The AI Job Search Engine
Senior Application & Product Security Engineer(m/w/x)
Embedding security into the development lifecycle for a language learning platform, with threat modeling and cloud security posture improvement. Solid understanding of cloud-native architectures and platforms (AWS, GCP, Azure) required. 30 vacation days, Jobbatical up to 3 months in EU/UK.
Requirements
- Strong experience in application, product, or software security engineering roles
- Solid understanding of modern software development practices, cloud-native architectures, and cloud platforms (AWS, GCP, Azure)
- Hands-on experience with secure coding principles, common vulnerability classes (OWASP Top 10), and secure code reviews
- Proficiency with security tooling (SAST, DAST, SCA, CSPM, secrets scanning, CI/CD security automation)
- Experience performing threat modeling and delivering actionable recommendations
- Familiarity with securing AI/ML systems, LLM integrations, or agentic AI architectures
- Strong communication skills
- Ability to partner with engineers
- Ability to contribute to architectural discussions
- Ability to explain security concepts to non-technical stakeholders
- Background as a software engineer or developer
- Experience with Infrastructure as Code (Terraform) and CI/CD automation (GitHub Actions)
- Experience in a product-led or agile development environment
- Knowledge of regulatory or certification frameworks (ISO 27001)
- Ability to work in English
- Openness to learning
Tasks
- Build, maintain, and evolve the application and product security program.
- Embed security into the development lifecycle.
- Improve cloud security posture.
- Identify risks early with pragmatic solutions.
- Lead threat modeling throughout the development lifecycle.
- Identify risks in new features, architecture, and existing systems.
- Mitigate risks in new features, architecture, and existing systems.
- Define and implement secure coding standards.
- Conduct and guide secure code reviews.
- Deliver developer training and best practices.
- Design and manage security automation across the SDLC.
- Implement automated scanning.
- Implement security gates in CI/CD pipelines.
- Enforce policy-as-code.
- Manage software supply chain security.
- Manage vulnerability detection, triage, prioritization, and remediation.
- Monitor emerging threats.
- Monitor industry trends relevant to the technology stack.
- Lead application-layer incident response.
- Drive secure AI adoption across the organization.
- Establish a framework for responsible and secure AI use.
- Adapt security to evolving AI capabilities and integrations.
Work Experience
Education
Languages
Tools & Technologies
Benefits
Flexible Working
- •Flexible working hours
More Vacation Days
- •30 vacation days
Family Support
- •Family and life situation counseling
Workation & Sabbatical
- •Jobbatical (up to 3 months in EU/UK)
Modern Office
- •Office with nap, faith, family rooms
Learning & Development
- •Internal learning opportunities
- •Yearly L&D budget
Other Benefits
- •Free Babbel language access
- •DE&I Community Networks
Parking & Commuter Benefits
- •Mobility benefits
Corporate Discounts
- •Discounted Urban Sports Club membership
Team Events
- •Cultural and social events
- Trade RepublicFull-timeOn-siteSeniorBerlin
- Trade Republic
Senior Security Engineer - Application Security(m/w/x)
Full-timeOn-siteSeniorBerlin - bonify
Senior Security Engineer(m/w/x)
Full-timeOn-siteSeniorBerlin - AutoScout24
Security Engineer(m/w/x)
Full-timeOn-siteExperiencedBerlin, München - Babbel
Senior Android Engineer - App Platform(m/w/x)
Full-timeOn-siteSeniorBerlin
Senior Application & Product Security Engineer(m/w/x)
Embedding security into the development lifecycle for a language learning platform, with threat modeling and cloud security posture improvement. Solid understanding of cloud-native architectures and platforms (AWS, GCP, Azure) required. 30 vacation days, Jobbatical up to 3 months in EU/UK.
Requirements
- Strong experience in application, product, or software security engineering roles
- Solid understanding of modern software development practices, cloud-native architectures, and cloud platforms (AWS, GCP, Azure)
- Hands-on experience with secure coding principles, common vulnerability classes (OWASP Top 10), and secure code reviews
- Proficiency with security tooling (SAST, DAST, SCA, CSPM, secrets scanning, CI/CD security automation)
- Experience performing threat modeling and delivering actionable recommendations
- Familiarity with securing AI/ML systems, LLM integrations, or agentic AI architectures
- Strong communication skills
- Ability to partner with engineers
- Ability to contribute to architectural discussions
- Ability to explain security concepts to non-technical stakeholders
- Background as a software engineer or developer
- Experience with Infrastructure as Code (Terraform) and CI/CD automation (GitHub Actions)
- Experience in a product-led or agile development environment
- Knowledge of regulatory or certification frameworks (ISO 27001)
- Ability to work in English
- Openness to learning
Tasks
- Build, maintain, and evolve the application and product security program.
- Embed security into the development lifecycle.
- Improve cloud security posture.
- Identify risks early with pragmatic solutions.
- Lead threat modeling throughout the development lifecycle.
- Identify risks in new features, architecture, and existing systems.
- Mitigate risks in new features, architecture, and existing systems.
- Define and implement secure coding standards.
- Conduct and guide secure code reviews.
- Deliver developer training and best practices.
- Design and manage security automation across the SDLC.
- Implement automated scanning.
- Implement security gates in CI/CD pipelines.
- Enforce policy-as-code.
- Manage software supply chain security.
- Manage vulnerability detection, triage, prioritization, and remediation.
- Monitor emerging threats.
- Monitor industry trends relevant to the technology stack.
- Lead application-layer incident response.
- Drive secure AI adoption across the organization.
- Establish a framework for responsible and secure AI use.
- Adapt security to evolving AI capabilities and integrations.
Work Experience
Education
Languages
Tools & Technologies
Benefits
Flexible Working
- •Flexible working hours
More Vacation Days
- •30 vacation days
Family Support
- •Family and life situation counseling
Workation & Sabbatical
- •Jobbatical (up to 3 months in EU/UK)
Modern Office
- •Office with nap, faith, family rooms
Learning & Development
- •Internal learning opportunities
- •Yearly L&D budget
Other Benefits
- •Free Babbel language access
- •DE&I Community Networks
Parking & Commuter Benefits
- •Mobility benefits
Corporate Discounts
- •Discounted Urban Sports Club membership
Team Events
- •Cultural and social events
About the Company
Babbel
Industry
Education
Description
The company is one of the fastest-growing education technology companies, committed to creating diverse learning experiences.
- Trade Republic
Senior Security Engineer - Cloud Security(m/w/x)
Full-timeOn-siteSeniorBerlin - Trade Republic
Senior Security Engineer - Application Security(m/w/x)
Full-timeOn-siteSeniorBerlin - bonify
Senior Security Engineer(m/w/x)
Full-timeOn-siteSeniorBerlin - AutoScout24
Security Engineer(m/w/x)
Full-timeOn-siteExperiencedBerlin, München - Babbel
Senior Android Engineer - App Platform(m/w/x)
Full-timeOn-siteSeniorBerlin