Senior Application Security Engineer

Maisa
Santiago de Compostela, Spain
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
Spanish

Tech stack

Kubernetes Security Java (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Computing Platforms Code Review Continuous Integration Github Python (Programming Language) Node.Js Systems Development Life Cycle Secure Coding
+15 more
Software Deployment SonarQube Tripwire TypeScript Software Vulnerability Management Software Security Mttr Cross-Site Scripting (XSS) Git GWAPT Infrastructure Automation Frameworks Static Application Security Testing Golang Programming Languages Dynamic Application Security Testing

Job description

Join to apply for theSenior Application Security Engineerrole atMaisaWelcome to Maisa - Making AI Accountable!Our agentic process automation platform helps enterprises automate complex, decision-heavy processes that traditional automation can’t handle and GenAI can’t be trusted with.We enable organizations to scale operations, resist hallucinations, and bring end-to-end visibility and control to your most complex processes.Powered by a new kind of computing platform, Maisa combines AI-driven problem solving with programmatic execution, so every action is reliable, auditable, and built for enterprise scale.About the role…We’re looking for a Senior Application Security Engineer to own and scale our Vulnerability Management Program, embed security into CI/CD pipelines, and perform deep code security reviews. This hands?on role partners with Engineering, SRE, and GRC to measurably reduce application risk across our portfolio. We value engineers who automate first, build guardrails instead of gates, and help teams ship secure software fast.What you’ll do…Vulnerability Management (Program Ownership):Define and operate end-to-end vulnerability management lifecycle (SCA, SAST, DAST, container, IaC scanning)Establish risk?based triage using CVSS and exploited vulnerability catalogsIntegrate scanners intoCI/CD(GitHub Actions) and container registriesBuild automated patch/dependency?update pipelines (e.g.,Dependabotautomated PRs)Generate and storeSBOMs; implement image signing and provenance (Sigstore, cosign, SLSA)Track MTTR, time?to?first?fix, and executive?level security metricsPartner with GRC to align withISO **andSOC 2frameworksSecurity in CI/CD (Shift?Left & Supply Chain):EmbedSAST, SCA, secret scanning, and IaC checks into pipelinesEnforce branch protections, mandatory code reviews, and artifact signingChampion least?privilege pipelines, ephemeral runners, and hardened build environmentsPublish attestations and SBOMs with every releaseCode Security Reviews (Depth Where It Matters):Perform targeted manual reviews of critical code paths (auth/authz, crypto, multi?tenant boundaries, PII handling)Write concise, actionable review notes with clear risk statements and remediation guidanceCollaborate with developers to land fixes quicklyContribute to secure coding patterns and internal librariesDeliver developer training based on real findingsWhat you’ll bring…Strong demonstrable experience in Application Security or Security EngineeringProven ownership of a Vulnerability Management or Secure SDLC programStrong hands?on skills with at least two programming languages: Go, Python, TypeScript/Node.js, or JavaExperience integrating SAST/SCA/DAST/Secrets/IaC tools into Git-based CI/CD (GitHub Actions preferred)Solid understanding of container and Kubernetes security (image scanning, admission controls, PodSecurity)Deep knowledge of authn/authz, cryptography, SSRF/XSS/Injection classes, and modern web/API architecturesFamiliarity with ISO ** and SOC 2 requirements for software securityExcellent communication and stakeholder management skillsFluent Spanish (essential for client interactions)Any familiarity with tools such as: Semgrep, CodeQL, Trivy, Grype, Snyk, Dependabot, Checkov, tfsec, ZAP, Burp, SonarQube would be beneficial. As would any formal certifications such as OSWE, OSCP, GCSA, GWAPT, GWEB, CSSLP.You will be joining one of Europe’s most exciting early?stage AI start?ups, where you’ll have the opportunity to work with cutting?edge Agentic Process Automation that’s reshaping how enterprises approach AI deployment. You will get to directly influence how major multinational organizations transform critical business processes, working on genuinely differentiated technology that solves real enterprise AI challenges.Following our recent $25m Seed Round, backed by leading Venture Capital firms including Creandum, Forgepoint, NFX, and Village Global, we’re scaling quickly and realizing significant enterprise traction. This is your opportunity to help solve real AI enterprise challenges, working alongside deep technical and industry experts, where you will be challenged daily and expedite your learning and development.Maisa is committed to Equal Employment Opportunity through attracting and retaining a complementary team of employees and building an inclusive environment for all.Seniority levelMid?Senior levelEmployment typeFull?timeJob functionIT Services and IT ConsultingReferrals increase your chances of interviewing at Maisa by 2xGet notified about new Senior Application Security Engineer jobs inSpain.We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.#J-*****-Ljbffr

Requirements

Strong demonstrable experience in Application Security or Security Engineering Proven ownership of a Vulnerability Management or Secure SDLC program Strong hands?on skills with at least two programming languages: Go, Python, TypeScript/Node.js, or Java Experience integrating SAST/SCA/DAST/Secrets/IaC tools into Git-based CI/CD (GitHub Actions preferred) Solid understanding of container and Kubernetes security (image scanning, admission controls, PodSecurity) Deep knowledge of authn/authz, cryptography, SSRF/XSS/Injection classes, and modern web/API architectures Familiarity with ISO ***** and SOC 2 requirements for software security Excellent communication and stakeholder management skills Fluent Spanish (essential for client interactions) Any familiarity with tools such as: Semgrep, CodeQL, Trivy, Grype, Snyk, Dependabot, Checkov, tfsec, ZAP, Burp, SonarQube would be beneficial. As would any formal certifications such as OSWE, OSCP, GCSA, GWAPT, GWEB, CSSLP.

About the company

You will be joining one of Europe’s most exciting early?stage AI start?ups, where you’ll have the opportunity to work with cutting?edge Agentic Process Automation that’s reshaping how enterprises approach AI deployment. You will get to directly influence how major multinational organizations transform critical business processes, working on genuinely differentiated technology that solves real enterprise AI challenges. Following our recent $25m Seed Round, backed by leading Venture Capital firms including Creandum, Forgepoint, NFX, and Village Global, we’re scaling quickly and realizing significant enterprise traction. This is your opportunity to help solve real AI enterprise challenges, working alongside deep technical and industry experts, where you will be challenged daily and expedite your learning and development. Maisa is committed to Equal Employment Opportunity through attracting and retaining a complementary team of employees and building an inclusive environment for all. Seniority level

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · WWC 2021

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all