> Markdown version of [/jobs/ext/1623662-application-security-architect](https://www.wearedevelopers.com/jobs/ext/1623662-application-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Architect - **Company:** Liebherr - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Continuous Integration, DevOps, Github, Identity and Access Management, OAuth, Open Web Application Security, Systems Development Life Cycle, Zero Trust Network Access, JSON Web Token, Sherwood Applied Business Security Architecture, Security Assertion Markup Language (SAML), Software Engineering, Working Model 2D, Google Cloud, Software Security, Kubernetes, Information Technology, Devsecops, Docker, Jenkins, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** July 22, 2026 - **Apply:** https://www.buscojobs.com.es/application-security-architect-m-f-d-en-madrid-ID-364957016 ## About the Role practices Collaborate with IT, EA, DevOps amd Engineering Team to align security Objectives Contributing your strengths: your qualifications Bachelor's/Master's in Cybersecurity, Computer Science, or related field 3+ years in cybersecurity, preferably in application security architecture role Following certificates are preferred; CISSP, SABSA as well asCloud certifications (AWS, Azure, or GCP) English is a Must, German and French are a plus Good understanding of cybersecurity frameworks and standards (ISO *****, NIST) Expertise in OWASP, SSDLC, and DevSecOps, with strong knowledge of secure software architecture Strong understanding of microservices security, API security, and IAM (e.G. OAuth, SAML, JWT) Knowledge of cloud-native security and CI/CD integration (e.G. Jenkins, GitHub Actions) Experience with container security and cloud platforms (e.G. AWS, Azure, GCP, Docker, Kubernetes) Our commitment to you: your benefits At Liebherr, we believe people are at the heart of our success. ## Description The Application Security Architect (m/f/d) designs and implements secure application architectures, defining security controls and policies to protect applications from threats.They provide strategic guidance to developers and security teams.The working location for this position will be in Madrid city where we are currently setting up a new office.We operate a hybrid model, requiring at least 40% of the working time on-site.Creating passion: your responsibilities Develop and enforce application security architecture frameworks, policies, standards, and best practices to align with compliance requirements (e.G. OWASP, NIST, ISO *****) Review and approve application security designs while ensuring secure software development and architecture Integrate security into the software development lifecycle (SDLC) by collaborating with development teams and enabling DevSecOps practices Adopt and promote a security-by-design approach with the different stakeholders Conduct threat modeling, security reviews, and risk assessments to proactively identify and mitigate vulnerabilities Evaluate, recommend, and oversee security tools and testing solutions (SAST, DAST, IAST) to strengthen application security Define security strategies for applications (e.G. IAM) and Implement Security Principles such as Zero Trust Actively contribute to the Coporate Information Security architecture community, sharing insights and best practices Collaborate with IT, EA, DevOps amd Engineering Team to align security Objectives Contributing your strengths: your qualifications Bachelor's/Master's in Cybersecurity, Computer Science, or related field 3+ years in cybersecurity, preferably in application security architecture role Following certificates are preferred; CISSP, SABSA as well asCloud certifications (AWS, Azure, or GCP) English is a Must, German and French are a plus Good understanding of cybersecurity frameworks and standards (ISO *****, NIST) Expertise in OWASP, SSDLC, and DevSecOps, with strong knowledge of secure software architecture Strong understanding of microservices security, API security, and IAM (e.G. OAuth, SAML, JWT) Knowledge of cloud-native security and CI/CD integration (e.G. Jenkins, GitHub Actions) Experience with container security and cloud platforms (e.G. AWS, Azure, GCP, Docker, Kubernetes) Our commitment to you: your benefits At Liebherr, we believe people are at the heart of our success.As part of our international team, you'll enjoy a secure role in a family-owned company that values innovation, collaboration, and long-term career growth: Competitive compensation and benefits package that recognizes your expertise Flexible and hybrid working model Creative freedom and responsibility to shape processes and solutions in our global transformation Continuous learning and development with tailored training and certification opportunities Meal vouchers Life and accident insurance Option to include a premium private health insurance package as part of the flexible remuneration A safe, stable and international workplace within a trusted family business that invests in people Please only use the online application option.Please note that we do not accept applications via recruitment agencies for this position. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)