> Markdown version of [/jobs/ext/2276236-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2276236-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Technosylva - **Location:** Madrid, Spain (Remote available) - **Salary:** €40,000.0 - €55,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Software as a Service, Cloud Engineering, Code Review, Cyber Security, Continuous Integration, DevOps, Github, Key Management, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, Systems Integration, Software Vulnerability Management, Scripting, GitHub Copilot, Software Security, Gitlab, Machine Learning Operations, Terraform, GPT, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 28, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role + Minimum 10 years of experience across Application Security, S-SDLC/DevSecOps, or Software Engineering/Security Engineering. + Proven track record driving AppSec programs in medium or large organizations within modern SDLC, cloud-native, and SaaS environments. + Strong technical expertise in AppSec fundamentals: OWASP Top 10, API security, multi-tenant application security, threat modeling, and security architecture reviews. + Hands-on DevSecOps experience: CI/CD pipeline security, SAST/DAST, SCA, secrets management, container/Kubernetes security, and IaC security (Terraform preferred). + Strong understanding of software engineering practices, experience with modern development frameworks/APIs, and the ability to read and review production-grade code. + Strong business and operational capabilities: project management, executive-level reporting, documentation practices, and prioritizing work based on business risk. + Excellent communication, coordination, and interpersonal skills, with the ability to influence engineering teams without direct authority. + High level of ownership, autonomy, maturity, and proactive problem-solving. PREFERRED QUALIFICATIONS + Penetration testing experience, red teaming, or an offensive security background. + Experience leading vulnerability management programs, security automation, and scripting. + Practical experience applying AI/ML tools in development and cybersecurity (e.g., ChatGPT, Claude, GitHub Copilot). + Specialized experience with GitLab / GitHub Security features. + Security certifications such as CSSLP, CISSP, OSCP, GIAC, or Azure/AWS certifications. ## Description Technosylva is seeking a highly experienced Senior Application Security Engineer to elevate and mature our Application Security (AppSec) program across a modern cloud-native software environment. This role is not limited to technical execution. We are looking for a security professional who combines deep hands-on AppSec expertise with strong business, communication, coordination, and program execution skills. The ideal candidate will partner closely with Engineering, Product, Platform, Infrastructure, and Security leadership to drive scalable security improvements across the software development lifecycle (S-SDLC). This position will play a key role in transforming AppSec from a primarily tooling-focused function into a strategic, measurable, and business-aligned security capability. RESPONSABILITIES + Lead the evolution of Technosylva's Application Security program and roadmap, defining and improving secure SDLC processes across all engineering teams. + Establish scalable security-by-design practices integrated into development workflows, driving adoption of secure coding standards, threat modeling, and security architecture reviews. + Build practical and measurable AppSec KPIs and reporting for leadership. + Improve and optimize GitLab/GitHub security capabilities and integrations (SAST, DAST, dependency scanning, container scanning, secrets detection, and IaC security workflows). + Work closely with DevOps and Engineering teams to embed security into CI/CD pipelines, defining risk-based security gates and exception processes while reducing developer friction. + Partner directly with developers, architects, and technical leads to remediate vulnerabilities, translate security requirements into actionable tasks, and conduct code reviews. + Establish mature application vulnerability management processes: improve triage, prioritization based on business risk, SLAs, tracking through closure, and executive reporting. + Own and drive AppSec initiatives from planning through execution across cross-functional teams (Engineering, Infrastructure, Product, Security), producing clear documentation and implementation plans. + Help improve security culture within engineering teams by delivering secure coding guidance, workshops, awareness sessions, and mentoring junior engineers. + Act as a trusted advisor rather than only an enforcement function, adapting communication effectively for both technical and non-technical stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)