Application Security Engineer
Job description
About the role
Egym is seeking an Application Security Engineer to help build secure, cloud-native products. You will work directly with our engineering teams to embed security into the development lifecycle and ensure our platform remains protected as we scale. In this capacity, you will serve as a bridge between security requirements and engineering execution, translating complex threats into actionable guidance for developers. You will own the security posture of application layers while fostering a culture of shared responsibility across the product teams. The role requires a proactive mindset that anticipates risks before they materialize in production environments. You will influence best practices and standards that shape how new applications are designed and built. This position demands strong communication skills to align technical controls with business objectives and delivery timelines. Your work will have a direct impact on the trust and reliability of the platform used by fitness providers and their members.
Key facts
What you'll do
- Integrate security practices into design, development, and deployment workflows for new applications and services.
- Conduct security assessments for new features, APIs, and critical services before they reach production.
- Implement and manage security tooling such as SAST and DAST within CI/CD pipelines to automate quality gates.
- Track and prioritize vulnerabilities, providing actionable remediation steps to developers with clear severity context.
- Partner with SRE and DevOps teams to secure containerized and cloud-native environments running on Kubernetes.
- Manage technical evidence and documentation required for certifications such as SOC 2 and ISO 27001.
- Support the sales process by acting as the technical lead for security questionnaires and compliance artifacts.
- Mentor engineering teams to increase overall security awareness through documentation and hands-on guidance during code reviews.
- Collaborate with product managers to define security acceptance criteria for upcoming milestones and releases.
- Analyze attack patterns and threat landscapes to adjust security controls and testing focus accordingly.
- Establish secure coding standards and guidelines tailored to the technologies used across the platform.
- Perform code reviews with a security lens, identifying weak points in authentication, authorization, and data handling.
- Coordinate with external auditors and security assessors to ensure alignment with industry frameworks and regulatory expectations.
- Drive continuous improvement of the security posture by measuring key indicators and refining processes over time.
Requirements
- Several years of professional experience in Application Security or Software Security Engineering within technology environments.
- Deep understanding of the OWASP Top 10, threat modeling methodologies, and secure coding standards applied to modern applications.
- Ability to read or write code in languages such as Go, Java, or Python to effectively conduct tooling and security reviews.
- Familiarity with cloud-native architectures, containerization technologies, and automated deployment pipelines is essential.
- Professional proficiency in English to communicate clearly with cross-functional teams and stakeholders.
- Collaborative approach to working with developers, focusing on enabling secure delivery rather than acting as a rigid gatekeeper.
- Strong analytical skills to assess complex systems, identify weaknesses, and recommend appropriate mitigations.
- Commitment to maintaining up-to-date knowledge of security trends, tools, and techniques relevant to cloud software.
Nice to have
- Experience with SAST and DAST tools integrated into CI/CD workflows in a cloud-native environment.
- Hands-on work with Kubernetes, Docker, and container orchestration in production scenarios.
- Practical exposure to major cloud platforms such as GCP and AWS, especially around identity and network security.
- Understanding of API security standards, protocols, and implementation best practices.
- Familiarity with threat modeling frameworks and their application in agile delivery contexts.
- Experience supporting compliance efforts for SOC 2, ISO 27001, or similar management systems.
Practical notes
- The position is based in Germany, with a primary work location in Munich as specified in the key facts.
- Benefits include 30 days of vacation, flexible hours, and home office options to support work-life balance.
- Employees receive 10 percent of their time dedicated to professional development and continuous learning activities.
- Perks include Egym Wellpass access, an in-house gym, a 60 Euro monthly flex budget for transit or meals, bike leasing, and employee discounts.
- To apply, submit your CV, salary expectations, and start date via the career portal, ensuring you reference job ID #1860 for proper routing.
- The designated contact person for this role is Sven Bunkus, who can assist with questions regarding the application process.
- Applications will be reviewed on a rolling basis, and candidates are encouraged to submit materials as early as possible to secure consideration.
- This role requires availability for full-time engagement, with standard working hours aligned with company policies and team collaboration needs.
- Successful candidates must be legally authorized to work in Germany and comply with local employment regulations.