d)

Awin • Milano

Ibrido
EUR 45.000 - 65.000
Flexi-Week
Flexi-Office
Work Expense Contribution & Remote/FI
+3
Cyber Security Engineer
Cyber Security Engineer

NET-A-PORTER • Bologna

Ibrido
EUR 50.000 - 70.000
App Developer (m/w/x)
App Developer (m/w/x)

Gunnebo Safe Storage • Verona

Ibrido
EUR 40.000 - 65.000
AppSec Program Lead & Security Champion (Hybrid/Remote)
AppSec Program Lead & Security Champion (Hybrid/Remote)

Awin • Milano

In loco
EUR 90.000 - 120.000
Flexi-Week
Flexi-office
Remote work furniture allowance
+3
Mobile Application Senior Security Engineer
Mobile Application Senior Security Engineer

Klarna • Milano

Ibrido
EUR 87.000 - 122.000