
Application Security Engineer
Hover or tap a row for full statistics (EUR / month on this chart).
Salary analysis
Compared with the selected benchmark ("Company in Remote - Europe"), this listing's salary midpoint is about 89% lower. The offer sits below the benchmark range (€1,667–€6,000). The listed pay band (€319–€500) is tighter than the benchmark, which suggests lower salary variability. This benchmark is based on 6 comparable listings.
| Market | Lower bound (25th percentile) | Median | Upper bound (75th percentile) |
|---|---|---|---|
| All roles in Remote - Europe | €1,978/per month | €4,914/per month | €13,713/per month |
| Company in Remote - Europe | €1,667/per month | €2,056/per month | €6,000/per month |
| Pay in our data — not quoted in ad (Senior) | €319/per month | €410/per month | €500/per month |
The Role We are looking for an Senior/Staff Application Security Engineer who will ensure the security of our software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams. The ideal candidate will have a strong background in secure coding, threat modeling and building Secure SDLC. What you will do Build and maintain Application Security Posture Management (ASPM) at the Company scale. Automate and support SAST, SCA tools, etc as part of CI/CD pipelines. Improving SAST, secrets detection rules. Keeping false positive rate low. Identify, analyze, and remediate application security vulnerabilities. Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC). Develop and maintain secure coding guidelines for development teams. Conduct, run threat modeling and risk assessments for new and existing applications. Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc. Stay updated on the latest security threats, vulnerabilities, and mitigation techniques. Serve as an application security subject matter expert to other teams. What we look for 6+ years of experience in application security. Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them. Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript. Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary. Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.). Understanding of authentication protocols like SAML or OIDC. Experience in conducting threat-modeling sessions. Bonus points Confidence in presenting your ideas and opinions in a manner that can be challenged, while responding well to feedback. Experience in designing, building, and maintaining security automation. Experience in translating compliance and regulation requirements into technical specifications. Experience in exploiting vulnerabilities in web applications, Linux kernels, containers, and networks. Security certifications such as OSCP or OSWE. We conduct coding interviews as part of the process. #LI-CP1
Job Details
Responsibilities
- Build and maintain ASPM at scale
- Automate SAST and SCA in CI/CD
- Improve SAST and secrets detection rules
- Identify, analyze, and remediate vulnerabilities
- Integrate security into the SDLC
- Develop secure coding guidelines
- Conduct threat modeling and risk assessments
- Provide tools for security work
- Stay updated on threats
- Serve as security SME to other teams
Requirements
- 6+ years of experience in application security
- Strong knowledge of OWASP Top 10
- Experience with Python/Go/Java/JavaScript
- Proficiency in a common programming language (Go or Python)
- Hands-on experience with Burp Suite, ZAP, Semgrep
- Understanding of SAML or OIDC
- Experience in threat-modeling sessions
Skills & Technologies

Related Opportunities
Discover more opportunities that match your interests and skills