Summary
✨ AI‑Generated
A growing technology organization is seeking an Application Security Engineer to strengthen the security of its web applications, internal systems, and customer-facing services. You will work within a dedicated security team, take meaningful ownership of security initiatives, and collaborate closely with engineering teams to improve the overall security posture.
Highlights
Join a dedicated security team focused on protecting digital applications, corporate systems, and customers. The role offers strong ownership, direct communication, pragmatic decision-making, and the opportunity to work in a collaborative technology environment.
Description
Company Description
ABOUT YOU is one of Europe’s fastest growing e-commerce companies.
Based in Hamburg and Berlin, we operate at the intersection of fashion and technology.
Our mission is to rethink online shopping and make it personal and seamless.
This takes more than good ideas.
It takes people who take initiative and challenge the status quo.
We believe in flat hierarchies, direct communication, and pragmatic decisions.
No long approval chains.
Just ownership, trust, and clear responsibility.
We work hard, but we also believe in enjoying the ride together - over team lunches, afterwork drinks, company events, or a quick coffee in between meetings.
If this sounds like you, ABOUT YOU could be the right place to bring in your perspective.
Job Description
We are looking for an Application Security Engineer (all genders) to join the Application Security circle of our IT-Security unit, dedicated to protecting our online shop, our corporate systems and our customers.
In this role, you will hack internal systems, design and implement security measures to safeguard our infrastructure, applications, and data.
You will work closely with other security engineers, developers and IT teams to ensure security best practices, automate security processes, and respond to emerging threats.
Conduct regular penetration tests and code reviewsAdvise in the setup and maintenance of applications and infrastructure (usually hosted in AWS/Kubernetes)Triage and respond to monitoring eventsOptimization and automation of security auditing processes.
This could also include setting up attack infrastructure, writing scripts in Python and implementing security scanning in Gitlab CITake part in some incident response activities within the SOC, which include occasional 24/7 on-call
Qualifications
Application securitySecurity engineeringTechnical Project Management skillsThreat modelingPenetration testingSecure code reviewCloud experience: AWS, Bonus: GCP, AzureProgramming experience: Python required, Bonus: PHP, JavaScript, GoRed teaming is a plus
Nice to have
Certificates:Offensive Security certificates; e.g.
OSCP, OSWP, etc.Knowledge of Laravel / PHP.Ability to read and understand JavaScriptAbility to read and understand GoExperience with incident response activitiesExperience with web application firewalls, CDN providers, e.g.
Cloudflare, AkamaiExperience with Gitlab CI/CD Pipelines
Additional Information
Your perks at a glance: Visit our benefits page.
Simply apply online via our career page - we will get back to you as soon as possible!
A Place Where You Can Be You
We take it as our responsibility to create an environment where everyone feels welcome, exactly as they are.
Different backgrounds and perspectives make us stronger and shape our culture in ways that matter.
What we stand for internally, we stand for as a brand: acceptance, inclusion, and a fairer approach to fashion.