Stellenangebot
(Senior) Application Security Engineer
Sygnurm sucht in Zürich einen (Senior) Application Security Engineer, der Sicherheitskonzepte in Cloud-native Umgebungen und CI/CD-Pipelines integriert. Die Rolle erfordert 5-7 Jahre Erfahrung in AppSec/DevSecOps sowie Kenntnisse in AWS/Azure, Kubernetes und der Automatisierung von Sicherheitsprozessen.
Aufgaben
- Evaluate application security dependencies and contribute to software supply chain security initiatives.
- Partner with engineering, platform, and product teams to design and implement secure-by-default architectures, perform threat modelling and promote secure software development practices.
- Partner to build new capabilities for application-layer security.
- Review and secure IAAS-enabled applications and services, including AI/ML integrations, pipeline security, model security controls, and secure deployment patterns.
- Partner with security teams to improve detection, alerting, and automation capabilities for application-layer threats.
- Review production code for public-facing systems like mobile apps, web apps, and backend services.
- Partner with software teams on threat modelling, static/dynamic analysis, and user input validation.
- Analyse code for vulnerabilities that meet security standards.
- Understand cloud architecture fundamentals, AWS, and Azure (preferred).
- Experience evaluating Infrastructure-as-Code and performing automated security code scans for backend, web, and/or mobile.
- Familiarity with application security concepts: Observability, detection engineering, production security operations.
- Knowledge of API security: authentication, authorization, API gateways, modern design patterns.
- Collaborate directly with engineers, influence technical roadmaps and implementation decisions.
- Experience building AI agents and applying AI to automate security remediation.
- Understand encryption and key management (AWS/Azure).
- Relevant education, certifications, or equivalent practical experience.
Anforderungen
- 5-7+ years of deep, hands-on experience in application security or DevSecOps in modern cloud-native environments.
- Strong experience securing cloud-native architectures (AWS and Azure preferred).
- Deep understanding of Kubernetes security, containers, and IaaS security.
- Experience reviewing Infrastructure-as-Code and performing secure code reviews across backend, web, and/or mobile applications.
- Practical knowledge of application security standards, e.g. OWASP Top 10 and API Top 10 in real-world systems.
- Familiarity with modern application security concepts including observability, detection engineering, and production security monitoring.
- Strong understanding of API security concepts including authentication, authorization, API gateways, and modern design patterns.
- Ability to work directly with engineers and influence technical design and implementation decisions.
- Experience building AI agents and applying AI to automate security remediation.
- Solid understanding of cryptography fundamentals and key management (KMS/HSM).
- Relevant education, certifications, or equivalent practical experience.
Wir bieten
- Attractive combination of market salaries and entrepreneurial incentive schemes
- Flexible-Work at home policies
- Professional development via Mentoring and Buddy programs
- One-month fully paid sabbatical after five years of continuous employment
Jobdetails