> Markdown version of [/jobs/ext/1683073-application-security-engineer-id70123](https://www.wearedevelopers.com/jobs/ext/1683073-application-security-engineer-id70123). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer Id70123 - **Company:** Agileengine - **Location:** Zaragoza, Spain - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Computer Programming, Continuous Integration, Secure Coding, Software Engineering, Software Vulnerability Management, Scripting, Software Security, Tenable Nessus, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 31, 2026 - **Apply:** https://www.buscojobs.com.es/application-security-engineer-id-70123-en-zaragoza-ID-364305670 ## About the Role 3-5 years of commercial experience blending software engineering and DevSecOps/AppSec; Solid coding proficiency in Python for automation and scripting; Working knowledge of modern CI/CD orchestration tools and practical experience interacting with vulnerability scoring frameworks; Ability to operate with minimal supervision on day-to-day execution, reliably completing complex scripting and integration tasks; Upper-intermediate English level. NICE TO HAVES Ability to comfortably read and navigate Java source code; Hands?on experience with specific CNAPP or ASPM platforms (e.g., Wiz); Basic understanding of application threat modeling. ## Description Job DescriptionAgileEngine is an Inc. **** company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas such as application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards.WHY JOIN USIf you're looking for a place to grow, make an impact, and work with people who care, we'd love to meet you!ABOUT THE ROLEWe are looking for aMiddle Application Security Engineerto execute hands?on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated hardened baseline deployment within a large?scale financial services security program. You will write Python scripts to integrate SAST, DAST, and SCA gates into CI/CD pipelines, tune scanning tools to reduce false positives, and provide code?level remediation guidance to Java and Python development teams. The role requires 3-5 years of combined software engineering and AppSec experience.WHAT YOU WILL DOWrite and maintain the scripts necessary to integrate security gates (SAST, DAST, SCA) seamlessly into the CI/CD pipeline;Continuously tune and configure existing security scanning tools to eliminate false positives and deliver high?confidence alerts;Assist in coding and deploying automated hardened baselines and secure coding patterns;Work directly with product development teams to provide actionable, code-level remediation guidance in Java and Python.MUST HAVES3-5 years of commercial experience blending software engineering and DevSecOps/AppSec;Solid coding proficiency inPythonfor automation and scripting;Working knowledge of modern CI/CD orchestration tools and practical experience interacting with vulnerability scoring frameworks;Ability to operate with minimal supervision on day-to-day execution, reliably completing complex scripting and integration tasks;Upper-intermediate English level.NICE TO HAVESAbility to comfortably read and navigate Java source code;Hands?on experience with specific CNAPP or ASPM platforms (e.g., Wiz);Basic understanding of application threat modeling.PERKS AND BENEFITSProfessional growth:Mentorship, TechTalks, and personalized growth roadmaps.Competitive compensation:USD-based pay with education, fitness, and team activity budgets.Exciting projects:Modern solutions with Fortune 500 and top product companies.Flextime:Flexible schedule with remote and office options.Meet Our Recruitment ProcessApplication ? Coding Challenge ? Video Interview ? Technical Interview or Hiring Manager Interview. Each step helps us understand your skills and overall fit. If it's a match, you'll receive an offer.#J-*****-Ljbffr ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)