Application Security Engineer
Indexed description
- Drive product security across the entire software development lifecycle (SDLC).
- Perform threat modeling, architecture reviews, and security assessments for applications, APIs, and distributed systems.
- Identify, assess, prioritize, and support the remediation of security vulnerabilities.
- Integrate, operate, and continuously improve security tooling within CI/CD pipelines, including SAST, DAST, SCA, dependency scanning, and secrets-scanning solutions.
- Define, promote, and support secure coding standards and security best practices across engineering teams.
- Review and advise on authentication, authorization, identity management, secrets management, and service-to-service communication designs.
- Support penetration testing activities, conduct targeted security testing, and drive remediation efforts.
- Contribute to security policies, standards, and security awareness initiatives.
- Partner closely with software engineers, architects, and platform teams to embed security into development processes and strengthen our DevSecOps culture.
- 5+ years of experience in Product Security, Application Security, Software Security, Secure Software Development, or a related field.
- Strong understanding of secure software development practices and common application security vulnerabilities.
- Proven experience performing threat modeling, architecture reviews, code reviews, and application security assessments.
- Hands-on experience with SAST, DAST, SCA, dependency-scanning, and secrets-scanning tools.
- Strong knowledge of application security, API security, and distributed-system security.
- Experience securing authentication, authorization, and identity-related workflows.
- Solid understanding of OWASP, CWE, security testing methodologies, and modern security engineering practices.
- Experience working with CI/CD pipelines and applying DevSecOps principles.
- Ability to collaborate effectively with software engineering, platform, and DevOps teams.
- Fluent English skills are required; German language skills are a plus.
- Development experience in C#, .NET, JavaScript/TypeScript, Python, or similar programming languages.
- Experience securing cloud-native applications and services in Azure and/or AWS environments.
- Relevant security certifications such as OSCP, CSSLP, OSWE, or GIAC Secure Development certifications.
- Experience working in agile software development environments.
Offene Unternehmenskultur: Tauche ein in ein internationales Arbeitsumfeld, in dem Ideen und Vielfalt gefördert werden.
Kollegiale Arbeitsatmosphäre: Genieße eine Arbeitsatmosphäre, die von Zusammenarbeit und Hands-on-Mentalität geprägt ist.
Hybrides Arbeitsmodell: Flexibilität - Kombiniere Arbeit vor Ort und im Home Office.
30 Tage Urlaub: Mehr Zeit für Erholung und Freizeit. Zusätzliche freie Tage am 24.12., 31.12. sowie einen halben Tag an deinem Geburtstag.
Attraktives Vergütungspaket: Wir honorieren deine Leistung angemessen.
Betriebliche Altersvorsorge: Mit großzügigem 25% Arbeitgeber-Zuschuss bis zu 75 €.
Pluxee-Gutscheine: Für unbeschwerte Verpflegung während der Arbeit.
HVV-Abo- oder Tiefgaragenstellplatz-Zuschuss: Unterstützung für Deine bequeme
JobRad: Nutze die Möglichkeit, nach der Probezeit ein JobRad zu leasen.
EGYM Wellpass: Nutze die Möglichkeit, nach der Probezeit dich körperlich und mental fit zu halten.
About Us
Telio is a medium-sized, internationally active, rapidly growing company in the field of telecommunications and IT services in the prison sector. As the European market leader, we have been providing communications solutions for prisons and their inmates worldwide for over 25 years. With more than 300 employees, we are active in 23 countries and develop, install and operate communication and media systems that make an important contribution to resocialization in prisons as well as in correctional facilities.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search