Job offer
(Senior) Application Security Engineer
Sygnurm is looking for a (Senior) Application Security Engineer in Zurich to integrate security concepts into cloud-native environments and CI/CD pipelines. The role requires 5–7 years of experience in AppSec/DevSecOps, as well as knowledge of AWS/Azure, Kubernetes, and the automation of security processes.
Tasks
- Evaluate application security dependencies and contribute to software supply chain security initiatives.
- Partner with engineering, platform, and product teams to design and implement architectures that are secure by default, perform threat modeling, and promote secure software development practices.
- Partner to develop new capabilities for application-layer security.
- Review and secure IaaS-enabled applications and services, including AI/ML integrations, pipeline security, model security controls, and secure deployment patterns.
- Partner with security teams to improve detection, alerting, and automation capabilities for application-layer threats.
- Review production code for public-facing systems such as mobile apps, web apps, and backend services.
- Collaborate with software teams on threat modeling, static and dynamic analysis, and user input validation.
- Analyze code for vulnerabilities that meet security standards.
- Understand the fundamentals of cloud architecture, AWS, and Azure (preferred).
- Experience evaluating Infrastructure-as-Code and performing automated security code scans for backend, web, and/or mobile applications.
- Familiarity with application security concepts: observability, detection engineering, and production security operations.
- Knowledge of API security: authentication, authorization, API gateways, modern design patterns.
- Collaborate directly with engineers, influence technical roadmaps and implementation decisions.
- Experience building AI agents and applying AI to automate security remediation.
- Understand encryption and key management (AWS/Azure).
- Relevant education, certifications, or equivalent practical experience.
Requirements
- 5–7+ years of in-depth, hands-on experience in application security or DevSecOps in modern cloud-native environments.
- Extensive experience securing cloud-native architectures (AWS and Azure preferred).
- In-depth understanding of Kubernetes security, containers, and IaaS security.
- Experience reviewing Infrastructure-as-Code and conducting secure code reviews for backend, web, and/or mobile applications.
- Practical knowledge of application security standards, such as the OWASP Top 10 and API Top 10, as applied in real-world systems.
- Familiarity with modern application security concepts, including observability, detection engineering, and production security monitoring.
- A strong understanding of API security concepts, including authentication, authorization, API gateways, and modern design patterns.
- Ability to work directly with engineers and influence technical design and implementation decisions.
- Experience building AI agents and applying AI to automate security remediation.
- A solid understanding of the fundamentals of cryptography and key management (KMS/HSM).
- Relevant education, certifications, or equivalent practical experience.
We offer
- An attractive combination of market-rate salaries and entrepreneurial incentive programs
- Flexible work-from-home policies
- Professional Development Through Mentoring and Buddy Programs
- A one-month, fully paid sabbatical after five years of continuous employment
Job details