
Web-App Security Engineer (d/m/w) - Remote
Haufe Group5 days ago
Freiburg im Breisgau, GermanySenior
Responsibilities
- Support feature teams with security questions during application conception, implementation, release, and operation.
- Develop and maintain cross-team security mechanisms for the application.
- Assess vulnerabilities in the application context and prepare actionable recommendations.
- Create threat models collaboratively and identify potential threats from an adversary’s perspective.
- Write Bash or Python scripts and other tools to automate suitable security tasks.
- Communicate vulnerabilities and security recommendations clearly and precisely to feature teams.
- Optionally contribute experience from incident response activities.
Requirements
- Good knowledge and extensive experience in web application security and cloud security, preferably with AWS.
- Knowledge of securely configuring, building, and releasing modern web applications, including IaC, CI/CD, and SDLC practices.
- Ability to assess application vulnerabilities and formulate recommendations for action.
- Knowledge of Java web applications and JavaScript/TypeScript web clients.
- Understanding of dependency management tools such as NPM and Gradle.
- Development experience and ability to automate tasks using Bash, Python, or other necessary tools.
- Familiarity with threat modeling and identifying threats from an adversary’s perspective.
- Very good German skills at least at C2 level and very good English skills.
- Incident response experience is advantageous.
Benefits
- Hybrid work combining office presence and home office according to team needs and agreement.
- Flexible working hours.
- Further training and professional development opportunities.
- Team-based recruiting process and a collaborative Security Enablement environment.
- Hacking Days and occasional after-work sessions.