Application Security Engineer
Summary
Application Security Engineer at Contentsquare in Barcelona working on securing SaaS applications through security audits, code reviews, and vulnerability management. Core technologies include NestJS, Vue.js, Angular, Snyk, Datadog ASM, AWS, Azure, Kubernetes, and Terraform.
The Contentsquare Security team is looking for an application security engineer (Appsec) who can work closely with the development team, product managers and diverse third-party groups (including bug bounty hunters).
Contentsquare provides a globally leading SaaS service and commits to the highest security standards for its customers. We are ISO 27001 and ISO 27701 certified and maintain robust security initiatives (SOC 2 Type 2 report, private bug bounty program, SIEM, advanced security awareness, etc.). Working alongside other cybersecurity experts, your mission will be to ensure the security of Contentsquare’s products and for keeping Contentsquare’s users and customers safe. You will work out of our Barcelona office.
What you'll do
-
Conduct continuous, automated security audits of our global SaaS applications to identify misconfigurations and ensure strict adherence to industry-standard security benchmarks and internal best practices.
-
Serve as a strategic security consultant to product and engineering teams, facilitating complex threat modeling sessions and AppSec reviews during the design phase to proactively mitigate risks.
-
Perform deep-dive, security-focused code reviews and mentor developers on secure coding patterns to minimize the introduction of high-impact vulnerabilities.
-
Architect and manage the end-to-end vulnerability lifecycle, developing sophisticated automation for the triage, reporting, and remediation tracking of security flaws across cloud infrastructure and application layers.
-
Orchestrate and optimize AI-driven security workflows, leveraging LLMs and autonomous agents to conduct scaleable, proactive vulnerability discovery and validation within our CI/CD pipelines.
-
Lead "Shift-Left" initiatives by integrating security checkpoints into the automation stack, developing custom security-as-code tools that empower developers to own security outcomes.
-
Oversee the strategic direction of our private and public bug-bounty programs, ensuring high-quality engagement with the researcher community and rapid internal response to critical findings.
-
Coordinate specialized external penetration testing engagements and customer-driven security assessments, acting as the primary technical point of contact for complex security inquiries.
-
Drive the technical response to application-level security incidents, conducting root-cause analysis to prevent recurrence and enhance our defensive posture.
What you'll need
-
3+ years of professional experience in Application Security Operations within a high-growth SaaS or cloud-native environment.
-
Advanced proficiency in securing modern technical stacks, with specific expertise in NestJS, Vue.js, and Angular frameworks.
-
Hands-on experience with enterprise security tooling, including Snyk, Datadog ASM/AppSec (WAF), Google SecOps, and Crowdstrike.
-
Deep architectural understanding of AWS and Azure environments, including Kubernetes/Docker container security and Infrastructure as Code (Terraform).
-
Demonstrated ability to apply AI and LLM technologies to automate security tasks, such as automated vulnerability validation or code analysis at scale.
-
Expertise in scripting and development (Python, Node.js, Shell) to build custom security tooling and integrations.
-
Comprehensive knowledge of web protocols, OWASP Top 10, and advanced threat frameworks (MITRE ATT&CK, NIST CSF).
-
Proven track record in ethical hacking, CTF competitions, or bug bounty hunting, showcasing a high level of technical tenacity and analytical rigor.
-
Exceptional cross-functional collaboration skills, with the ability to articulate complex security risks to both technical and non-technical stakeholders.
-
Fluency in English is mandatory
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website, Mutual consent I consent to the collection of my gender and race/ethnicity data. I am aware that providing this information is voluntary and that this data will solely be used by Contentsquare in an aggregated format to measure the diversity within candidate pools and to ensure a fair hiring process., What is your gender? (Optional & Voluntary), What is your race/races or ethnicity/ethnicities? Select one or more. (Optional & Voluntary)Select all that apply, Mutual consent I consent to the collection of my gender, race/ethnicity, and/or disability status data. I am aware that providing this information is voluntary and that this data will solely be used by Contentsquare in an aggregated format to measure the diversity within candidate pools and to ensure a fair hiring process., What is your race/races or ethnicity/ethnicities? Select one or more. (Optional & Voluntary), Disability* status (Optional & Voluntary)“Disability” can include but is not limited to any of the following disabilities, impairments or long-term health conditions: - Physical disability/ies (e.g. hearing, mobility or visual impairment/s) - Mental health condition/s (e.g. anxiety, depression, OCD, schizophrenia, bipolar) - Neurodivergent condition/s (e.g. ADHD, autistic spectrum disorder, dyslexia, dyspraxia) - Long-term health condition (e.g. Crohn's disease, chronic heart condition, diabetes, epilepsy, cancer - past or present)
- Where did you hear about this opportunity? choose one · optional
- If you selected "other" please specify below written answer · optional
- Do you now, or will you in the future, require sponsorship to work in the job posting location? choose one