> Markdown version of [/jobs/ext/2789898-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2789898-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Distribusion - **Location:** Berlin, Germany (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Cloud Computing, Cloud Computing Security, Code Review, Continuous Integration, DevOps, Identity and Access Management, Python (Programming Language), OAuth, Ruby, Software Engineering, TypeScript, Web Application Frameworks, Software Security, Cross-Site Scripting (XSS), Rate Limiting, Gitlab-ci, Kubernetes, Production Code, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** September 8, 2026 - **Apply:** https://startup.jobs/senior-application-security-engineer-all-genders-distribusion-9946260 ## About the Role * You bring 5+ years in AppSec (or 3+ years plus a strong software engineering/web-pentesting background), with a track record of true ownership. * You read and write production code (Python, Go, TypeScript, Ruby, etc.) and deeply understand web frameworks, CI/CD, and Kubernetes. * You have deep knowledge of web and API security, specifically authentication/authorization models (OAuth2, JWT), rate limiting, tenant isolation, IDOR, and XSS. * You have strong cloud security fundamentals (GCP preferred), specifically regarding public exposure, secrets hygiene, and WAF rules. * You prioritize by real-world risk, propose trade-offs rather than demanding perfection, and communicate complex risks plainly to engineers and leadership. * Bonus Points: You have experience securing high-volume, multi-tenant B2B APIs and utilizing AI tooling to accelerate triage and review. ## Description * Lead threat modeling and secure design reviews for high-risk changes, partner integrations, and payment flows. * Implement, tune, and enforce security gates in GitLab CI/CD (SAST, SCA, secrets scanning, and DAST) while minimizing developer friction. * Act as the primary technical owner for triaging, reproducing, and prioritizing findings from bug bounties, partner pentests, and automated scanners. * Work hands-on with the DevOps team to implement GCP organizational policies, IAM least-privilege architectures, and Cloud Armor (WAF/rate limiting). * Establish a security-champions network across engineering squads and leverage automation/AI-assisted tooling to scale code reviews effectively. Workplace: We are a remote-first company with teams located around the Globe. Also, the HQ office is in Berlin, where the team often meets., Your Talent Partner (TP) and point of contact is Lorena Rebenciuc, and the Hiring Manager (HM) is Ilya Isakov. For any queries, contact your Talent Partner at talent@distribusion.com. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)