Cyber Security Staff Engineer - Application Security

Solaris

Sweden

On-site

SEK 1,324,210 - 1,986,316

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Home office budget
Learning & development budget €1000/yr
Competitive salary & variable remunera
Monthly meal allowance
Deutschland ticket subsidy
28 vacation days + 2/3 day increases

Job summary

Solaris is Europe’s leading embedded finance platform and is seeking an experienced Application Security professional to integrate security into the SDLC and DevSecOps pipelines. You will automate security gates, perform threat modeling, and conduct deep-dive secure code reviews across multi‑tier cloud apps.

You will design secure-by-default libraries, own the vulnerability lifecycle, and partner with product and engineering to balance speed with security.

Qualifications

  • 6+ years in Application Security, DevSecOps, or secure software engineering.
  • Experience securing code in cloud-native environments (Fintech or regulated contexts a plus).
  • Strong knowledge of OWASP Top 10, CWE, API security, and threat modeling.

Responsibilities

  • Integrate security into the Software Development Lifecycle and DevSecOps pipelines via automated gates (SAST, DAST, SCA, container scanning).
  • Conduct threat modeling and architectural security reviews for complex apps, APIs, and microservices.
  • Perform deep-dive secure code reviews across codebases to identify vulnerabilities.
  • Develop secure-by-default internal libraries and tools to reduce vulnerabilities.
  • Own vulnerability lifecycle from triage to prioritization from internal tests and bug bounty programs.
  • Provide mitigation guidance to product and engineering teams balancing velocity and security.

Skills

Java
Go
Python
TypeScript
Rust

Education

Bachelor's in CS / equivalent

Tools

GitHub Actions
GitLab CI
Jenkins
Snyk
Semgrep

Job description

Solaris is Europe's leading embedded finance platform. Solaris’ full German banking license and proprietary modular B2B tech stack empowers its partners – from SMEs to large, multinational, non-financial companies – to offer compliant, customer-centric banking services, providing seamless experiences to customers across all industries. Founded in 2016, Solaris pioneered the Banking-as-a-Service market with an unparalleled combination of tech and banking. Solaris is headquartered in Berlin and employs 300 people in Europe.

Your Role
  • Integrate security seamlessly into the Software Development Lifecycle (SDLC) and DevSecOps pipelines by automating security gates (SAST, DAST, SCA, and container scanning).
  • Conduct thorough threat modeling and architectural security reviews for complex applications, APIs, and microservices prior to deployment.
  • Perform deep-dive manual and automated secure code reviews across various codebases to identify logic flaws and subtle implementation vulnerabilities.
  • Build and maintain "secure-by-default" internal libraries, frameworks, and developer tools to systematically eliminate entire classes of vulnerabilities.
  • Take ownership of the application vulnerability lifecycle, including triaging, validating, and prioritizing vulnerabilities originating from internal testing, penetration tests, and external bug bounty programs.
  • Act as a strategic partner to product and engineering teams, providing pragmatic mitigation guidance that balances product velocity with security assurance.
  • Design and deliver modern, hands‑on secure coding training and security awareness initiatives for engineering teams (e.g., addressing OWASP Top 10, LLM/AI security risks).
  • Support incident response and detection teams during application‑level security incidents or potential data breaches, leading post‑mortem analysis for software flaws.
  • Ensure application security controls remain fully compliant with relevant financial data protection regulations, fintech standards, and internal tech policies.
  • Owners of this function make sure that they follow the defined Policies & Procedures for the institution (which includes explicit processes defined for Tech, which are properly defined in the respective confluence spaces).
  • Take ownership of the tech responsibilities as described in our Change Management Policies.
We’d love to see
  • A degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or equivalent professional experience.
  • 6+ years of experience in dedicated Application Security, DevSecOps, or Software Engineering roles with a strong focus on security in high‑growth cloud environments (Fintech or highly regulated environment is a plus).
  • Proven experience analyzing and securing code written in our core tech stack/modern languages (e.g., Java, Go, Python, TypeScript, or Rust).
  • Deep understanding of web application vulnerabilities, API security, and exploitation techniques (OWASP Top 10, CWE).
  • Hands‑on experience integrating security testing tools into modern CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins, Snyk, Semgrep).
  • Experience with cloud computing infrastructure (AWS, GCP, or Azure), containerization (Docker), and orchestration (Kubernetes).
  • Experience managing or triaging external penetration testing reports and crowdsourced bug bounty programs.
  • Understands agile workflows and lean principles.
  • Experience by doing threat modeling.
  • Individual Contributor, technical mentorship focus.
  • Business proficient written and spoken English. German is a plus.
  • Ability to translate complex cryptographic or technical security vulnerabilities into business risk for non-technical stakeholders and actionable fixes for developers.
  • Empathic collaborator who builds bridges between security goals and engineering targets, avoiding the "department of No" stereotype.
  • Strong analytical mindset capable of finding creative ways to secure cutting‑edge application architectures.
  • Ability to thrive in a fast‑paced environment and adapt security strategies to evolving product frameworks.
  • Proactive peer that helps the growth of the team.
  • Curious, constant learner that is willing to share learning with others
Benefits
  • Home office budget.
  • Learning & development budget of €1000 per year and a transparent growth framework to support your career goals.
  • Competitive salary and a variable remuneration program.
  • Monthly meal allowance.
  • Deutschland ticket subsidy.
  • 28 vacation days, increasing by 2 days after 2 years and 3 days after 3 years with Solaris.
  • Opportunity to work abroad for up to 12 weeks per year.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer (Vulnerability Management & SecOperations)
Cyber Security Engineer (Vulnerability Management & SecOperations)

