ABOUT YOU SE & Co. KG

Application Security Engineer (all genders)

ABOUT YOU SE & Co. KG · Hamburg, Germany · €62K–€75K/yr

Internet Marketplace Platforms · 1,001-5,000 employees

2 d ago
Mid (2-5 yrs) Full-time Germany
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Application Security Engineer will conduct penetration tests, perform code reviews, and implement security measures to protect infrastructure and applications. They will also automate security auditing processes and participate in incident response activities within the SOC.

What they look for

Application security Security engineering Penetration testing Secure code review AWS Python Kubernetes Gitlab CI/CD Threat modeling Incident response Web application firewalls CDN PHP JavaScript Go Red teaming

Requirements

Candidates must have experience in application security, cloud environments like AWS, and proficiency in Python programming. Additional requirements include knowledge of threat modeling, secure code review, and familiarity with CI/CD pipelines.

Full description

Company Description

 

Job Description

We are looking for an Application Security Engineer (all genders) to join the Application Security circle of our IT-Security unit, dedicated to protecting our online shop, our corporate systems and our customers. 

In this role, you will hack internal systems, design and implement security measures to safeguard our infrastructure, applications, and data. You will work closely with other security engineers, developers and IT teams to ensure security best practices, automate security processes, and respond to emerging threats.

  • Conduct regular penetration tests and code reviews
  • Advise in the setup and maintenance of applications and infrastructure (usually hosted in AWS/Kubernetes)
  • Triage and respond to monitoring events
  • Optimization and automation of security auditing processes. This could also include setting up attack infrastructure, writing scripts in Python and implementing security scanning in Gitlab CI
  • Take part in some incident response activities within the SOC, which include occasional 24/7 on-call

Qualifications

  • Application security
  • Security engineering
  • Technical Project Management skills
  • Threat modeling
  • Penetration testing
  • Secure code review
  • Cloud experience: AWS, Bonus: GCP, Azure
  • Programming experience: Python required, Bonus: PHP, JavaScript, Go
  • Red teaming is a plus

 

Nice to have

  • Certificates:
  • Offensive Security certificates; e.g. OSCP, OSWP, etc.
  • Knowledge of Laravel / PHP.
  • Ability to read and understand JavaScript
  • Ability to read and understand Go
  • Experience with incident response activities
  • Experience with web application firewalls, CDN providers, e.g. Cloudflare, Akamai
  • Experience with Gitlab CI/CD Pipelines

Additional Information

Your perks at a glance: Visit our benefits page.

Simply apply online via our career page - we will get back to you as soon as possible!

A Place Where You Can Be You

We take it as our responsibility to create an environment where everyone feels welcome, exactly as they are.

Different backgrounds and perspectives make us stronger and shape our culture in ways that matter.

What we stand for internally, we stand for as a brand: acceptance, inclusion, and a fairer approach to fashion.

  • Compensation: EUR 65000 - EUR 75000 - yearly