> Markdown version of [/jobs/ext/2910457-lead-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2910457-lead-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Application Security Engineer - **Company:** EGYM GmbH - **Location:** München, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Cloud Engineering, Continuous Integration, DevOps, Python (Programming Language), Open Web Application Security, Secure Coding, Google Cloud, Cloud Platform System, Software Security, Kubernetes, Devsecops, Docker, Static Application Security Testing, Golang - **Published:** September 15, 2026 - **Apply:** https://www.jobfinder.de/job/lead-application-security-engineer-m-f-d/ ## About the Role demonstrate compliance with customer security requirementsYour fitness levelProfessional Experience: You have 5+ years of experience in Application Security, Software Security Engineering, or a closely related roleApplication Security Know-how: You have strong knowledge of OWASP Top 10, secure coding principles, threat modeling, and security testing approaches such as SAST and DASTTechnical Skills: You are comfortable working with modern software stacks and can read or write code (e.g. Go, Java, Python, or similar) to support reviews, PoCs, or toolingCloud & DevSecOps Understanding: You are familiar with cloud-native architectures, APIs, CI/CD pipelines, and containerized environmentsMindset: You enjoy working with engineers rather than acting as a gatekeeperWorking Style: You work in a structured, pragmatic, and collaborative way and feel comfortable shaping processes in a greenfield environmentLanguage Skills: You have professional proficiency in EnglishYour training goal for your first 6 monthsUnderstanding: You gain a deep understanding of our tech stack, development processes, and teamsPlanning: You create and align a plan to continuously improve the application security posture across the organizationExecution: You collaborate with engineering teams on concrete AppSec initiatives such as security tooling rollout and process improvementsImpact: You drive and deliver individual application security projects derived from the aligned planThe equipment we provideModern Tech Stack & AI Evolution: We don't just maintain; we evolve. Explore our Tech Radar to see our stack, and join us in building an AI-agentic, iterative, and incremental product culture where AI is a core accelerator of our development lifecycleLearning Time: Use 10% of your time on learning topics of your choice (conferences, hackathons, internal and external events, videos, books or innovation projects)International Team: Join our diverse and international team to collaborate with ## Description advisor, translating security requirements and findings into practical, developer-friendly solutionsCloud & Platform Security: You collaborate with SRE, DevOps, and platform teams to improve security in containerized and cloud-native setups (e.g. Kubernetes, Docker, GCP/AWS)Security Awareness: You contribute to improving security awareness and knowledge across engineering teams through documentation, guidance, and hands-on supportContinuous Improvement: You stay up to date with emerging threats, application security trends, and DevSecOps best practicesCompliance & Certification Leadership: You lead technical readiness and evidence collection for security certifications (e.g., SOC 2, ISO 27001) and emerging regulatory requirements, ensuring the product ecosystem meets global security StandardsTrust & Sales Enablement: You serve as the technical authority for security questionnaires, providing accurate and timely responses to prospects and clients to streamline the sales process and ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)