Solaris • Sweden

On-site
SEK 662,000 - 883,000
Home office budget
Learning & development budget €1000/yr
Competitive salary with variable pay
+3
Cyber Security Staff Engineer - AWS Cloud
Cyber Security Staff Engineer - AWS Cloud

Solaris • Sweden

Hybrid
SEK 993,000 - 1,325,000
Home office budget
Learning budget €1000/year
Competitive salary and bonus program
+4
Principal Engineer
Principal Engineer

Solaris • Sweden

On-site
SEK 1,200,000 - 1,800,000
Home office budget
Learning & development budget of €1000
Competitive salary and variable bonus
+4
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Solaris • Sweden

On-site
SEK 827,000 - 1,049,000
Home office budget
Learning & development budget of €1000
Competitive salary and a variableremun
Senior Software Engineer (f/m/d)
Senior Software Engineer (f/m/d)

Solaris • Sweden

On-site
SEK 849,000 - 961,000
Home office budget
Learning budget €1000 per year
Competitive salary & bonus
+4
Senior Data Protection Manager
Senior Data Protection Manager

Solaris • Stockholms kommun

On-site
SEK 800,000 - 1,200,000
Home office budget
Learning & development budget of €1000
Competitive salary and variable bonus
+4
Senior AI Engineer (f/m/d)
Senior AI Engineer (f/m/d)

Solaris • Sweden

On-site
SEK 882,000 - 1,104,000
Home office budget
Meal allowance
Deutschland ticket
+2
Staff AppSec Engineer — DevSecOps & Threat Modeling
Staff AppSec Engineer — DevSecOps & Threat Modeling

Solaris • Sweden

On-site
SEK 1,324,000 - 1,987,000
Home office budget
Learning & development budget €1000/yr
Competitive salary & variable remunera
+3
Product Owner - Cards Transactions
Product Owner - Cards Transactions

Solaris • Sweden

Hybrid
SEK 827,000 - 994,000
Home office budget
Learning & development budget €1000/yr
Competitive salary
+4
Credit Risk Manager (f/m/d)
Credit Risk Manager (f/m/d)

Solaris • Stockholms kommun

On-site
SEK 772,000 - 1,104,000
Competitive salary
Home office budget
Learning budget
+4