Security Application Engineer

Agileengine
Madrid, Spain
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Java (Programming Language) Artificial Intelligence Computer Programming Continuous Integration Python (Programming Language) Secure Coding Software Engineering Software Vulnerability Management Scripting Software Security Tenable Nessus Devsecops
+2 more
Static Application Security Testing Dynamic Application Security Testing

Job description

AgileEngine is an Inc. ** company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries.We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards.WHY JOIN US If you’re looking for a place to grow, make an impact, and work with people who care, we’d love to meet you!ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated hardened baseline deployment within a large-scale financial services security program.You will write Python scripts to integrate SAST, DAST, and SCA gates into CI/CD pipelines, tune scanning tools to reduce false positives, and provide code-level remediation guidance to Java and Python development teams.The role requires 3-5 years of combined software engineering and AppSec experience.WHAT YOU WILL DO Write and maintain the scripts necessary to integrate security gates (SAST, DAST, SCA) seamlessly into the CI/CD pipeline; Continuously tune and configure existing security scanning tools to eliminate false positives and deliver high-confidence alerts; Assist in coding and deploying automated hardened baselines and secure coding patterns; Work directly with product development teams to provide actionable, code-level remediation guidance in Java and Python.MUST HAVES ~3-5 years of commercial experience blending software engineering and DevSecOps/AppSec; ~ Solid coding proficiency in Python for automation and scripting; ~ Working knowledgeof modern CI/CD orchestration tools and practical experience interacting with vulnerability scoring frameworks; ~ Ability to operate with minimal supervision on day-to-day execution, reliably completing complex scripting and integration tasks; ~ Upper-intermediate English level.NICE TO HAVES Ability to comfortably read and navigate Java source code; Hands-on experiencewith specific CNAPP or ASPM platforms (e.G., Wiz); Basic understandingof application threat modeling.PERKS AND BENEFITS Professional growth : Mentorship, TechTalks, and personalized growth roadmaps.Competitive compensation : USD-based pay with education, fitness, and team activity budgets.Exciting projects : Modern solutions with Fortune 500 and top product companies.Flextime : Flexible schedule with remote and office options.Meet Our Recruitment Process Application - Coding Challenge - Video Interview - Technical Interview or Hiring Manager Interview Each step helps us understand your skills and overall fit.If it’s a match, you’ll receive an offer.#J-***-Ljbffr

Requirements

ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated hardened baseline deployment within a large-scale financial services security program. You will write Python scripts to integrate SAST, DAST, and SCA gates into CI/CD pipelines, tune scanning tools to reduce false positives, and provide code-level remediation guidance to Java and Python development teams. The role requires 3-5 years of combined software engineering and AppSec experience. WHAT YOU WILL DO Write and maintain the scripts necessary to integrate security gates (SAST, DAST, SCA) seamlessly into the CI/CD pipeline; Continuously tune and configure existing security scanning tools to eliminate false positives and deliver high-confidence alerts; Assist in coding and deploying automated hardened baselines and secure coding patterns; Work directly with product development teams to provide actionable, code-level remediation guidance in Java and Python. MUST HAVES ~3-5 years of commercial experience blending software engineering and DevSecOps/AppSec; ~ Solid coding proficiency in Python for automation and scripting; ~ Working knowledgeof modern CI/CD orchestration tools and practical experience interacting with vulnerability scoring frameworks; ~ Ability to operate with minimal supervision on day-to-day execution, reliably completing complex scripting and integration tasks; ~ Upper-intermediate English level. NICE TO HAVES Ability to comfortably read and navigate Java source code; Hands-on experiencewith specific CNAPP or ASPM platforms (e.G., Wiz); Basic understandingof application threat modeling. PERKS AND BENEFITS Professional growth : Mentorship, TechTalks, and personalized growth roadmaps.

Benefits & conditions

Competitive compensation : USD-based pay with education, fitness, and team activity budgets. Exciting projects : Modern solutions with Fortune 500 and top product companies. Flextime : Flexible schedule with remote and office options. Meet Our Recruitment Process Application - Coding Challenge - Video Interview - Technical Interview or Hiring Manager Interview Each step helps us understand your skills and overall fit. If it’s a match, you’ll receive an offer. #J-*****-Ljbffr

About the company

Madrid, España

AgileEngine is an Inc. ** company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards.WHY JOIN US If you’re looking for a place to grow, make an impact, and work with people who care, we’d love to meet you!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all