> Markdown version of [/jobs/ext/3043801-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3043801-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Flywire Advantage - **Location:** Valencia, Spain - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Software System Penetration Testing, Application Testing, Cloud Computing, Cross-Site Request Forgery, Web Development, Information Systems Security Architecture Professional, Python (Programming Language), Node.Js, OAuth, Open Web Application Security, PCI Data Security Standards, Systems Development Life Cycle, Ruby on Rails, Security Assertion Markup Language (SAML), Information Technology Security Auditing, Security Support Provider Interface, Single Sign-On, Software Engineering, SQL Injection, Web Applications, Large Language Models, Software Security, Cross-Site Scripting (XSS), Containerization, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 24, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role + Experience: 4+ years in AppSec. Proven experience performing web application penetration tests and vulnerability research. Skills in source code auditing, product assessments, and development of security tools are essential. + Security Mindset: A "breaker" mentality, with the ability to think like an attacker to identify flaws, but effectively crafting the mitigating controls to fix them. + Technical Proficiencies: o Proficiency in Ruby on Rails, Java, and modern web dev (JavaScript, Python, Node.js, etc.). o Deep understanding of OWASP Top 10 (XSS, CSRF, SQLi, Cookie Manipulation, etc.). o Practical knowledge of the OWASP Top 10 for LLM Applications (Prompt Injection, Insecure Output Handling, etc.). o Working experience in authentication: OAuth, SAML, and SSO. o General knowledge of applied cryptography. o Familiarity with cloud technologies and containerization. o Experience with SAST/DAST/SCA tools and integrating them into DevSecOps pipelines. o Ability to implement security guardrails for AI-driven features and validate model integrity (nice to have). + Compliance & Audits: Knowledge of security audit certifications like PCI-DSS, SOC 1, and SOC 2. + Soft Skills: Ability to explain complex technical findings (from pentests or reviews) to both technical and non-technical audiences with empathy and clear communication. ## Description The Opportunity: We are looking to hire an eager and skilful Application Security Engineer. This individual will support our Security Team in providing security support for our development houses and ensure the privacy and security of confidential business and personal information., + Security Design & Architecture: Draft security requirements for systems, services, or integrations. Conduct secure design, threat modeling, and secure architecture initiatives. + Engineering Collaboration: Collaborate frequently with different engineering teams to identify and address security issues. Attend engineering syncs to ensure that product features have security "built-in." + Full-Stack Reviews: Perform technical tasks on change and integration reviews, including full security reviews from source code auditing to live application testing. + Automation & SDLC: Contribute to the automated security controls we are building and take an active part in every aspect of the secure software development lifecycle (S-SDLC). + Technical Guidance: Provide hands-on remediation guidance to development teams and perform technical lead tasks with other team members. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)