Application Security Engineer

About You — Germany · Posted ~2 hours ago

Visa History ✓

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

An Application Security Engineer is sought to join an IT security team responsible for protecting customer-facing online services and internal corporate systems. The position offers meaningful ownership, direct communication, pragmatic decision-making, and a collaborative environment with relatively flat structures.

Highlights

Join an application security team focused on protecting online services, corporate systems, and customers. The role offers ownership, direct communication, pragmatic decision-making, and a collaborative work culture.

Description

Company Description ABOUT YOU is one of Europe’s fastest growing e-commerce companies. Based in Hamburg and Berlin, we operate at the intersection of fashion and technology. Our mission is to rethink online shopping and make it personal and seamless. This takes more than good ideas. It takes people who take initiative and challenge the status quo. We believe in flat hierarchies, direct communication, and pragmatic decisions. No long approval chains. Just ownership, trust, and clear responsibility. We work hard, but we also believe in enjoying the ride together - over team lunches, afterwork drinks, company events, or a quick coffee in between meetings. If this sounds like you, ABOUT YOU could be the right place to bring in your perspective. Job Description We are looking for an Application Security Engineer (all genders) to join the Application Security circle of our IT-Security unit, dedicated to protecting our online shop, our corporate systems and our customers. In this role, you will hack internal systems, design and implement security measures to safeguard our infrastructure, applications, and data. You will work closely with other security engineers, developers and IT teams to ensure security best practices, automate security processes, and respond to emerging threats. Conduct regular penetration tests and code reviewsAdvise in the setup and maintenance of applications and infrastructure (usually hosted in AWS/Kubernetes)Triage and respond to monitoring eventsOptimization and automation of security auditing processes. This could also include setting up attack infrastructure, writing scripts in Python and implementing security scanning in Gitlab CITake part in some incident response activities within the SOC, which include occasional 24/7 on-call Qualifications At least 1+ year in a Junior-level position and overall min. 2+ years of experience in application securityStrong background in threat modeling, penetration testing, and manual secure code reviewsFluency in Python for security automation, tooling, and code assessmentSolid hands-on experience securing modern cloud environments (AWS or GCP)Demonstrated ability to manage complex technical security projects, align dependencies, and track deliverables across multi-functional engineering teams Nice to have Certificates: e.g. OSCP, OSWP, etc.Knowledge of Laravel / PHP.Ability to read and understand JavaScriptAbility to read and understand GoExperience with incident response activitiesExperience with web application firewalls, CDN providers, e.g. Cloudflare, AkamaiExperience with Gitlab CI/CD Pipelines Additional Information Your perks at a glance: Visit our benefits page. Simply apply online via our career page - we will get back to you as soon as possible! A Place Where You Can Be You We take it as our responsibility to create an environment where everyone feels welcome, exactly as they are. Different backgrounds and perspectives make us stronger and shape our culture in ways that matter. What we stand for internally, we stand for as a brand: acceptance, inclusion, and a fairer approach to fashion.