Job&Talent

HQ - Senior Application Security Engineer (Remote)

Job&Talent · Madrid, Community of Madrid, Spain

Software Development · 1,001-5,000 employees

20 h ago
Remote Mid (2-5 yrs) Full-time Spain
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will act as the Application Security Subject Matter Expert, partnering with engineering teams to embed security throughout the software development lifecycle. Responsibilities include leading security reviews, threat modelling, and automating security controls within CI/CD pipelines.

What they look for

Application Security Threat Modelling Secure Code Reviews SAST SCA CI/CD Pipelines OWASP Top 10 API Security WAF Kubernetes Security Python Penetration Testing Burp Suite Cloud-native Applications Networking Fundamentals SDLC

Requirements

The ideal candidate has 3-4 years of experience in Information Security with a strong focus on application security and secure coding practices. You must possess hands-on experience with SAST, SCA, WAF solutions, and Kubernetes security, alongside excellent communication skills.

Benefits

Competitive pay Meaningful benefits

Full description

We are looking for a proactive and experienced Senior Application Security Engineer to help build secure products at scale. As a trusted partner to Engineering and Product teams, you will drive security by design across the Software Development Lifecycle (SDLC), leading initiatives such as threat modelling, secure code reviews, security automation, and developer enablement.

You will play a key role in shaping our Application Security strategy, helping us build secure, resilient products while enabling engineering teams to move fast with confidence.

This is a fully remote position with flexibility within ±1 hour of CET.

\n

Responsibilities

• Act as the Application Security Subject Matter Expert (SME), partnering with Engineering and Product teams to embed security throughout the SDLC.

• Lead application security reviews, threat modelling, code reviews and penetration testing to identify and mitigate security risks.

• Design, implement and automate security controls across CI/CD pipelines, including SAST, SCA and other AppSec tooling.

• Drive the technical roadmap of the Application Security program, improving secure development practices and scaling security initiatives across the organisation.

• Improve and manage application security controls, including WAF, Kubernetes security and vulnerability management.

• Mentor Security Champions and junior engineers, promoting a strong security culture across development teams.

• Define and communicate meaningful Application Security metrics to measure risk reduction and program effectiveness.

A successful candidate will have

• 3-4 years of experience in Information Security, including at least 2 years in Application Security.

• Strong experience with Secure SDLC, threat modelling, application security reviews and secure code reviews.

• Hands-on experience with SAST, SCA and automated security testing integrated into CI/CD pipelines.

• Strong knowledge of OWASP Top 10, OWASP ASVS, API Security and secure coding best practices.

• Experience implementing and managing WAF solutions, as well as conducting internal penetration testing (including APIs using Burp Suite).

• Solid understanding of Kubernetes security, cloud-native applications and networking fundamentals (HTTP, HTTPS, TCP/IP).

• Basic scripting or development experience, preferably in Python.

• Excellent communication skills, with the ability to influence engineering teams and explain complex security concepts to technical and non-technical stakeholders.

\n

About us

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. We help companies boost productivity and efficiency at scale, while giving workers the tools they need to thrive. Our mission is simple: to empower the people who make the world go round.

Built on deep industry expertise, cutting-edge technology, and smart AI agents, our end-to-end platform covers the entire workforce lifecycle — from recruitment and planning to time and attendance, performance, cost management, and communication.

It delivers measurable improvements in the areas that matter most: fulfilment, attendance, retention, and workforce quality. Our platform strength is rooted in unique experience: placing millions of workers over the years and serving thousands of blue-chip clients across delivery, logistics, manufacturing, e-commerce, retail, and hospitality.

Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America and is backed by leading investors including Atomico, Goldman Sachs, Kinnevik, BlackRock, and SoftBank.

Join our community and make an impact

Innovation, high standards, and analytical thinking are in our DNA. Everyone has a voice here, and that voice matters. It’s how we stay sharp, move fast, and make decisions that keep us ahead of the curve.

You’ll take full ownership of your work, collaborate across borders, and grow by doing. Around here, you’ll hear a lot about 10x experiences, human-centered design, and the power of AI. But what truly sets us apart is our people: Our diverse team brings unique perspectives, deep commitment and real-world experience to the table.

We champion empathy, honesty, and inclusion. Because when people can be their authentic selves, incredible things happen—for our workers, our clients, and for each other.

And we reward that impact—with competitive pay, meaningful benefits, and the opportunity to shape what work looks like for millions around the globe.

If you're ready to make a real impact at scale, you're in the right place.

Proud to champion equality

At Job&Talent we value diversity and we're an Equal Opportunity Employer. We welcome applications from all suitably qualified people regardless of national origin, race, disability, religious beliefs or sexual orientation. Come join us. We look forward to your application.

#LI-ML2