Application Security Engineer
Summary
The Cloud Security Engineer will work with development and infrastructure teams to implement secure development practices, manage vulnerabilities, and ensure compliance in cloud-native and Kubernetes environments. The role involves using tools like SAST/DAST scanners, SIEM platforms, and threat modeling to secure applications.
About the role
We are looking for a Cloud Security Engineer to join our team and play a key role in strengthening security across cloud-native environments. In this position, you will work closely with development and infrastructure teams to identify security risks, improve secure development practices, and ensure compliance with relevant security standards.
You will have the opportunity to work with modern security tools, cloud technologies, containers, Kubernetes, and threat modelling methodologies in a dynamic, technology-driven environment.
Responsibilities:
- Support and promote secure software development practices throughout the SDLC.
- Identify, assess, and manage security vulnerabilities using industry-standard security tools and methodologies.
- Work with SAST, DAST, and vulnerability scanning solutions such as Tenable/Nessus, Rapid7, Aqua Security/Trivy.
- Monitor and investigate security events using SIEM platforms, including Splunk or Elastic.
- Collaborate with development and infrastructure teams to define and implement effective security solutions.
- Moderate and facilitate Threat Modelling workshops and translate identified risks into actionable mitigation plans.
- Contribute to security governance and ensure alignment with relevant compliance and security standards.
- Support the security of cloud-native applications, containers, and Kubernetes environments.
- Manage and track security findings and remediation activities using Jira or similar ticketing systems.
- Analyse complex security findings and provide clear, practical recommendations to technical and business stakeholders.
Requirements:
- Experience with SDLC and secure development practices.
- Strong knowledge of application and cloud security principles.
- Hands-on experience with SAST, DAST, and vulnerability scanning tools, such as Tenable/Nessus, Rapid7, Aqua Security/Trivy.
- Experience with SIEM solutions, preferably Splunk or Elastic.
- Experience with Jira or similar ticketing systems.
- Strong understanding of security and compliance standards, such as:
- ISO 27001
- SOC 2
- PCI-DSS
- IT-Grundschutz
- Experience moderating or facilitating Threat Modelling workshops.
- Deep understanding of cloud-native development, containers, and Kubernetes.
- Development experience with Python and/or Golang.
- Exposure to at least one major cloud platform: AWS, Azure, GCP, or OpenStack.
- Strong analytical and problem-solving skills with the ability to turn complex security findings into clear, actionable plans.
- Good communication and collaboration skills.
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company, LinkedIn URL
- Are you legally authorized to work in the country where you will be working? choose one · optional
- Will you now or in the future require sponsorship for an employment Visa? choose one · optional
- Are you currently residing in the hiring country mentioned for the position you are applying for? choose one · optional
- Are you able to commute to the Budapest office? choose one · optional