Senior Security Engineer - AppSec (d/f/m)
This isn't just a maintenance role - it is a blank canvas to build, scale, and architect a state-of-the-art AppSec program from the ground up. We are currently operating at a fraction of our ultimate potential, which means you have an immense, blank-canvas opportunity to fundamentally shape our security culture, processes, and tooling across the entire global engineering organization.
You will drive the entire AppSec lifecycle: from offensive red teaming and threat modeling to risk-based vulnerability management and pioneering a true shift-left culture.
What Makes This Role Challenging and Engaging:
High-Impact Technical Environment: You won't just follow blueprints; you will holistically influence a shift-left architecture across both application and platform layers.
Modern Technology Stack: Dive into securing a massive TypeScript monolith alongside Go supporting services, giving you hands-on experience in modern language security and advanced GitHub CI/CD pipeline hardening.
Web and API: secure the application of the vivenu platform which provides customers with an out-of-the-box ticketing software as well as the underlying API structure
Complex Multi-Cloud Architecture: Challenge your skills against a sophisticated multi-tenant, multi-region environment spanning k8s, GCP (our primary compute) and and separate database services
Cutting-Edge Deployment: Secure a next-gen Kubernetes "satellite architecture" utilizing hardened private compute nodes, VPC peering, and Argo CD for GitOps-a true, modern cloud-native security mandate.
As a Senior Security Engineer - AppSec (d/f/m) your responsibilities will include:
- Be a Trusted Advisor: Partner closely with engineering teams to champion security-by-design and elevate our overall security posture.
- Offensive & Defensive Testing: Coordinate and execute threat modeling and advanced security tests across our product and underlying infrastructure.
- Lead Next-Gen Vulnerability Management: Drive triage and remediation using modern, risk-based principles like EPSS, while leveraging AI technologies to accelerate security testing at scale.
- Pioneer Security-as-Code: Design, implement, and automate security checks and guardrails (SAST, DAST, and secret scanning) directly into CI/CD pipelines.
- Review & Refine: Perform deep-dive code and configuration reviews, advocating for secure coding practices that support a proactive shift-left strategy.
What you will need to succeed in this role:
- Experience: 5+ years of dedicated Security Engineering experience, ideally within a high-growth SaaS, E-commerce, or Fintech environment.
- SaaS Deep-Dive: The ability to dive deep into the business logic of a complex SaaS application to uncover and verify elusive attack vectors.
- Web and API Security Mastery: a deep understanding of web/API attack vectors and scalable best practices and how to run workloads securely in a cloud environment (k8s, AWS/GCP/Azure)
- Ownership: A proven track record of autonomously driving security initiatives from conception to completion.
- Automation Mindset: Proficiency in at least one programming language for scripting and security tool development (bonus points for automating GRC evidence collection).
-
Education: A Bachelor's or Master's degree in Computer Science, Cybersecurity, IT, or a related technical field (or equivalent practical experience).
Preferred:
- Experience navigating PCI DSS script security.
- A background in Red/Purple Team operations and advanced penetration testing, paired with the empathy and collaboration skills needed to help dev teams fix software vulnerabilities.
- Hands-on experience with Terraform for securing infrastructure-as-code and integrating security testing.
- Familiarity with our modern tech stack: GCP, Golang, and TypeScript.