
Posted Today
Application Security Engineer
AI Summary
An Application Security Engineer who drives product security across the SDLC, performs threat modeling and architecture reviews, and integrates security tooling into CI/CD pipelines.
About this role
Your mission
As our Application Security Engineer, you will play a key role in shaping and strengthening the security of our products and platforms. Working closely with highly skilled engineering, platform, and security teams, you will help build secure, resilient, and trusted software while driving a security-first culture across the organization. This is an opportunity to make a measurable impact on modern products, influence security strategy, and continuously develop your expertise in a collaborative and innovative environment.
- Drive product security across the entire software development lifecycle (SDLC).
- Perform threat modeling, architecture reviews, and security assessments for applications, APIs, and distributed systems.
- Identify, assess, prioritize, and support the remediation of security vulnerabilities.
- Integrate, operate, and continuously improve security tooling within CI/CD pipelines, including SAST, DAST, SCA, dependency scanning, and secrets-scanning solutions.
- Define, promote, and support secure coding standards and security best practices across engineering teams.
- Review and advise on authentication, authorization, identity management, secrets management, and service-to-service communication designs.
- Support penetration testing activities, conduct targeted security testing, and drive remediation efforts.
- Contribute to security policies, standards, and security awareness initiatives.
- Partner closely with software engineers, architects, and platform teams to embed security into development processes and strengthen our DevSecOps culture.
Your profile
- 5+ years of experience in Product Security, Application Security, Software Security, Secure Software Development, or a related field.
- Strong understanding of secure software development practices and common application security vulnerabilities.
- Proven experience performing threat modeling, architecture reviews, code reviews, and application security assessments.
- Hands-on experience with SAST, DAST, SCA, dependency-scanning, and secrets-scanning tools.
- Strong knowledge of application security, API security, and distributed-system security.
- Experience securing authentication, authorization, and identity-related workflows.
- Solid understanding of OWASP, CWE, security testing methodologies, and modern security engineering practices.
- Experience working with CI/CD pipelines and applying DevSecOps principles.
- Ability to collaborate effectively with software engineering, platform, and DevOps teams.
- Fluent English skills are required; German language skills are a plus.
- Development experience in C#, .NET, JavaScript/TypeScript, Python, or similar programming languages.
- Experience securing cloud-native applications and services in Azure and/or AWS environments.
- Relevant security certifications such as OSCP, CSSLP, OSWE, or GIAC Secure Development certifications.
- Experience working in agile software development environments.
Why us?
Modernes, zentral gelegenes Büro: Nur 5 Gehminuten von der Haltestelle Bahrenfeld entfernt - bequeme Anreise garantiert!
Offene Unternehmenskultur: Tauche ein in ein internationales Arbeitsumfeld, in dem Ideen und Vielfalt gefördert werden.
Kollegiale Arbeitsatmosphäre: Genieße eine Arbeitsatmosphäre, die von Zusammenarbeit und Hands-on-Mentalität geprägt ist.
Hybrides Arbeitsmodell: Flexibilität - Kombiniere Arbeit vor Ort und im Home Office.
30 Tage Urlaub: Mehr Zeit für Erholung und Freizeit. Zusätzliche freie Tage am 24.12., 31.12. sowie einen halben Tag an deinem Geburtstag.
Attraktives Vergütungspaket: Wir honorieren deine Leistung angemessen.
Betriebliche Altersvorsorge: Mit großzügigem 25% Arbeitgeber-Zuschuss bis zu 75 €.
Pluxee-Gutscheine: Für unbeschwerte Verpflegung während der Arbeit.
HVV-Abo- oder Tiefgaragenstellplatz-Zuschuss: Unterstützung für Deine bequeme
JobRad: Nutze die Möglichkeit, nach der Probezeit ein JobRad zu leasen.
EGYM Wellpass: Nutze die Möglichkeit, nach der Probezeit dich körperlich und mental fit zu halten.
Skills
Explore related jobs
More jobs at Jobs at Telio Group
Similar API Security jobs
Jobs in Hamburg
Event Manager (m/w/d)Jobs bei Nord Event GmbH · Hamburg Kaufmännisch
Werkstudent - Archiv (m/w/d)Jobs bei HafenCity Hamburg GmbH · Hamburg
(Mini-/Studentenjob) in der Logistik: Event-, Veranstaltungs-, und MesselogistikYoung Talents GmbH · Hamburg, Hamburg- Senior Java Fullstack Developer (m/w/d)virtual7 GmbH · Hamburg, Hamburg
- Trainee: Creator Management in Vollzeit (m/w/d)Freiheit Media GmbH · Hamburg, Hamburg
- Werkstudent Content Creation & Social Media (m/w/d)Freiheit Media GmbH · Hamburg, Hamburg
Browse these categories
Market data for security engineer roles
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.