> Markdown version of [/jobs/ext/2997494-application-security-engineer-relocation-to-barcelona](https://www.wearedevelopers.com/jobs/ext/2997494-application-security-engineer-relocation-to-barcelona). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer (Relocation To Barcelona) - **Company:** Commit - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Architectural Patterns, Burp Suite, Cloud Computing, Cloud Engineering, Fuzz Testing, Systems Integration, Large Language Models, Software Security, Backend, Kubernetes, Metasploit, Software Coding, Vulnerability Analysis, Microservices - **Published:** September 19, 2026 - **Apply:** https://www.buscojobs.com.es/application-security-engineer-relocation-to-barcelona-en-madrid-ID-370467242 ## About the Role 4+ year experience in Research and penetration testing. Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies. AI and LLM Penetration testing knowldge and Experience Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and Custom Security Tools development. Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes). Familiarity with secure software architecture and typical attack vectors. Demonstrated ability to do security testing engagements and report technical findings effectively. Experience building or integrating automated PT or fuzzing pipelines is a strong advantage. Knowledge and hands?on experience with SSDLC tools and CI/CD pipelines, #J-*****-Ljbffr ## Description We're running the software that runs the world - and we want you along for the ride.The company is a special place with a unique combination of brilliance, spirit, and great people.Here, if you're willing to do more, your career can take off.And since software plays a central role in everyone's lives, you'll be part of a critical mission.In this role, you will work with a team of researchers and ethical hackers focused on offensive security testing, automated exploit discovery, and advanced application security research.Your work will directly influence the security posture of the company's products and help scale secure?by?design principles.This is a hands?on technical role with a strong emphasis on offensive security, code exploitation, automation, and innovation.ResponsibilitiesHelp to reshape JFrog Product SecurityPlan and execute advanced penetration testing campaigns.Develop tools and frameworks for scalable security testing and fuzzing.Lead Security innovation by building and managing penetration testing tools \ AI AgentsAnalyze vulnerabilities, perform root cause analysis, and develop proofs of concept.Identify systemic product weaknesses and help define long?term mitigations.Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.Contribute to security research publications, CVE submissions, and industry knowledge sharing.Continuously evolve internal testing capabilities using modern tooling and AI?assisted approaches.Requirements4+ year experience in Research and penetration testing.Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies.AI and LLM Penetration testing knowldge and ExperienceExperience with penetration testing tools (Burp Suite, Metasploit, etc.) and Custom Security Tools development.Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes).Familiarity with secure software architecture and typical attack vectors.Demonstrated ability to do security testing engagements and report technical findings effectively.Experience building or integrating automated PT or fuzzing pipelines is a strong advantage.Knowledge and hands?on experience with SSDLC tools and CI/CD pipelines,#J-*****-Ljbffr ## Related Videos - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)