HQ - Senior Application Security Engineer
JobandtalentSpainPermanent1w ago
Job description
About the role
Jobandtalent is seeking a proactive and experienced Senior Application Security Engineer to join the team and help build secure products at scale. In this role you will serve as a trusted partner to Engineering and Product teams, embedding security by design throughout the entire Software Development Lifecycle. You will lead initiatives including threat modelling, secure code reviews, security automation, and developer enablement across all product squads and engineering groups. Your work will shape the Application Security strategy, helping the company build secure and resilient products while giving engineering teams the confidence to move quickly and deliver value without compromise.
Key facts
What you'll do
- Drive security by design principles across every phase of the Software Development Lifecycle and ensure consistent adoption by all engineering teams
- Lead threat modelling sessions with cross-functional teams to identify and address risks early in product designs before development begins
- Conduct thorough secure code reviews to catch vulnerabilities and misconfigurations before they ever reach production or staging environments
- Build and maintain security automation pipelines that scale reliably alongside growing engineering output and increasing deployment frequency across the organization
- Partner closely with Engineering and Product teams to embed security practices into daily development workflows and release cycles
- Enable developers with hands-on training, practical guidance, and tooling to write secure code independently and with confidence
- Shape the Application Security strategy in alignment with business objectives, product roadmaps, and engineering priorities across the organization
- Build secure and resilient products that protect user data, company assets, and customer trust at every layer
- Identify and prioritize application security improvements across the engineering organization based on risk assessment and business impact
- Champion a security-first culture by working closely with cross-functional teams to raise security awareness and accountability
Requirements
- Proven experience as an Application Security Engineer or equivalent security role in a product-driven technology organization
- Strong understanding of threat modelling methodologies and secure design principles applied to modern software systems
- Hands-on experience conducting secure code reviews across multiple technology stacks and diverse programming languages
- Knowledge of security automation tools and practices for integrating checks into CI/CD pipelines effectively
- Ability to partner effectively with Engineering and Product teams in a fast-paced and iterative development environment
- Experience enabling developers to adopt secure coding practices independently through coaching, documentation, and hands-on support
- Familiarity with building and executing an Application Security strategy that aligns with business goals and growth plans
- Deep understanding of application-level vulnerabilities including injection flaws, authentication weaknesses, and access control deficiencies
Nice to have
- Experience working in a scaled product environment with multiple engineering teams and high deployment velocity
- Background in developer education or security enablement programs that measurably improve team security maturity over time
- Familiarity with cloud-native application security and containerized workloads in production environments at significant scale
- Exposure to regulatory or compliance frameworks relevant to application security and data protection standards
- Prior experience collaborating with security operations or incident response teams to address and remediate vulnerabilities promptly
Skills & tools
- Proficiency in threat modelling frameworks such as STRIDE or PASTA for structured risk analysis and assessment
- Experience with static and dynamic application security testing tools for automated vulnerability detection and remediation
- Knowledge of secure coding practices across common programming languages, frameworks, and application architectures
- Familiarity with CI/CD pipeline security and automation tooling for continuous protection throughout the development cycle
- Understanding of cloud security fundamentals and infrastructure as code security best practices for modern deployments
- Strong communication skills for translating security concepts to both technical and non-technical audiences clearly
- Familiarity with identity and access management protocols and OAuth or SAML standards for secure authentication
Practical notes
- This role is based at the Madrid HQ with a permanent contract and a structured onboarding process
- The position offers a clear growth path within the security organization and regular mentorship opportunities
- You will work closely with cross-functional teams across Engineering and Product on a daily basis
- Scheduling flexibility is available within one hour of CET for collaboration with distributed colleagues
- The hiring process includes technical interviews focused on application security fundamentals, practical problem solving, and collaborative scenario exercises