CareerPlanSign in

Application Security Engineer

Barcelona💼 Full-time🗓 2026-08-19 → 2026-09-26

Core

Offensive security engineer challenging the security of Contentsquare's SaaS products, web applications, APIs, and cloud-native services by acting as an attacker to identify and exploit vulnerabilities.

Role type

Senior IC Application Security Engineer (Offensive Security/Red Team)

Builds

Secure web applications, APIs, and cloud-native services for global SaaS customers

Domain

SaaS, Cloud Security, Web Application Security

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Offensive security testing, threat modeling, secure code review, vulnerability lifecycle management, AI/LLM security automation, security-as-code, bug bounty program management, penetration testing coordination, incident response, NestJS, Vue.js, Angular, Snyk, Datadog ASM, Google SecOps, Crowdstrike, AWS, Azure, Kubernetes, Docker, Terraform, Python, Node.js, Shell, OWASP Top 10, MITRE ATT&CK, NIST CSF

Preferred skills

Experience with high-growth SaaS environments, CTF competition participation

Technologies

NestJS, Vue.js, Angular, Snyk, Datadog ASM, Google SecOps, Crowdstrike, AWS, Azure, Kubernetes, Docker, Terraform, Python, Node.js, Shell

Responsibilities

Conduct automated security audits of global SaaS applications; Serve as a strategic security consultant for threat modeling and AppSec reviews; Perform deep-dive security code reviews and mentor developers; Architect and manage the vulnerability lifecycle; Orchestrate AI-driven security workflows using LLMs; Lead Shift-Left initiatives and security-as-code tool development; Oversee bug-bounty programs; Coordinate external penetration testing; Drive technical response to application-level security incidents

Seniority

Senior, hands-on IC

Sourced via lever · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.