> Markdown version of [/jobs/ext/2943842-security-engineer-appsec](https://www.wearedevelopers.com/jobs/ext/2943842-security-engineer-appsec). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - Appsec - **Company:** Chronos Consulting - **Location:** Almería, Spain - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Bash Shell, Cloud Computing, Cyber Security, Computer Programming, Continuous Integration, Python (Programming Language), Systems Development Life Cycle, Ruby, Secure Coding, Software Engineering, Scripting, Software Security, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** September 16, 2026 - **Apply:** https://www.buscojobs.com.es/security-engineer-appsec-en-almeria-ID-372113809 ## About the Role Requisitos principales4+ years in cybersecurity or software engineering with at least 2 years in application security Strong understanding of software development processes and engineers language Proficiency in programming/scripting languages (e.g., Ruby, Java, Python, JavaScript, Bash) Hands-on experience with vulnerability scanners and security testing tools Strong knowledge of threat modeling and security architecture reviews AI/ML security experience including risk assessment and prevention guidelines Cross-functional collaboration Training and knowledge sharing Proactive security advocacy Ruby, Java, Python, JavaScript, Bash Vulnerability scanners and security testing tools Threat modeling and security architecture reviews ## Description OverviewIn this role you will drive security across the product lifecycle for an AI-powered enterprise platform.You'll partner with engineering teams to bake security into design, development, and deployment, addressing risk early and continuously.You'll lead threat modeling, reviews, and secure coding practices while enabling product teams with training and automation.This is an opportunity to safeguard mission-critical, cloud-based systems at scale and shape secure software delivery.You will operate as a security advocate, delivering practical, engineering-friendly security improvements.ResponsabilidadesSecure SDLC integration with engineering teamsThreat modeling and design reviews to identify and mitigate risksSecurity enablement through training and championing secure coding practicesCode and CI/CD pipeline reviews with a security lensVulnerability discovery and triage with remediation guidanceSecurity tooling and automation to improve feedback loopsCross-functional collaboration with Product, SecOps, and Platform teamsSecurity advocacy through documentation, workshops, and coachingSecurity automation to improve detection, response, and compliance efficiencyRequisitos principales4+ years in cybersecurity or software engineering with at least 2 years in application securityStrong understanding of software development processes and engineers languageProficiency in programming/scripting languages (e.g., Ruby, Java, Python, JavaScript, Bash)Hands-on experience with vulnerability scanners and security testing toolsStrong knowledge of threat modeling and security architecture reviewsAI/ML security experience including risk assessment and prevention guidelinesCross-functional collaborationTraining and knowledge sharingProactive security advocacyRuby, Java, Python, JavaScript, BashVulnerability scanners and security testing toolsThreat modeling and security architecture reviews ## Related Videos - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)