> Markdown version of [/jobs/ext/2760761-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2760761-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Jobgether - **Location:** Málaga, Spain - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Software System Penetration Testing, Burp Suite, Cloud Computing, Distributed Systems, Python (Programming Language), OAuth, OpenID, Open Web Application Security, Systems Development Life Cycle, Security Assertion Markup Language (SAML), Secure Coding, Software Engineering, AI Infrastructure, Cloud Platform System, Software Security, AI Platforms, Security Orchestration, Automation & Response, Golang, Programming Languages - **Published:** September 6, 2026 - **Apply:** https://www.buscojobs.com.es/application-security-engineer-en-malaga-ID-370105829 ## About the Role Minimum of 4 years of experience in application security, secure software development, or related cybersecurity engineering roles. Strong understanding of application security risks, including OWASP Top 10 and common web and system vulnerabilities. Hands-on experience with secure coding practices in languages such as Python, Go, Java, or JavaScript. Proficiency in at least one programming language (e.g., Go or Python) with willingness to learn additional technologies. Practical experience with security testing tools such as Burp Suite, OWASP ZAP, Semgrep, or equivalent solutions. Experience conducting threat modeling exercises and security risk assessments. Solid understanding of authentication and authorization protocols such as SAML, OAuth, or OIDC. Strong analytical thinking and problem-solving skills with attention to detail in complex systems. Excellent communication skills in English, with the ability to explain technical security concepts to engineering teams. Ability to work independently while collaborating effectively in distributed and fast-paced environments. A proactive mindset and willingness to continuously learn and adapt to new security challenges. Security certifications such as OSCP or OSWE are considered a strong advantage. Experience with security automation, compliance translation, or exploitation of complex systems is a plus. ## Description This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Application Security Engineer based in Spain.Join a high-impact security engineering environment where you will play a key role in protecting and strengthening large-scale cloud-native applications that power next-generation AI infrastructure. In this role, you will work at the intersection of software engineering and cybersecurity, ensuring that applications are designed, built, and maintained with security at their core. You will collaborate closely with development teams to integrate security practices throughout the software development lifecycle, identify and remediate vulnerabilities, and improve the overall security posture of complex distributed systems. This position offers the opportunity to work with modern technologies, advanced cloud environments, and cutting-edge AI platforms while influencing how security is embedded into engineering practices at scale. It is ideal for a hands-on security professional who enjoys deep technical work, proactive risk identification, and cross-functional collaboration in a fast-paced engineering culture.AccountabilitiesIdentify, analyze, and remediate application security vulnerabilities using modern application security posture management (ASPM) tools and related security technologies.Build, maintain, and enhance ASPM tools, rules, and automation to strengthen application security across engineering teams.Integrate security best practices into the software development lifecycle (SDLC) in close collaboration with development and platform engineering teams.Conduct manual and automated penetration testing to identify weaknesses in applications and supporting infrastructure.Lead threat modeling sessions and risk assessments for both new and existing applications to proactively address security risks.Develop, maintain, and promote secure coding standards and guidelines for engineering teams.Serve as a subject matter expert in application security, providing guidance and support to internal teams across the organization.Stay up to date with emerging security threats, vulnerabilities, attack techniques, and mitigation strategies.Contribute to the continuous improvement of security engineering processes, automation, and tooling.RequirementsMinimum of 4 years of experience in application security, secure software development, or related cybersecurity engineering roles.Strong understanding of application security risks, including OWASP Top 10 and common web and system vulnerabilities.Hands-on experience with secure coding practices in languages such as Python, Go, Java, or JavaScript.Proficiency in at least one programming language (e.g., Go or Python) with willingness to learn additional technologies.Practical experience with security testing tools such as Burp Suite, OWASP ZAP, Semgrep, or equivalent solutions.Experience conducting threat modeling exercises and security risk assessments.Solid understanding of authentication and authorization protocols such as SAML, OAuth, or OIDC.Strong analytical thinking and problem-solving skills with attention to detail in complex systems.Excellent communication skills in English, with the ability to explain technical security concepts to engineering teams.Ability to work independently while collaborating effectively in distributed and fast-paced environments.A proactive mindset and willingness to continuously learn and adapt to new security challenges.Security certifications such as OSCP or OSWE are considered a strong advantage.Experience with security automation, compliance translation, or exploitation of complex systems is a plus.BenefitsCompetitive compensation package aligned with experience, skills, and location.Opportunity to work on large-scale, high-impact AI and cloud infrastructure projects.Flexible, remote-friendly working environment with strong autonomy and ownership.Career growth opportunities in a highly technical and fast-evolving security domain.Exposure to cutting-edge technologies in cloud computing, AI platforms, and distributed systems.Collaborative and innovative engineering culture focused on trust, learning, and impact.International environment working with highly skilled engineering and security teams.Inclusive workplace with equal opportunity policies and strong support for diversity.How Jobgether works:We use anAI-powered matching processto ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.We appreciate your interest and wish you the best!Why Apply Through Jobgether?Data Privacy Notice:By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.#LI-CL1We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)