Lead Application Security Engineer (m/f/d)

Stellenbeschreibung:

Overview

In this role, you will strengthen our cloud-native product security by embedding security into design, development, and deployment. You will partner with software engineers to enable secure-by-design practices and lead security reviews for key features and services. You will shape tooling and automation for SAST/DAST, guide remediation, and act as a trusted security advisor across engineering and platform teams. This role sits at the intersection of DevSecOps, compliance, and cross-functional collaboration to raise our security posture.

Leistungen / Benefits
  • 30 days vacation
  • flexible working hours
  • home office possibilities
  • learning time (10% of time)
  • EGYM Wellpass fitness program
  • flex budget for transport and meals (60 per month)
Verantwortungsbereiche
  • Drive secure-by-design enablement with software teams
  • Perform and manage security reviews for major features, services, APIs, and critical applications
  • Design, implement, and improve application security tooling and CI/CD integration (SAST/DAST)
  • Identify, validate, and prioritize vulnerabilities across apps, APIs, and cloud-native environments
  • Advise teams with practical remediation guidance and developer-friendly solutions
  • Collaborate with SRE/DevOps/platform teams to enhance security in containerized, cloud-native setups
  • Improve security awareness via documentation, guidance, and hands-on support
  • Stay current on threats and DevSecOps best practices for continuous improvement
  • Lead technical readiness and evidence collection for security certifications (SOC 2, ISO 27001)
  • Serve as the security authority in responses to prospects and clients to demonstrate compliance
Zentrale Anforderungen
  • Several years of experience in Application Security or Software Security Engineering
  • Strong knowledge of OWASP Top 10, secure coding, threat modeling, and security testing (SAST/DAST)
  • Proficient with modern software stacks and able to read/write code (Go, Java, Python) for reviews, PoCs, or tooling
  • Familiarity with cloud-native architectures, APIs, CI/CD pipelines, and containers (Kubernetes, Docker)
  • Mindset of working with engineers rather than gatekeeping
  • Structured, pragmatic, collaborative working style; able to shape greenfield processes
  • Professional proficiency in English
  • Collaborative mindset
  • Developer-friendly advisory approach
  • Pragmatic problem solving
  • SAST/DAST tooling
  • CI/CD integration for security tooling
  • Cloud-native and container security (Kubernetes, Docker)
NOTE / HINWEIS:
EnglishEN: Please refer to Fuchsjobs for the source of your application
DeutschDE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung

Stelleninformationen

  • Veröffentlichungsdatum:

    14 Sep 2026
  • Standort:

    München
  • Typ:

    Vollzeit
  • Arbeitsmodell:

    Vor Ort
  • Kategorie:

  • Erfahrung:

    2+ years
  • Arbeitsverhältnis:

    Angestellt

KI Suchagent

AI job search

Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!