Job offer

(Senior) Application Security Engineer

Sygnym is looking for a (Senior) Application Security Engineer in Zurich to strengthen the security of modern cloud and Web3 applications through DevSecOps practices, CI/CD integrations, and threat modeling. The role requires 5+ years of experience in application security and cloud-native architectures (AWS/Azure), as well as knowledge of cryptography and, ideally, digital assets.

Tasks

  • Contribute to the implementation of security controls in CI/CD pipelines, including SAST, DAST, SCA, and IaC scanning, to strengthen DevSecOps practices.
  • Optimization, exploration, and implementation of application security tools to ensure that findings are actionable and integrated into engineering workflows.
  • Collaborate with engineering, platform, and product teams to design and implement secure-by-design architectures, conduct threat modeling, and promote secure development practices.
  • Assessment of open-source dependencies and contribution to initiatives for software supply chain security.
  • Assessment and securing of AI-powered applications and services, including LLM integrations, AI supply chain risks, model security controls, and secure deployment patterns.
  • Testing and hardening Infrastructure-as-Code implementations to enable secure cloud deployment patterns and reusable guardrails.
  • Assessment of the security design of smart contracts, blockchain integrations, and third-party Web3 services.
  • Collaborate with SOCs and engineering teams to improve detection, alerting, and response capabilities for application-level threats.

Requirements

  • 5+7+ years of in-depth, hands-on experience in application security or DevSecOps in modern engineering environments.
  • Extensive experience in securing cloud-native architectures (preferably AWS and Azure).
  • In-depth understanding of Kubernetes security, containers, and IaC security.
  • Experience reviewing Infrastructure-as-Code and conducting secure code reviews for backend, web, and mobile applications.
  • Practical knowledge of application security standards, such as the OWASP Top 10 and API Top 10, as applied in real-world systems.
  • Familiarity with concepts of runtime application security, including observability, detection engineering, and production security monitoring.
  • Strong understanding of API security concepts, including authentication, authorization, API gateways, and modern identity patterns.
  • Ability to work directly with engineers and influence design and implementation decisions.
  • Experience in developing AI agents and applying AI to automate secure security workflows.
  • In-depth knowledge of the fundamentals of cryptography and key management (KMS/HSM).
  • Relevant education, certifications, or equivalent practical experience.

Bonus Points

  • Experience with digital asset custody, Web3, smart contracts, or transaction signing workflows.
  • Proven experience in establishing or leading an application security function.
  • Background in offensive security, red teaming, or bug bounties.
  • Experience with regulatory requirements in the financial services sector (FINMA, MAS, DORA).

We offer

  • A generous, competitive salary and attractive performance-based bonuses.
  • Flexibility for hybrid/remote work arrangements within Switzerland.
  • Professional Development: Budget for training, conferences, and mentors.
  • Access to private health insurance for you and your family members.
  • Interest-free vacation loans.
  • A one-month, fully paid sabbatical after five years of continuous employment.

Job details

© 2025 House of Skills by skillaware. All rights reserved.
Our website uses cookies to make navigation easier for you and to analyze the use of the site. You can find more information in our privacy policy.