Application Security Engineer (Senior) Id71663

Agileengine
Barcelona, Spain
10 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
6 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Java (Programming Language) Artificial Intelligence Continuous Integration Python (Programming Language) Systems Development Life Cycle Secure Coding Software Engineering Scripting Large Language Models Software Security Devsecops Security Orchestration, Automation & Response
+2 more
Static Application Security Testing Dynamic Application Security Testing

Job description

Job Description AgileEngine is an Inc. ** company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries.We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards.WHY JOIN US If you’re looking for a place to grow, make an impact, and work with people who care, we’d love to meet you!ABOUT THE ROLE We are looking for a Senior Application Security Engineer to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration across a large-scale financial services program.You will work in Python and Java to deploy and tune SAST, DAST, and SCA tools, provide code-level remediation guidance to development teams, and operate with full autonomy building automated security runbooks.The role requires 6+ years of software engineering experience with a strong AppSec and DevSecOps focus.WHAT YOU WILL DO - Engineer and deploy AI-enabled secure code scanning capabilities and Golden Images to drive secure-from-the-start adoption; - Automate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows; - Architectthe integration of continuous security scanning tools (SAST, DAST, SCA) into enterprise CI/CD pipelines, tuning them to eliminate noise; - Act as a senior technical SME, reading and reviewing complex application code (Java/Python) to provide software engineers with highly specific, code-level remediation guidance.MUST HAVES - 6+ years of software engineering experience with a strong subsequent focus on Application Security and DevSecOps; - Strong coding and architectural proficiency in Python (for security automation and scripting) and/or Java (to confidently read, review, and secure enterprise source code); - Deep, hands-on expertise deploying and tuning modern application security testing tools (SAST , DAST , SCA ) and integrating them into complex CI/CD orchestration ecosystems; - Fully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks; - Upper-intermediate English level.NICE TO HAVES - Experience integrating LLMs, AI agents, or automated coding assistants to streamline vulnerability triaging or secure code generation; - Advanced application threat modeling experience.PERKS AND BENEFITS - Professional growth : Mentorship, TechTalks, and personalized growth roadmaps.- Competitive compensation : USD-based pay with education, fitness, and team activity budgets.- Exciting projects : Modern solutions with Fortune 500 and top product companies.- Flextime : Flexible schedule with remote and office options.Meet Our Recruitment Process Application ? Coding Challenge ? Video Interview ? Technical Interview or Hiring Manager Interview Each step helps us understand your skills and overall fit.If it’s a match, you’ll receive an offer.Requirements 6+ years of software engineering experience with a strong subsequent focus on Application Security and DevSecOps.Strong coding and architectural proficiency in Python (for security automation and scripting) and/or Java (to confidently read, review, and secure enterprise source code).Deep, hands-on expertise deploying and tuning modern application security testing tools (SAST, DAST, SCA) and integrating them into complex CI/CD orchestration ecosystems.Fully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks.

Requirements

ABOUT THE ROLE We are looking for a Senior Application Security Engineer to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration across a large-scale financial services program., The role requires 6+ years of software engineering experience with a strong AppSec and DevSecOps focus. WHAT YOU WILL DO - Engineer and deploy AI-enabled secure code scanning capabilities and Golden Images to drive secure-from-the-start adoption; - Automate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows; - Architectthe integration of continuous security scanning tools (SAST, DAST, SCA) into enterprise CI/CD pipelines, tuning them to eliminate noise; - Act as a senior technical SME, reading and reviewing complex application code (Java/Python) to provide software engineers with highly specific, code-level remediation guidance. MUST HAVES - 6+ years of software engineering experience with a strong subsequent focus on Application Security and DevSecOps; - Strong coding and architectural proficiency in Python (for security automation and scripting) and/or Java (to confidently read, review, and secure enterprise source code); - Deep, hands-on expertise deploying and tuning modern application security testing tools (SAST , DAST , SCA ) and integrating them into complex CI/CD orchestration ecosystems; - Fully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks; - Upper-intermediate English level. NICE TO HAVES - Experience integrating LLMs, AI agents, or automated coding assistants to streamline vulnerability triaging or secure code generation; - Advanced application threat modeling experience. PERKS AND BENEFITS - Professional growth : Mentorship, TechTalks, and personalized growth roadmaps., Requirements 6+ years of software engineering experience with a strong subsequent focus on Application Security and DevSecOps. Strong coding and architectural proficiency in Python (for security automation and scripting) and/or Java (to confidently read, review, and secure enterprise source code). Deep, hands-on expertise deploying and tuning modern application security testing tools (SAST, DAST, SCA) and integrating them into complex CI/CD orchestration ecosystems. Fully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks.

Benefits & conditions

Competitive compensation : USD-based pay with education, fitness, and team activity budgets.

  • Exciting projects : Modern solutions with Fortune 500 and top product companies.
  • Flextime : Flexible schedule with remote and office options. Meet Our Recruitment Process Application ? Coding Challenge ? Video Interview ? Technical Interview or Hiring Manager Interview Each step helps us understand your skills and overall fit.

About the company

Barcelona, España

Job Description AgileEngine is an Inc. ** company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards. WHY JOIN US If you’re looking for a place to grow, make an impact, and work with people who care, we’d love to meet you!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

Videos

See all

Related articles

See all