Trade Republic

Senior Security Engineer - Application Security

Trade RepublicLocation Not Available

Stellenbeschreibung:

Position based in Berlin or London.

Responsibilities

  • Partner with engineering teams to embed security into the software development lifecycle from design to deployment.
  • Conduct security code reviews, threat modeling sessions, and architecture reviews for critical applications and services.
  • Design and implement SAST, DAST, and SCA solutions to identify vulnerabilities early in the development process.
  • Build and maintain application security testing automation within CI/CD pipelines.
  • Develop secure coding standards, security libraries, and reusable security components for engineering teams.
  • Perform penetration testing and vulnerability assessments of web applications, APIs, and mobile applications.
  • Triage, prioritise, and remediate application vulnerabilities working closely with development teams.
  • Create security champions program and provide security training to engineering teams.
  • Research emerging application security threats and integrate defensive measures into the security architecture.
  • Contribute to bug bounty program management and coordinate with external security researchers.

Qualifications

  • 5+ years as a Security Engineer with 4+ years focused on application security.
  • Deep understanding of web application security (OWASP Top 10, API security, authentication/authorization).
  • Hands‑on experience with security testing tools (Burp Suite, OWASP ZAP, Semgrep, etc.).
  • Strong programming skills in modern languages (Python, Java, Kotlin, Go, or JavaScript).
  • Experience integrating security tooling into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins).
  • Expertise in secure architecture patterns for microservices, APIs, and distributed systems.
  • Solid understanding of cryptography, secure session management, and identity/access management.
  • Hands‑on experience with security testing of cryptocurrency/blockchain infrastructure and applications is a major bonus.
  • Experience with mobile application security (iOS/Android).
  • Knowledge of compliance frameworks (PCI‑DSS, GDPR, MaRisk) is advantageous.
  • Excellent communication skills to translate security concepts for engineering audience.

Diversity & Inclusion

We believe it's our team's varied identities and backgrounds that make us sharper and stronger. We are committed to creating an environment where everyone feels respected and has equal opportunity to thrive in their careers. For any questions on DEI during the interview process, reach out to your recruitment partner.

#J-18808-Ljbffr
NOTE / HINWEIS:
EnglishEN: Please refer to Fuchsjobs for the source of your application
DeutschDE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung

Stelleninformationen

  • Veröffentlichungsdatum:

    20 Mai 2026
  • Standort:

    Einsatzort:

    Berlin
  • Typ:

    Vollzeit
  • Arbeitsmodell:

    Vor Ort
  • Kategorie:

  • Erfahrung:

    2+ years
  • Arbeitsverhältnis:

    Angestellt

KI Suchagent

AI job search

Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!