Job offer
(Senior) Application Security Engineer
Sygnym is looking for a (Senior) Application Security Engineer in Zurich to strengthen the security of modern cloud and Web3 applications through DevSecOps practices, CI/CD integrations, and threat modeling. The role requires 5+ years of experience in application security and cloud-native architectures (AWS/Azure), as well as knowledge of cryptography and, ideally, digital assets.
Tasks
- Contribute to the implementation of security controls in CI/CD pipelines, including SAST, DAST, SCA, and IaC scanning, to strengthen DevSecOps practices.
- Optimization, exploration, and implementation of application security tools to ensure that findings are actionable and integrated into engineering workflows.
- Collaborate with engineering, platform, and product teams to design and implement secure-by-design architectures, conduct threat modeling, and promote secure development practices.
- Assessment of open-source dependencies and contribution to initiatives for software supply chain security.
- Assessment and securing of AI-powered applications and services, including LLM integrations, AI supply chain risks, model security controls, and secure deployment patterns.
- Testing and hardening Infrastructure-as-Code implementations to enable secure cloud deployment patterns and reusable guardrails.
- Assessment of the security design of smart contracts, blockchain integrations, and third-party Web3 services.
- Collaborate with SOCs and engineering teams to improve detection, alerting, and response capabilities for application-level threats.
Requirements
- 5+7+ years of in-depth, hands-on experience in application security or DevSecOps in modern engineering environments.
- Extensive experience in securing cloud-native architectures (preferably AWS and Azure).
- In-depth understanding of Kubernetes security, containers, and IaC security.
- Experience reviewing Infrastructure-as-Code and conducting secure code reviews for backend, web, and mobile applications.
- Practical knowledge of application security standards, such as the OWASP Top 10 and API Top 10, as applied in real-world systems.
- Familiarity with concepts of runtime application security, including observability, detection engineering, and production security monitoring.
- Strong understanding of API security concepts, including authentication, authorization, API gateways, and modern identity patterns.
- Ability to work directly with engineers and influence design and implementation decisions.
- Experience in developing AI agents and applying AI to automate secure security workflows.
- In-depth knowledge of the fundamentals of cryptography and key management (KMS/HSM).
- Relevant education, certifications, or equivalent practical experience.
Bonus Points
- Experience with digital asset custody, Web3, smart contracts, or transaction signing workflows.
- Proven experience in establishing or leading an application security function.
- Background in offensive security, red teaming, or bug bounties.
- Experience with regulatory requirements in the financial services sector (FINMA, MAS, DORA).
We offer
- A generous, competitive salary and attractive performance-based bonuses.
- Flexibility for hybrid/remote work arrangements within Switzerland.
- Professional Development: Budget for training, conferences, and mentors.
- Access to private health insurance for you and your family members.
- Interest-free vacation loans.
- A one-month, fully paid sabbatical after five years of continuous employment.
Job details