> Markdown version of [/jobs/ext/2725782-security-engineer](https://www.wearedevelopers.com/jobs/ext/2725782-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** api GmbH - **Location:** Frankfurt am Main, Germany (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Business Logic, Software System Penetration Testing, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Continuous Integration, Github, Octopus Deploy, PCI Data Security Standards, Systems Integration, TypeScript, Software Vulnerability Management, Google Cloud, Software Security, Multi-Cloud, Amazon Virtual Private Cloud (VPC), Kubernetes, Information Technology, Purple Team (Cyber Security), Terraform, Service Stack, Static Application Security Testing, Vulnerability Analysis, Golang, Programming Languages, Dynamic Application Security Testing - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/senior-security-engineer-appsec-d-f-m-vivenu-9921640 ## About the Role * Experience: 5+ years of dedicated Security Engineering experience, ideally within a high-growth SaaS, E-commerce, or Fintech environment. * SaaS Deep-Dive: The ability to dive deep into the business logic of a complex SaaS application to uncover and verify elusive attack vectors. * Web and API Security Mastery: a deep understanding of web/API attack vectors and scalable best practices and how to run workloads securely in a cloud environment (k8s, AWS/GCP/Azure) * Ownership: A proven track record of autonomously driving security initiatives from conception to completion. * Automation Mindset: Proficiency in at least one programming language for scripting and security tool development (bonus points for automating GRC evidence collection). * Education: A Bachelor's or Master's degree in Computer Science, Cybersecurity, IT, or a related technical field (or equivalent practical experience). Preferred: * Experience navigating PCI DSS script security. * A background in Red/Purple Team operations and advanced penetration testing, paired with the empathy and collaboration skills needed to help dev teams fix software vulnerabilities. * Hands-on experience with Terraform for securing infrastructure-as-code and integrating security testing. * Familiarity with our modern tech stack: GCP, Golang, and TypeScript. Why join vivenu? ## Description * Modern Technology Stack: Dive into securing a massive TypeScript monolith alongside Go supporting services, giving you hands-on experience in modern language security and advanced GitHub CI/CD pipeline hardening. * Web and API: secure the application of the vivenu platform which provides customers with an out-of-the-box ticketing software as well as the underlying API structure * Complex Multi-Cloud Architecture: Challenge your skills against a sophisticated multi-tenant, multi-region environment spanning k8s, GCP (our primary compute) and and separate database services * Cutting-Edge Deployment: Secure a next-gen Kubernetes "satellite architecture" utilizing hardened private compute nodes, VPC peering, and Argo CD for GitOps-a true, modern cloud-native security mandate. As a Senior Security Engineer - AppSec (d/f/m) your responsibilities will include: * Be a Trusted Advisor: Partner closely with engineering teams to champion security-by-design and elevate our overall security posture. * Offensive & Defensive Testing: Coordinate and execute threat modeling and advanced security tests across our product and underlying infrastructure. * Lead Next-Gen Vulnerability Management: Drive triage and remediation using modern, risk-based principles like EPSS, while leveraging AI technologies to accelerate security testing at scale. * Pioneer Security-as-Code: Design, implement, and automate security checks and guardrails (SAST, DAST, and secret scanning) directly into CI/CD pipelines. * Review & Refine: Perform deep-dive code and configuration reviews, advocating for secure coding practices that support a proactive shift-left strategy. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)