
Application Security Engineer (m/w/d)
Bundesdruckerei GmbH17 days ago
Berlin, GermanySenior
Responsibilities
- Integrate security into the full software development lifecycle, from design and threat modeling through secure implementation, release, and operations.
- Build and operate SAST, DAST, SCA, and secret-scanning tools within development pipelines.
- Perform code reviews, vulnerability analyses, and threat modeling with development teams.
- Assess, prioritize, track, and support remediation of vulnerabilities through vulnerability management.
- Support and coach Security Champions under central technical guidance.
- Contribute to quality gates and define security-related acceptance criteria.
- Advise business units on secure architecture and implementation decisions.
- Help develop standards, policies, and activity-oriented requirements for code security.
Requirements
- Completed degree in computer science, information security, or IT security, or vocational training with several years of practical information and IT security experience.
- Several years of experience in application security or software development with a security focus.
- Strong understanding of common vulnerability classes such as OWASP Top 10, secure development practices, and secure software architectures.
- Experience with threat modeling and application security tooling, especially SAST, DAST, and SCA, including pipeline integration.
- Knowledge of at least one relevant programming language, such as Java, C#, Python, or JavaScript.
- Knowledge of BSI IT-Grundschutz, especially BSI 200-2 and 200-3, and standards such as ISO 27001 is desirable.
- OSCP, OSWE, or GWAPT certification is desirable.
- Strong analytical, prioritization, learning, moderation, consulting, teamwork, and communication skills, including the ability to communicate security requirements in German and English at C1 level.