Application Security Engineer (Senior) Id71663

Agileengine
Valencia, Spain
11 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
6 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Java (Programming Language) Artificial Intelligence Continuous Integration Python (Programming Language) Systems Development Life Cycle Secure Coding Software Engineering Scripting Large Language Models Software Security Devsecops Security Orchestration, Automation & Response
+2 more
Static Application Security Testing Dynamic Application Security Testing

Job description

ph3About the Role /h3 pWe are looking for a bSenior Application Security Engineer /b to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration across a large-scale financial services program.You will work in Python and Java to deploy and tune SAST, DAST, and SCA tools, provide code-level remediation guidance to development teams, and operate with full autonomy building automated security runbooks.The role requires 6+ years of software engineering experience with a strong AppSec and DevSecOps focus./p h3What You Will Do /h3 ul liEngineer and deploy AI-enabled secure code scanning capabilities and Golden Images to drive secure-from-the-start adoption./li liAutomate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows./li liArchitect the integration of continuous security scanning tools (SAST, DAST, SCA) into enterprise CI/CD pipelines, tuning them to eliminate noise./li liAct as a senior technical SME, reading and reviewing complex application code (Java/Python) to provide software engineers with highly specific, code-level remediation guidance./li /ul h3Must Haves /h3 ul li6+ years of software engineering experience with a strong subsequent focus on Application Security and DevSecOps./li liStrong coding and architectural proficiency in bPython /b (for security automation and scripting) and/or bJava /b (to confidently read, review, and secure enterprise source code)./li liDeep, hands?on expertise deploying and tuning modern application security testing tools (bSAST /b, bDAST /b, bSCA /b) and integrating them into complex bCI/CD /b orchestration ecosystems./li liFully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks./li liUpper?intermediate English level./li /ul h3Nice to Haves /h3 ul liExperience integrating LLMs, AI agents, or automated coding assistants to streamline vulnerability triaging or secure code generation./li liAdvanced application threat modeling experience./li /ul h3Perks and Benefits /h3 ul libProfessional growth /b: Mentorship, TechTalks, and personalized growth roadmaps./li libCompetitive compensation /b: USD-based pay with education, fitness, and team activity budgets./li libExciting projects /b: Modern solutions with Fortune 500 and top product companies./li libFlextime /b: Flexible schedule with remote and office options./li /ul /p #J-*****-Ljbffr

Requirements

ph3About the Role /h3 pWe are looking for a bSenior Application Security Engineer /b to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration across a large-scale financial services program., The role requires 6+ years of software engineering experience with a strong AppSec and DevSecOps focus. /p h3What You Will Do /h3 ul liEngineer and deploy AI-enabled secure code scanning capabilities and Golden Images to drive secure-from-the-start adoption. /li liAutomate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows. /li liArchitect the integration of continuous security scanning tools (SAST, DAST, SCA) into enterprise CI/CD pipelines, tuning them to eliminate noise. /li liAct as a senior technical SME, reading and reviewing complex application code (Java/Python) to provide software engineers with highly specific, code-level remediation guidance. /li /ul h3Must Haves /h3 ul li6+ years of software engineering experience with a strong subsequent focus on Application Security and DevSecOps. /li liStrong coding and architectural proficiency in bPython /b (for security automation and scripting) and/or bJava /b (to confidently read, review, and secure enterprise source code). /li liDeep, hands?on expertise deploying and tuning modern application security testing tools (bSAST /b, bDAST /b, bSCA /b) and integrating them into complex bCI/CD /b orchestration ecosystems. /li liFully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks. /li liUpper?intermediate English level. /li /ul h3Nice to Haves /h3 ul liExperience integrating LLMs, AI agents, or automated coding assistants to streamline vulnerability triaging or secure code generation. /li liAdvanced application threat modeling experience.

About the company

li /ul h3Perks and Benefits /h3 ul libProfessional growth /b: Mentorship, TechTalks, and personalized growth roadmaps. /li libCompetitive compensation /b: USD-based pay with education, fitness, and team activity budgets. /li libExciting projects /b: Modern solutions with Fortune 500 and top product companies. /li libFlextime /b: Flexible schedule with remote and office options. /li /ul /p #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all