> Markdown version of [/jobs/ext/2943573-application-security-research-engineer](https://www.wearedevelopers.com/jobs/ext/2943573-application-security-research-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Research Engineer - **Company:** Commit - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Architectural Patterns, Burp Suite, Cloud Computing, Cloud Engineering, Fuzz Testing, Systems Integration, Large Language Models, Software Security, Backend, Kubernetes, Metasploit, Free and Open-Source Software, Software Coding, Vulnerability Analysis, Microservices - **Published:** September 16, 2026 - **Apply:** https://www.buscojobs.com.es/application-security-research-engineer-en-madrid-ID-370572677 ## About the Role 5+ year experience in Research and penetration testing. Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies. AI and LLM Penetration testing knowldge and Experience Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and Custom Security Tools development. Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes). Familiarity with secure software architecture and typical attack vectors. Demonstrated ability to lead security testing engagements and report technical findings effectively. Experience building or integrating automated PT or fuzzing pipelines is a strong advantage. Knowledge and hands?on experience with SSDLC tools and CI/CD pipelines, Publications or open-source contributions in the security domain are a plus. #J-*****-Ljbffr ## Description We are looking for Application Security Research Engineer in Barselona.In this role, you will work with a team of researchers and ethical hackers focused on offensive security testing, automated exploit discovery, and advanced application security research.Your work will directly influence the security posture of company products and help scale secure-by-design principles.This is a hands?on technical role with a strong emphasis on offensive security, code exploitation, automation, and innovation.ResponsibilitiesHelp to reshape company Product SecurityPlan and execute advanced penetration testing campaigns.Develop tools and frameworks for scalable security testing and fuzzing.Lead Security innovation by building and managing penetration testing tools \ AI AgentsAnalyze vulnerabilities, perform root cause analysis, and develop proofs of concept.Identify systemic product weaknesses and help define long?term mitigations.Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.Contribute to security research publications, CVE submissions, and industry knowledge sharing.Continuously evolve internal testing capabilities using modern tooling and AI-assisted approaches.Requirements5+ year experience in Research and penetration testing.Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies.AI and LLM Penetration testing knowldge and ExperienceExperience with penetration testing tools (Burp Suite, Metasploit, etc.) and Custom Security Tools development.Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes).Familiarity with secure software architecture and typical attack vectors.Demonstrated ability to lead security testing engagements and report technical findings effectively.Experience building or integrating automated PT or fuzzing pipelines is a strong advantage.Knowledge and hands?on experience with SSDLC tools and CI/CD pipelines,Publications or open-source contributions in the security domain are a plus.#J-*****-Ljbffr ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)