Job Drop BerlinYOUR WAY INTO BERLIN TECH
Theme
NewsletterLinkedIn
AboutTermsImpressumPrivacy
Browse jobs
Engineering jobs in BerlinProduct jobs in BerlinDesign jobs in BerlinMarketing jobs in BerlinSales jobs in BerlinData jobs in BerlinOperations jobs in BerlinFinance jobs in BerlinCustomer success jobs in BerlinPeople & HR jobs in BerlinEnglish-speaking jobs in BerlinRemote jobs at Berlin startupsStartup internships in BerlinEnglish-speaking working student jobs in BerlinEnglish-speaking junior jobs in BerlinEnglish-speaking fintech jobs in BerlinEnglish-speaking ai & machine learning jobs in BerlinEnglish-speaking senior jobs in Berlin

Senior Application Security Engineer

DDistribusion Technologies
Seniority
Senior
Model
Remote
Sector
Travel tech
Salary
Undisclosed
Contract
Full-Time

Build the AppSec practice from the ground up as the first dedicated Application Security Engineer. You will own secure development, define what gets reviewed, implement security gates, and build the "paved road" for ~150 engineers with a real attack surface: public partner-facing APIs and payment flows.

What you'll do

  • Lead threat modeling and secure design reviews for high-risk changes, partner integrations, and payment flows.
  • Implement, tune, and enforce security gates in GitLab CI/CD (SAST, SCA, secrets scanning, and DAST) while minimizing developer friction.
  • Act as the primary technical owner for triaging, reproducing, and prioritizing findings from bug bounties, partner pentests, and automated scanners.
  • Work hands-on with the DevOps team to implement GCP organizational policies, IAM least-privilege architectures, and Cloud Armor (WAF/rate limiting).
  • Establish a security-champions network across engineering squads and leverage automation/AI-assisted tooling to scale code reviews effectively.
  • Own vulnerability management end to end: a risk-ranked backlog, remediation SLAs, an escalation path, and closing findings together with the teams.

What you'll need

  • 5+ years in AppSec (or 3+ years plus a strong software engineering/web-pentesting background), with a track record of true ownership.
  • Read and write production code (Python, Go, TypeScript, Ruby, etc.) and deeply understand web frameworks, CI/CD, and Kubernetes.
  • Deep knowledge of web and API security, specifically authentication/authorization models (OAuth2, JWT), rate limiting, tenant isolation, IDOR, and XSS.
  • Strong cloud security fundamentals (GCP preferred), specifically regarding public exposure, secrets hygiene, and WAF rules.
  • Experience running threat modelling and secure design reviews on real systems (STRIDE or similar).
  • Hands-on with SAST/SCA/secrets scanning in CI (Aikido, Semgrep, Snyk or similar).
  • Prioritize by real-world risk, propose trade-offs rather than demanding perfection, and communicate complex risks plainly to engineers and leadership.

Nice to have

  • Experience securing high-volume, multi-tenant B2B APIs and utilizing AI tooling to accelerate triage and review.

What they offer

  • Flat organizational structure with exciting opportunities, ownership, and responsibility.
  • International team of talented and driven people with a clear mission.
  • Flexible work policy with remote work options and international opportunities.
  • Competitive salary.
APPLY →

ABOUT DISTRIBUSION TECHNOLOGIES

Travel tech · Series B stage

100+ employees

23 more open roles at Distribusion Technologies

This role is English-speaking. No German required.

SIMILAR OPEN ROLES

More roles like this, every Thursday →

No spam. Unsubscribe anytime.