Application Security / Product Security Engineer

Itransition
La Unión, Spain
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
2 years minimum
Working hours
Regular working hours
Languages
English
Job source

Tech stack

JIRA Cloud Computing Security Cloud Engineering Cyber Security Continuous Integration Github Issue Tracking Systems Open Source Technology Systems Development Life Cycle Secure Coding Software Engineering Software Vulnerability Management
+8 more
Diagnostic Tools Delivery Pipeline Software Security Kubernetes Devsecops Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

We are looking for an Application Security / Product Security Engineer to support and improve security processes across the software development lifecycle (SDLC) and CI/CD environments for our client. In this role, you will work closely with engineering teams to help implement and maintain security controls, improve vulnerability management processes, support compliance initiatives, and strengthen secure development practices across modern software delivery pipelines. office remoteEuropean UnionUkraine, * Support Software Composition Analysis (SCA) processes and open-source license compliance activities

  • Help implement and maintain secret detection practices, including pre-commit hooks and CI/CD secret scanning
  • Participate in vulnerability management activities: vulnerability scanning, triage and prioritization, Jira ticket tracking, remediation follow-up and SLA monitoring
  • Collaborate with engineering teams to improve Secure SDLC and CI/CD security practices
  • Support security tooling integrations within CI/CD pipelines (e.g., GitHub Actions)
  • Maintain security-related documentation and assist with audit/compliance activities
  • Contribute to asset inventory and security governance processes
  • Work with development and infrastructure teams to improve overall security posture

Requirements

Do you have experience in Software development?, * 2-5 years of experience in Application Security, Product Security, DevSecOps, Security Operations, or related cybersecurity roles

  • General understanding of Secure SDLC and application security principles
  • Experience working with security tools or processes related to vulnerability management, CI/CD security, or dependency/security scanning
  • Familiarity with Jira or similar ticketing/tracking systems
  • Understanding of common application security risks and vulnerabilities
  • Ability to document processes and communicate effectively with technical teams
  • English skills sufficient for technical communication and participation in project discussions, * Hands-on experience with SCA tools such as FOSSA, Snyk, Mend, Black Duck, or similar
  • Familiarity with open-source license compliance processes
  • Experience with secret detection tools, pre-commit hooks, or CI/CD secret scanning
  • Experience integrating security controls into GitHub Actions or other CI/CD platforms
  • Familiarity with vulnerability remediation workflows and SLA tracking
  • Experience with asset inventory tools such as NetBox
  • Experience supporting audits or compliance initiatives (ISO 27001, SOC 2, etc.)
  • Familiarity with SAST, DAST, container scanning, or cloud security tooling
  • Experience working in cloud-native or Kubernetes environments

Benefits & conditions

  • Projects for such clients as PayPal, Wargaming, Xerox, Philips, Adidas and Toyota;
  • Competitive compensation that depends on your qualification and skills
  • Career development system with clear skill qualifications
  • Flexible working hours aligned to your schedule
  • Options to work remotely
  • Corporate medical insurance covering services of private and public medical centers
  • English courses online
  • Corporate parties and events for employees and their children
  • Internal conferences, workshops and meetups for learning and experience sharing
  • Gym membership compensation
  • 5 days of paid sick leave per year with no obligation to submit a sick-leave certificate

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all