> Markdown version of [/jobs/ext/3048054-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3048054-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Prima - **Location:** Madrid, Spain - **Salary:** €55,000.0 - €70,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Software System Penetration Testing, Burp Suite, Distributed Systems, Python (Programming Language), OAuth, OpenID, Open Web Application Security, Systems Development Life Cycle, Security Assertion Markup Language (SAML), Secure Coding, Software Engineering, AI Infrastructure, Cloud Platform System, Software Security, Security Orchestration, Automation & Response, Golang - **Published:** September 24, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role Minimum of 4 years of experience in application security, secure software development, or related cybersecurity engineering roles. Strong understanding of application security risks, including OWASP Top 10 and common web and system vulnerabilities. Hands-on experience with secure coding practices in languages such as Python, Go, Java, or JavaScript. Proficiency in at least one programming language (e.g., Go or Python) with willingness to learn additional technologies. Practical experience with security testing tools such as Burp Suite, OWASP ZAP, Semgrep, or equivalent solutions. Experience conducting threat modeling exercises and security risk assessments. Solid understanding of authentication and authorization protocols such as SAML, OAuth, or OIDC. Strong analytical thinking and problem-solving skills with attention to detail in complex systems. Excellent communication skills in English, with the ability to explain technical security concepts to engineering teams. Ability to work independently while collaborating effectively in distributed and fast-paced environments. A proactive mindset and willingness to continuously learn and adapt to new security challenges. Security certifications such as OSCP or OSWE are considered a strong advantage. Experience with security automation, compliance translation, or exploitation of complex systems is a plus. ## Description Join a high-impact security engineering environment where you will play a key role in protecting and strengthening large-scale cloud-native applications that power next-generation AI infrastructure. In this role, you will work at the intersection of software engineering and cybersecurity, ensuring that applications are designed, built, and maintained with security at their core. You will collaborate closely with development teams to integrate security practices throughout the software development lifecycle, identify and remediate vulnerabilities, and improve the overall security posture of complex distributed systems. This position offers the opportunity to work with modern technologies, advanced cloud environments, and cutting-edge AI platforms while influencing how security is embedded into engineering practices at scale. It is ideal for a hands-on security professional who enjoys deep technical work, proactive risk identification, and cross-functional collaboration in a fast-paced engineering culture. Accountabilities Identify, analyze, and remediate application security vulnerabilities using modern application security posture management (ASPM) tools and related security technologies. Build, maintain, and enhance ASPM tools, rules, and automation to strengthen application security across engineering teams. Integrate security best practices into the software development lifecycle (SDLC) in close collaboration with development and platform engineering teams. Conduct manual and automated penetration testing to identify weaknesses in applications and supporting infrastructure. Lead threat modeling sessions and risk assessments for both new and existing applications to proactively address security risks. Develop, maintain, and promote secure coding standards and guidelines for engineering teams. Serve as a subject matter expert in application security, providing guidance and support to internal teams across the organization. Stay up to date with emerging security threats, vulnerabilities, attack techniques, and mitigation strategies. Contribute to the continuous improvement of security engineering processes, automation, and tooling. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)