> Markdown version of [/jobs/ext/3411224-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3411224-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** TripleTen - **Location:** Spain (Remote available) - **Salary:** €48,000.0 - €72,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, User Authentication, Cloud Computing, Encodings, Continuous Integration, Information Leak Prevention, Identity and Access Management, Python (Programming Language), Key Management, OAuth, OpenID, Open Web Application Security, Role-Based Access Control, Security Assertion Markup Language (SAML), Secure Coding, Web Application Security, Session Management, Software Engineering, Software Vulnerability Management, Large Language Models, Software Security, Production Code, Devsecops, Static Application Security Testing - **Published:** September 28, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5a851c2d166c2bde ## About the Role * 5+ years of engineering experience, including at least 2 years focused on Application Security or Product Security. * Strong software engineering background with the ability to read, review, and write production code; Python experience is highly preferred. * Deep practical knowledge of web application security, including OWASP Top 10, ASVS, authentication and session management, OAuth2 / OIDC / SAML, and authorization issues such as IDOR and broken access control. * Experience securing multitenant or B2B SaaS products, including tenant isolation, RBAC / ABAC, and access control models. * Hands-on experience embedding security into CI/CD, including SAST, SCA, secrets scanning, container scanning, and IaC scanning. * Strong experience with threat modelling, secure design reviews, and secure code reviews in collaboration with product and engineering teams. * Experience managing vulnerabilities based on risk, criticality, and exploitability, including remediation prioritisation and escalation when needed. * Working knowledge of AWS and Kubernetes security, including IAM, secrets management, network boundaries, and workload hardening. * Strong communication skills and the ability to explain security risks clearly to engineers, product managers, and auditors. * Fluent Russian and English at B2 level or above. Nice to have: * Experience building a DevSecOps practice from scratch. * Experience running or participating in a Security Champions programme. * Hands-on penetration testing experience. * Experience securing LLM-powered or AI products. * Experience with SOC 2 or ISO 27001 from an engineering perspective. * Knowledge of software supply chain security, including SBOMs, SLSA, image signing, or similar practices. ## Description You will work closely with product and platform teams to make security part of the engineering process, building secure defaults and helping prevent vulnerabilities from reaching production without slowing development down., * Own application and product security end to end, from design reviews and threat modelling to vulnerability remediation and follow-up. * Partner with product and platform teams to embed security into the development lifecycle rather than treat it as a final review step. * Build and improve security controls in CI/CD, including SAST, dependency, secrets, container, and IaC scanning. * Review application designs and code where security risk is meaningful, and turn recurring findings into secure defaults, shared libraries, lint rules, and CI gates. * Drive vulnerability management across application code and cloud posture, including triage, risk-based prioritisation, remediation timelines, and external pentest findings. * Strengthen security in multitenant B2B systems, including tenant isolation, authentication, authorization, RBAC / ABAC, and access controls. * Work on cloud and Kubernetes security across AWS environments, including IAM, secrets management, network boundaries, and workload hardening. * Help translate GDPR, SOC 2, and ISO 27001 requirements into practical engineering controls and system properties. * Develop and support a security champions programme to help engineering teams adopt secure practices in their day-to-day work. * Address security risks specific to AI and LLM-powered features, including prompt injection, data leakage, and untrusted model output. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)