Senior Application Security Engineer (España)

Senior Application Security Engineer (España)

04 ago
|
Maisa
|
España

04 ago

Maisa

España

ppJoin to apply for the bSenior Application Security Engineer /b role at bMaisa /b /p pbWelcome to Maisa - Making AI Accountable! /b /p pOur agentic process automation platform helps enterprises automate complex, decision-heavy processes that traditional automation can’t handle and GenAI can’t be trusted with. /p pWe enable organizations to scale operations, resist hallucinations, and bring end-to-end visibility and control to your most complex processes. /p pPowered by a new kind of computing platform, Maisa combines AI-driven problem solving with programmatic execution, so every action is reliable, auditable, and built for enterprise scale. /p h3About the role… /h3 pWe're looking for a Senior Application Security Engineer to own and scale our Vulnerability Management Program, embed security into CI/CD pipelines, and perform deep code security reviews. This hands‑on role partners with Engineering, SRE, and GRC to measurably reduce application risk across our portfolio. We value engineers who automate first, build guardrails instead of gates, and help teams ship secure software fast. /p h3What you’ll do… /h3 pbVulnerability Management (Program Ownership): /b /p ul liDefine and operate end-to-end vulnerability management lifecycle (SCA, SAST, DAST, container, IaC scanning) /li liEstablish risk‑based triage using CVSS and exploited vulnerability catalogs /li liIntegrate scanners into bCI/CD /b (bGitHub Actions /b) and container registries /li liBuild automated patch/dependency‑update pipelines (e.g., bDependabot /b automated PRs) /li liGenerate and store bSBOMs /b; implement image signing and provenance (Sigstore, cosign, SLSA) /li liTrack MTTR, time‑to‑first‑fix, and executive‑level security metrics /li liPartner with GRC to align with bISO 27001 /b and bSOC 2 /b frameworks /li /ul pbSecurity in CI/CD (Shift‑Left Supply Chain): /b /p ul liEmbed bSAST,



SCA /b, secret scanning, and IaC checks into pipelines /li liEnforce branch protections, mandatory code reviews, and artifact signing /li liChampion least‑privilege pipelines, ephemeral runners, and hardened build environments /li liPublish attestations and SBOMs with every release /li /ul pbCode Security Reviews (Depth Where It Matters): /b /p ul liPerform targeted manual reviews of critical code paths (auth/authz, crypto, multi‑tenant boundaries, PII handling) /li liWrite concise, actionable review notes with clear risk statements and remediation guidance /li liCollaborate with developers to land fixes quickly /li liContribute to secure coding patterns and internal libraries /li liDeliver developer training based on real findings /li /ul h3What you’ll bring… /h3 ul liStrong demonstrable experience in Application Security or Security Engineering /li liProven ownership of a Vulnerability Management or Secure SDLC program /li liStrong hands‑on skills with at least two programming languages: Go, Python, TypeScript/Node.js, or Java /li liExperience integrating SAST/SCA/DAST/Secrets/IaC tools into Git-based CI/CD (GitHub Actions preferred) /li liSolid understanding of container and Kubernetes security (image scanning, admission controls, PodSecurity) /li liDeep knowledge of authn/authz, cryptography, SSRF/XSS/Injection classes,



and modern web/API architectures /li liFamiliarity with ISO 27001 and SOC 2 requirements for software security /li liExcellent communication and stakeholder management skills /li liFluent Spanish (essential for client interactions) /li liAny familiarity with tools such as: Semgrep, CodeQL, Trivy, Grype, Snyk, Dependabot, Checkov, tfsec, ZAP, Burp, SonarQube would be beneficial. As would any formal certifications such as OSWE, OSCP, GCSA, GWAPT, GWEB, CSSLP. /li /ul pYou will be joining one of Europe’s most exciting early‑stage AI start‑ups, where you’ll have the opportunity to work with cutting‑edge Agentic Process Automation that’s reshaping how enterprises approach AI deployment. You will get to directly influence how major multinational organizations transform critical business processes, working on genuinely differentiated technology that solves real enterprise AI challenges. /p pFollowing our recent $25m Seed Round, backed by leading Venture Capital firms including Creandum, Forgepoint, NFX, and Village General, we’re scaling quickly and realizing significant enterprise traction. This is your opportunity to help solve real AI enterprise challenges, working alongside deep technical and industry experts, where you will be challenged daily and expedite your learning and development. /p pMaisa is committed to Equal Employment Opportunity through attracting and retaining a complementary team of employees and building an inclusive environment for all. /p h3Seniority level /h3 pMid‑Senior level /p h3Employment type /h3 pFull‑time /p h3Job function /h3 pIT Services and IT Consulting /p pReferrals increase your chances of interviewing at Maisa by 2x /p pGet notified about new Senior Application Security Engineer jobs in bSpain /b. /p pWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI. /p /p #J-18808-Ljbffr

📌 Senior Application Security Engineer (España)
🏢 Maisa
📍 España

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior application security engineer (españa) / españa

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior application security engineer (españa) / españa