Application Security Engineer - Barcelona

Contentsquare
Barcelona, Spain
5 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Tech stack

Artificial Intelligence Amazon Web Services Software System Penetration Testing Microsoft Azure Bash Shell Software as a Service Code Review Cyber Security Continuous Integration Python (Programming Language) Node.Js Open Web Application Security
+14 more
Secure Coding Software Vulnerability Management Datadog Scripting Large Language Models Software Security Mitre Att&ck Vue.js Containerization AngularJS Kubernetes NestJS Terraform Docker

Job description

OverviewIn this role you will strengthen the security of Contentsquare’s global SaaS products.You will partner with product and engineering teams to embed robust security practices across design, development, and deployment.You will lead threat modeling, secure-code reviews, and vulnerability management to prevent and mitigate risks.You will leverage automation and AI to scale security workflows within CI/CD and champion security-as-code.This position offers impact at scale within a security-first culture that values collaboration and continuous improvement.Compensaciones / BeneficiosHybrid/remote work policiesGenerous paid time-offStock optionsLifestyle allowanceEmployee Resource GroupsHackathon and virtual onboardingResponsabilidadesRun continuous automated security audits of global SaaS applications to detect misconfigurations and enforce benchmarksAct as security advisor to product and engineering teams, guiding threat modeling and AppSec reviews during designLead in-depth secure coding reviews and mentor developers on secure patternsArchitect and manage end-to-end vulnerability lifecycle across cloud and app layers with automationImplement AI-driven security workflows to automate vulnerability discovery and validation in CI/CDDrive shift-left initiatives by adding security checks to the automation stack and creating security-as-code toolsOversee private and public bug-bounty programs and coordinate with researchers for high-quality engagementCoordinate external penetration testing and customer security assessments as primary technical contactRespond to application-layer security incidents with root-cause analysis and defensive improvementsRequisitos principales3+ years in Application Security Operations in a high-growth SaaS or cloud-native environmentProficiency with NestJS, Vue.js, and AngularExperience with Snyk, Datadog ASM/AppSec (WAF), Google SecOps, and CrowdstrikeStrong understanding of AWS and Azure, Kubernetes/Docker security, and Terraform IaCAbility to apply AI/LLM tech to automate security tasksScripting experience (Python, Node.js, Shell) for building security toolingKnowledge of web protocols, OWASP Top 10, MITRE ATT&CK, and NIST CSFExperience in ethical hacking, CTFs, or bug bountyExcellent cross-functional collaboration and ability to explain risks to non-technical stakeholdersFluency in Englishcollaborationcommunicationanalytical rigorAppSecThreat modelingSecure coding

Requirements

Requisitos principales3+ years in Application Security Operations in a high-growth SaaS or cloud-native environment Proficiency with NestJS, Vue.js, and Angular Experience with Snyk, Datadog ASM/AppSec (WAF), Google SecOps, and Crowdstrike Strong understanding of AWS and Azure, Kubernetes/Docker security, and Terraform IaC Ability to apply AI/LLM tech to automate security tasks Scripting experience (Python, Node.js, Shell) for building security tooling Knowledge of web protocols, OWASP Top 10, MITRE ATT&CK, and NIST CSF Experience in ethical hacking, CTFs, or bug bounty Excellent cross-functional collaboration and ability to explain risks to non-technical stakeholders Fluency in English collaboration communication analytical rigor AppSec Threat modeling Secure coding

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

2:10 min

Analyzing the out-of-the-box security posture of Vue.js

Philippe De Ryck · LIVE

2:04 min

Comparing flexible tools against opinionated NestJS frameworks

Matteo Collina Matteo Collina · JS Congress

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all