> Markdown version of [/jobs/ext/2394804-hq-senior-application-security-engineer-remote](https://www.wearedevelopers.com/jobs/ext/2394804-hq-senior-application-security-engineer-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # HQ - Senior Application Security Engineer (Remote) - **Company:** Job&talent - **Location:** Madrid, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Burp Suite, Code Review, Cyber Security, Python (Programming Language), Networking Basics, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Security Software, Software Engineering, TCP/IP, Software Vulnerability Management, Scripting, Spring Cloud, Software Security, Static Application Security Testing - **Published:** August 7, 2026 - **Apply:** https://www.jobleads.com/es/job/e74e960020c9df0901d9a1f00965b5fc7 ## About the Role * 3-4 years of experience in Information Security, including at least 2 years in Application Security. * Strong experience with Secure SDLC, threat modelling, application security reviews and secure code reviews. * Hands-on experience with SAST, SCA and automated security testing integrated into CI/CD pipelines. * Strong knowledge of OWASP Top 10, OWASP ASVS, API Security and secure coding best practices. * Experience implementing and managing WAF solutions, as well as conducting internal penetration testing (including APIs using Burp Suite). * Solid understanding of Kubernetes security, cloud-native applications and networking fundamentals (HTTP, HTTPS, TCP/IP). * Basic scripting or development experience, preferably in Python. * Excellent communication skills, with the ability to influence engineering teams and explain complex security concepts to technical and non-technical stakeholders. ## Description We are looking for a proactive and experienced Senior Application Security Engineer to help build secure products at scale. As a trusted partner to Engineering and Product teams, you will drive security by design across the Software Development Lifecycle (SDLC), leading initiatives such as threat modelling, secure code reviews, security automation, and developer enablement. You will play a key role in shaping our Application Security strategy, helping us build secure, resilient products while enabling engineering teams to move fast with confidence., * Act as the Application Security Subject Matter Expert (SME), partnering with Engineering and Product teams to embed security throughout the SDLC. * Lead application security reviews, threat modelling, code reviews and penetration testing to identify and mitigate security risks. * Design, implement and automate security controls across CI/CD pipelines, including SAST, SCA and other AppSec tooling. * Drive the technical roadmap of the Application Security program, improving secure development practices and scaling security initiatives across the organisation. * Improve and manage application security controls, including WAF, Kubernetes security and vulnerability management. * Mentor Security Champions and junior engineers, promoting a strong security culture across development teams. * Define and communicate meaningful Application Security metrics to measure risk reduction and program effectiveness. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)