> Markdown version of [/jobs/ext/3375613-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3375613-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Telio Management GmbH - **Location:** Hamburg, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Agile Methodology, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, C Sharp (Programming Language), Code Review, DevOps, Distributed Systems, Identity and Access Management, Python (Programming Language), Key Management, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, TypeScript, Spring Cloud, Software Security, Tenable Nessus, Devsecops, Static Application Security Testing, Programming Languages, Dynamic Application Security Testing - **Published:** September 24, 2026 - **Apply:** https://www.adzuna.de/details/5897676201 ## About the Role * 5+ years of experience in Product Security, Application Security, Software Security, Secure Software Development, or a related field. * Strong understanding of secure software development practices and common application security vulnerabilities. * Proven experience performing threat modeling, architecture reviews, code reviews, and application security assessments. * Hands-on experience with SAST, DAST, SCA, dependency-scanning, and secrets-scanning tools. * Strong knowledge of application security, API security, and distributed-system security. * Experience securing authentication, authorization, and identity-related workflows. * Solid understanding of OWASP, CWE, security testing methodologies, and modern security engineering practices. * Experience working with CI/CD pipelines and applying DevSecOps principles. * Ability to collaborate effectively with software engineering, platform, and DevOps teams. * Fluent English skills are required; German language skills are a plus. Nice to have * Development experience in C#, .NET, JavaScript/TypeScript, Python, or similar programming languages. * Experience securing cloud-native applications and services in Azure and/or AWS environments. * Relevant security certifications such as OSCP, CSSLP, OSWE, or GIAC Secure Development certifications. * Experience working in agile software development environments. ## Description As our Application Security Engineer, you will play a key role in shaping and strengthening the security of our products and platforms. Working closely with highly skilled engineering, platform, and security teams, you will help build secure, resilient, and trusted software while driving a security-first culture across the organization. This is an opportunity to make a measurable impact on modern products, influence security strategy, and continuously develop your expertise in a collaborative and innovative environment. * Drive product security across the entire software development lifecycle (SDLC). * Perform threat modeling, architecture reviews, and security assessments for applications, APIs, and distributed systems. * Identify, assess, prioritize, and support the remediation of security vulnerabilities. * Integrate, operate, and continuously improve security tooling within CI/CD pipelines, including SAST, DAST, SCA, dependency scanning, and secrets-scanning solutions. * Define, promote, and support secure coding standards and security best practices across engineering teams. * Review and advise on authentication, authorization, identity management, secrets management, and service-to-service communication designs. * Support penetration testing activities, conduct targeted security testing, and drive remediation efforts. * Contribute to security policies, standards, and security awareness initiatives. * Partner closely with software engineers, architects, and platform teams to embed security into development processes and strengthen our DevSecOps culture. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Shifting Stress to Progress— Understanding DevOps to do DevOps Better](https://www.wearedevelopers.com/videos/268-shifting-stress-to-progress-understanding-devops-to-do-devops-better) - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)