Senior Application Security Engineer

Maisa

España

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

An innovative technology company is seeking a Senior Application Security Engineer to enhance their vulnerability management program and embed security into CI/CD pipelines. The ideal candidate will possess strong experience in Application Security, hands-on programming skills, and familiarity with security frameworks. This opportunity involves working with cutting-edge technology and contributing to enterprise AI challenges. Join a fast-paced environment with significant enterprise traction.

Qualifications

  • Strong demonstrable experience in Application Security or Security Engineering.
  • Proven ownership of a Vulnerability Management or Secure SDLC program.
  • Strong hands-on skills with at least two programming languages: Go, Python, TypeScript/Node.js, or Java.
  • Experience integrating SAST/SCA/DAST/Secrets/IaC tools into Git-based CI/CD.
  • Solid understanding of container and Kubernetes security.
  • Deep knowledge of authn/authz, cryptography, SSRF/XSS/Injection classes.
  • Familiarity with ISO 27001 and SOC 2 requirements.

Responsibilities

  • Own and scale the Vulnerability Management Program.
  • Embed security into CI/CD pipelines.
  • Perform deep code security reviews.
  • Define and operate vulnerability management lifecycle.
  • Establish risk-based triage.
  • Integrate scanners into CI/CD.
  • Build automated patch dependency-update pipelines.

Job description

Join to apply for the Senior Application Security Engineer role at Maisa

Welcome to Maisa - Making AI Accountable!

Our agentic process automation platform helps enterprises automate complex, decision-heavy processes that traditional automation can’t handle and GenAI can’t be trusted with.

We enable organizations to scale operations, resist hallucinations, and bring end-to-end visibility and control to your most complex processes.

Powered by a new kind of computing platform, Maisa combines AI-driven problem solving with programmatic execution, so every action is reliable, auditable, and built for enterprise scale.

About the role…

We're looking for a Senior Application Security Engineer to own and scale our Vulnerability Management Program, embed security into CI/CD pipelines, and perform deep code security reviews. This hands‑on role partners with Engineering, SRE, and GRC to measurably reduce application risk across our portfolio. We value engineers who automate first, build guardrails instead of gates, and help teams ship secure software fast.

What you’ll do…

Vulnerability Management (Program Ownership):

  • Define and operate end-to-end vulnerability management lifecycle (SCA, SAST, DAST, container, IaC scanning)
  • Establish risk‑based triage using CVSS and exploited vulnerability catalogs
  • Integrate scanners into CI/CD (GitHub Actions) and container registries
  • Build automated patch/dependency‑update pipelines (e.g., Dependabot automated PRs)
  • Generate and store SBOMs; implement image signing and provenance (Sigstore, cosign, SLSA)
  • Track MTTR, time‑to‑first‑fix, and executive‑level security metrics
  • Partner with GRC to align with ISO 27001 and SOC 2 frameworks

Security in CI/CD (Shift‑Left & Supply Chain):

  • Embed SAST, SCA, secret scanning, and IaC checks into pipelines
  • Enforce branch protections, mandatory code reviews, and artifact signing
  • Champion least‑privilege pipelines, ephemeral runners, and hardened build environments
  • Publish attestations and SBOMs with every release

Code Security Reviews (Depth Where It Matters):

  • Perform targeted manual reviews of critical code paths (auth/authz, crypto, multi‑tenant boundaries, PII handling)
  • Write concise, actionable review notes with clear risk statements and remediation guidance
  • Collaborate with developers to land fixes quickly
  • Contribute to secure coding patterns and internal libraries
  • Deliver developer training based on real findings
What you’ll bring…
  • Strong demonstrable experience in Application Security or Security Engineering
  • Proven ownership of a Vulnerability Management or Secure SDLC program
  • Strong hands‑on skills with at least two programming languages: Go, Python, TypeScript/Node.js, or Java
  • Experience integrating SAST/SCA/DAST/Secrets/IaC tools into Git-based CI/CD (GitHub Actions preferred)
  • Solid understanding of container and Kubernetes security (image scanning, admission controls, PodSecurity)
  • Deep knowledge of authn/authz, cryptography, SSRF/XSS/Injection classes, and modern web/API architectures
  • Familiarity with ISO 27001 and SOC 2 requirements for software security
  • Excellent communication and stakeholder management skills
  • Fluent Spanish (essential for client interactions)
  • Any familiarity with tools such as: Semgrep, CodeQL, Trivy, Grype, Snyk, Dependabot, Checkov, tfsec, ZAP, Burp, SonarQube would be beneficial. As would any formal certifications such as OSWE, OSCP, GCSA, GWAPT, GWEB, CSSLP.

You will be joining one of Europe’s most exciting early‑stage AI start‑ups, where you’ll have the opportunity to work with cutting‑edge Agentic Process Automation that’s reshaping how enterprises approach AI deployment. You will get to directly influence how major multinational organizations transform critical business processes, working on genuinely differentiated technology that solves real enterprise AI challenges.

Following our recent $25m Seed Round, backed by leading Venture Capital firms including Creandum, Forgepoint, NFX, and Village Global, we’re scaling quickly and realizing significant enterprise traction. This is your opportunity to help solve real AI enterprise challenges, working alongside deep technical and industry experts, where you will be challenged daily and expedite your learning and development.

Maisa is committed to Equal Employment Opportunity through attracting and retaining a complementary team of employees and building an inclusive environment for all.

Seniority level

Mid‑Senior level

Employment type

Full‑time

Job function

IT Services and IT Consulting

Referrals increase your chances of interviewing at Maisa by 2x

Get notified about new Senior Application Security Engineer jobs in Spain.

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Application Security Engineer
Staff Application Security Engineer

Triwill Group • United States

On-site
USD 120,000 - 145,000
Fully remote work arrangement
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent, Inc. • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Bonus
Competitive benefits
Application Security Manager
Application Security Manager

Alter Domus • Chicago (IL)

Hybrid
USD 120,000 - 150,000
Flexible arrangements
Generous holidays
Employee Share Plan
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Application Security Engineer
Application Security Engineer

Compunnel Inc. • Orlando (FL)

On-site
USD 80,000 - 120,000
Application Security Engineer
Application Security Engineer

ApplyMint • Germany (OH)

Hybrid
USD 75,000 - 240,000
Competitive compensation
Career growth and learning opportunities
Flexibility and ownership
+3
Senior/Lead AppSec Engineer
Senior/Lead AppSec Engineer

AgileEngine, LLC • Brazil (IN)

On-site
USD 120,000 - 160,000
Senior Security Engineer – Remote (US) – Competitive Salary Opportunity to work with an Ambitio[...]
Senior Security Engineer – Remote (US) – Competitive Salary Opportunity to work with an Ambitio[...]

Orbis Group • United States

Remote
USD 180,000 - 200,000
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Triwill Group • United States

On-site
USD 140,000 - 200,000
Remote-first
Competitive salary
Unlimited PTO
+2