Application Security Engineer (all genders)

About You
Berlin, Germany
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work
Job source

Tech stack

JavaScript (Programming Language) PHP (Programming Language) Amazon Web Services Application Firewall Software System Penetration Testing Code Review Computer Programming Python (Programming Language) Laravel Software Maintenance Akamai Secure Coding
+6 more
Scripting Software Security Gitlab-ci Kubernetes Cloudflare Golang

Job description

We are looking for an Application Security Engineer (all genders) to join the Application Security circle of our IT-Security unit, dedicated to protecting our online shop, our corporate systems and our customers.

In this role, you will hack internal systems, design and implement security measures to safeguard our infrastructure, applications, and data. You will work closely with other security engineers, developers and IT teams to ensure security best practices, automate security processes, and respond to emerging threats.

  • Conduct regular penetration tests and code reviews
  • Advise in the setup and maintenance of applications and infrastructure (usually hosted in AWS/Kubernetes)
  • Triage and respond to monitoring events
  • Optimization and automation of security auditing processes. This could also include setting up attack infrastructure, writing scripts in Python and implementing security scanning in Gitlab CI
  • Take part in some incident response activities within the SOC, which include occasional 24/7 on-call

Requirements

  • Security engineering
  • Technical Project Management skills
  • Threat modeling
  • Penetration testing
  • Secure code review
  • Cloud experience: AWS, Bonus: GCP, Azure
  • Programming experience: Python required, Bonus: PHP, JavaScript, Go
  • Red teaming is a plus

Nice to have

  • Certificates:
  • Offensive Security certificates; e.g. OSCP, OSWP, etc.
  • Knowledge of Laravel / PHP.
  • Ability to read and understand JavaScript
  • Ability to read and understand Go
  • Experience with incident response activities
  • Experience with web application firewalls, CDN providers, e.g. Cloudflare, Akamai
  • Experience with Gitlab CI/CD Pipelines

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on de.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

2:34 min

Leveraging Akamai edge workers for broad geographic scale

Austin Gil · LIVE

9:43 min

Tracing the HTTP request lifecycle inside Laravel

Rumpel Christoph · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:33 min

Case study on adopting Kubernetes and Golang effectively

Andrew Holway · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all