
Application Security Engineer (all genders)
About You SE & Co. KG2 days ago
Hamburg, Germany or Berlin, GermanyMid Level
Responsibilities
- Conduct regular penetration tests and manual secure code reviews.
- Perform threat modeling and implement security measures for applications, infrastructure, and data.
- Advise on the setup and maintenance of applications and infrastructure hosted in AWS or Kubernetes.
- Triage and respond to monitoring events and participate in SOC incident response activities, including occasional 24/7 on-call.
- Optimize and automate security auditing processes using Python and security tooling.
- Set up attack infrastructure and implement security scanning in GitLab CI.
- Coordinate technical security projects, dependencies, and deliverables across multifunctional engineering teams.
Requirements
- At least one year in a junior-level position and at least two years of overall application security experience.
- Strong background in threat modeling, penetration testing, and manual secure code reviews.
- Fluency in Python for security automation, tooling, and code assessment.
- Hands-on experience securing modern cloud environments such as AWS or GCP.
- Ability to manage complex technical security projects and coordinate dependencies across engineering teams.
- Preferred qualifications include OSCP or OSWP certifications, Laravel/PHP knowledge, ability to read JavaScript and Go, incident response experience, familiarity with web application firewalls and CDN providers such as Cloudflare or Akamai, and experience with GitLab CI/CD pipelines.
Benefits
- Inclusive workplace that values acceptance, inclusion, and diverse perspectives.
- Flat hierarchies, direct communication, pragmatic decision-making, ownership, and clear responsibility.
- Team lunches, afterwork drinks, company events, and informal coffee breaks.
- Role based in or associated with the Hamburg and Berlin offices.