Application Security Engineer
Location: Fully Remote (Within EU)
Rate: Up to €20 - 23/hour
About the Role
We are looking for an experienced Application Security Engineer to support security testing and vulnerability remediation across applications and infrastructure.
The role is hands-on and focuses on configuring and running application security scans, analyzing vulnerabilities, assessing risk, and providing clear remediation guidance to development and infrastructure teams. You will work closely with application owners, developers, DevOps teams, and security stakeholders to improve the overall security posture of applications.
Key Responsibilities
- Configure, execute, and maintain application security scans across different environments.
- Analyze security findings and vulnerabilities identified through SAST, DAST, and SCA tools.
- Assess vulnerability severity, risk, and potential impact.
- Provide development and infrastructure teams with technical remediation guidance.
- Support root cause analysis of identified vulnerabilities and security weaknesses.
- Track remediation activities and help ensure security findings are addressed within agreed timelines.
- Work closely with application owners, development teams, DevOps teams, suppliers, and security stakeholders.
- Support container security and secrets management activities.
- Contribute to secure development practices, security standards, and SSDLC improvements.
- Support the integration of security testing into CI/CD pipelines.
- Produce technical security reports and clear management-level summaries.
- Help improve application security processes, tooling, and overall security practices.
Requirements
- Professional experience in Application Security, Security Engineering, Vulnerability Management, or a similar security-focused role.
- Strong understanding of Secure Software Development Lifecycle (SSDLC) practices.
- Hands-on knowledge of: SAST – Static Application Security Testing, DAST – Dynamic Application Security Testing, SCA – Software Composition Analysis, OWASP Top 10, Vulnerability Management, Container Security, Secrets Management
- Ability to analyze technical security findings and recommend practical remediation actions.
- Experience collaborating with development, DevOps, and security teams.
- Strong troubleshooting and root cause analysis skills.
- Ability to communicate technical security risks clearly to both technical and non-technical stakeholders.
- Fluent English is mandatory.
Preferred Technical Experience
Experience with some of the following tools would be considered a strong advantage:
- Polaris – SAST and SCA
- Invicti – DAST
- Entro – Secrets Management
- Aqua Security – Container Security
- Cloud environments such as AWS, Microsoft Azure, or Google Cloud Platform (GCP)
- Security integration within CI/CD pipelines
Nice to Have
Relevant security certifications would be considered an advantage, including:
- OSCP
- GWAPT
- CSSLP
- CEH
- Similar Application Security or Cybersecurity certifications