Senior Security Engineer - Application Security
Core
Safeguard Trade Republic's applications and development lifecycle through proactive security integration and engineering excellence.
Role type
Senior IC application security engineer
Builds
Secure software development lifecycle, automated security testing pipelines, and secure architecture for a European savings platform
Domain
Fintech / Application Security
Deliverable
production ML models | product features | infrastructure
Required skills
Web application security (OWASP Top 10, API security, auth/authorization), security testing tools (Burp Suite, OWASP ZAP, Semgrep), programming (Python, Java, Kotlin, Go, JavaScript), CI/CD integration, secure architecture patterns (microservices, APIs, distributed systems), cryptography, session management, identity/access management
Preferred skills
Cryptocurrency/blockchain infrastructure security, mobile application security (iOS/Android), compliance frameworks (PCI-DSS, GDPR, MaRisk)
Technologies
Burp Suite, OWASP ZAP, Semgrep, GitHub Actions, GitLab CI, Jenkins
Responsibilities
Partner with engineering to embed security in SDLC; conduct security code reviews, threat modeling, and architecture reviews; design/implement SAST, DAST, and SCA solutions; build security testing automation in CI/CD; develop secure coding standards and reusable components; perform penetration testing and vulnerability assessments; triage and remediate vulnerabilities; create security champions program and training; research emerging threats; manage bug bounty program
Seniority
Senior, hands-on IC