SlipstreamJobsFresh Startup & VC-Backed Jobs

Application Security Engineer

Heap - Barcelona, Spain - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Contentsquare, a global leader in experience analytics and digital intelligence, is seeking an Application Security Engineer to join its Security team in Barcelona. This role sits at the intersection of security strategy and engineering execution, requiring deep technical expertise in securing modern SaaS platforms. You will conduct continuous automated security audits of Contentsquare's global SaaS applications, identifying misconfigurations and ensuring adherence to industry-standard security benchmarks. You'll serve as a strategic security consultant to product and engineering teams, facilitating threat modeling sessions and AppSec reviews during the design phase to proactively mitigate risks. Key responsibilities include performing deep-dive security-focused code reviews, mentoring developers on secure coding patterns, and architecting the end-to-end vulnerability lifecycle with sophisticated automation for triage, reporting, and remediation tracking. You'll orchestrate AI-driven security workflows, leveraging LLMs and autonomous agents for scalable vulnerability discovery within CI/CD pipelines. You'll lead Shift-Left initiatives by integrating security checkpoints into the automation stack and developing custom security-as-code tools that empower developers. You'll oversee the strategic direction of Contentsquare's private and public bug-bounty programs, coordinate external penetration testing engagements, and drive technical response to application-level security incidents. Required qualifications: 3+ years of professional Application Security Operations experience in high-growth SaaS or cloud-native environments. Advanced proficiency in securing modern stacks (NestJS, Vue.js, Angular). Hands-on experience with enterprise security tooling (Snyk, Datadog ASM/AppSec, Google SecOps, Crowdstrike). Deep architectural understanding of AWS and Azure, including Kubernetes/Docker and Infrastructure as Code. Demonstrated ability to apply AI/LLM technologies to automate security tasks. Expertise in Python, Node.js, and Shell scripting. Comprehensive knowledge of web protocols, OWASP Top 10, and threat frameworks (MITRE ATT&CK, NIST CSF). Proven track record in ethical hacking, CTF competitions, or bug bounty hunting. Exceptional cross-functional collaboration skills and fluency in English. Contentsquare offers hybrid and remote work flexibility, generous paid time off, lifestyle allowance, stock options for all full-time employees, career development and mentorship, and multiple Employee Resource Groups.

Similar roles