> Markdown version of [/jobs/ext/44767-application-security-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/44767-application-security-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security / Product Security Engineer - **Company:** Itransition - **Location:** La Unión, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** JIRA, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Github, Issue Tracking Systems, Open Source Technology, Systems Development Life Cycle, Secure Coding, Software Engineering, Software Vulnerability Management, Diagnostic Tools, Delivery Pipeline, Software Security, Kubernetes, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** May 15, 2026 - **Apply:** https://es.indeed.com/viewjob?jk=0118a1a1a49ce5e8 ## About the Role Do you have experience in Software development?, * 2-5 years of experience in Application Security, Product Security, DevSecOps, Security Operations, or related cybersecurity roles * General understanding of Secure SDLC and application security principles * Experience working with security tools or processes related to vulnerability management, CI/CD security, or dependency/security scanning * Familiarity with Jira or similar ticketing/tracking systems * Understanding of common application security risks and vulnerabilities * Ability to document processes and communicate effectively with technical teams * English skills sufficient for technical communication and participation in project discussions, * Hands-on experience with SCA tools such as FOSSA, Snyk, Mend, Black Duck, or similar * Familiarity with open-source license compliance processes * Experience with secret detection tools, pre-commit hooks, or CI/CD secret scanning * Experience integrating security controls into GitHub Actions or other CI/CD platforms * Familiarity with vulnerability remediation workflows and SLA tracking * Experience with asset inventory tools such as NetBox * Experience supporting audits or compliance initiatives (ISO 27001, SOC 2, etc.) * Familiarity with SAST, DAST, container scanning, or cloud security tooling * Experience working in cloud-native or Kubernetes environments ## Description We are looking for an Application Security / Product Security Engineer to support and improve security processes across the software development lifecycle (SDLC) and CI/CD environments for our client. In this role, you will work closely with engineering teams to help implement and maintain security controls, improve vulnerability management processes, support compliance initiatives, and strengthen secure development practices across modern software delivery pipelines. office remoteEuropean UnionUkraine, * Support Software Composition Analysis (SCA) processes and open-source license compliance activities * Help implement and maintain secret detection practices, including pre-commit hooks and CI/CD secret scanning * Participate in vulnerability management activities: vulnerability scanning, triage and prioritization, Jira ticket tracking, remediation follow-up and SLA monitoring * Collaborate with engineering teams to improve Secure SDLC and CI/CD security practices * Support security tooling integrations within CI/CD pipelines (e.g., GitHub Actions) * Maintain security-related documentation and assist with audit/compliance activities * Contribute to asset inventory and security governance processes * Work with development and infrastructure teams to improve overall security posture ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)