Skip to content
← Back to job listings

Cyber Security Staff Engineer (Application Security)

Solaris · Berlin, Germany

External listingfull-time24 days ago

About The Role

Join our team as a Cyber Security Staff Engineer (Application Security) and play a crucial role in integrating security into the Software Development Lifecycle (SDLC) and DevSecOps pipelines. You will conduct threat modeling, perform secure code reviews, and build internal libraries and frameworks to eliminate vulnerabilities. Additionally, you will take ownership of the application vulnerability lifecycle, provide guidance to product and engineering teams, and support incident response efforts. This position offers a range of benefits, including a learning and development budget, remote working allowance, and additional vacation days.

  • Integrate security seamlessly into the Software Development Lifecycle (SDLC) and DevSecOps pipelines by automating security gates.
  • Conduct thorough threat modeling and architectural security reviews for complex applications, APIs, and microservices prior to deployment.
  • Perform deep-dive manual and automated secure code reviews across various codebases to identify logic flaws and subtle implementation vulnerabilities.
  • Depending on your level of experience, your responsibilities and scope of role will range. We don’t care much about fancy titles, but rather about real personal and professional development, as laid out in our learning framework. Let’s figure together out how you can contribute to our team
  • Business proficient written and spoken English. German is a plus
  • Hands-on experience integrating security testing tools into modern CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins, Snyk, Semgrep)
  • Proven experience analyzing and securing code written in our core tech stack/modern languages (e.g., Java, Go, Python, TypeScript, or Rust)
  • 6+ years of experience in dedicated Application Security, DevSecOps, or Software Engineering roles with a strong focus on security in high-growth cloud environments (Fintech or highly regulated environment is a plus)
  • Ability to translate complex cryptographic or technical security vulnerabilities into business risk for non-technical stakeholders and actionable fixes for developers
  • Experience managing or triaging external penetration testing reports and crowdsourced bug bounty programs
  • Individual Contributor, technical mentorship focus
  • Curious, constant learner that is willing to share learning with others
  • Strong analytical mindset capable of finding creative ways to secure cutting-edge application architectures
  • Ability to thrive in a fast-paced environment and adapt security strategies to evolving product frameworks
  • A degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or equivalent professional experience
  • Experience with cloud computing infrastructure (AWS, GCP, or Azure), containerization (Docker), and orchestration (Kubernetes)
  • Empathic collaborator who builds bridges between security goals and engineering targets, avoiding the "department of No" stereotype
  • Proactive peer that helps the growth of the team
  • Deep understanding of web application vulnerabilities, API security, and exploitation techniques (OWASP Top 10, CWE)
  • Experience by doing threat modeling
  • Understands agile workflows and lean principles
  • Unfortunately, many promising candidates tend to apply only if they meet all the criteria. So if you think you have what it takes, but don't necessarily meet every single item in the job description, please contact us anyway. We'd love to talk with you and find out if you might be a good fit for us

This is an external listing. JobSpring does not represent or verify the employer. Report this listing