🏢 Offshore Consulting Shops

AgileEngine is a software development consultancy and IT staffing provider that hires engineers to work on projects for its external clients, rather than as a direct employer for internal product development.

This company was flagged and excluded from default search results. Proceed with caution.

AgileEngine
Posted 1mo ago

Application Security Engineer ID71662

AgileEngine
Bucharest, Bucharest, Romania
HybridFull Time
Responsibilities
  • integrating security
  • tuning scanners
  • providing remediation
Requirements
  • 3–5 years of combined software engineering and AppSec/DevSecOps experience
  • Strong Python scripting
  • CI/CD integration and vulnerability tool tuning
  • English upper-intermediate
Technical tools mentioned
PythonJavaCI/CDSASTDASTSCAWiz

Job description

AgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards.

WHY JOIN US
If you're looking for a place to grow, make an impact, and work with people who care, we'd love to meet you!

ABOUT THE ROLE
We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated hardened baseline deployment within a large-scale financial services security program. You will write Python scripts to integrate SAST, DAST, and SCA gates into CI/CD pipelines, tune scanning tools to reduce false positives, and provide code-level remediation guidance to Java and Python development teams. The role requires 3–5 years of combined software engineering and AppSec experience.

WHAT YOU WILL DO
- Write and maintain the scripts necessary to integrate security gates (SAST, DAST, SCA) seamlessly into the CI/CD pipeline;
- Continuously tune and configure existing security scanning tools to eliminate false positives and deliver high-confidence alerts;
- Assist in coding and deploying automated hardened baselines and secure coding patterns;
- Work directly with product development teams to provide actionable, code-level remediation guidance in Java and Python.

MUST HAVES
- 3–5 years of commercial experience blending software engineering and DevSecOps/AppSec;
- Solid coding proficiency in Python for automation and scripting;
- Working knowledge of modern CI/CD orchestration tools and practical experience interacting with vulnerability scoring frameworks;
- Ability to operate with minimal supervision on day-to-day execution, reliably completing complex scripting and integration tasks;
- Upper-intermediate English level.

NICE TO HAVES
- Ability to comfortably read and navigate Java source code;
- Hands-on experience with specific CNAPP or ASPM platforms (e.g., Wiz);
- Basic understanding of application threat modeling.

PERKS AND BENEFITS
- Professional growth: Mentorship, TechTalks, and personalized growth roadmaps.
- Competitive compensation: USD-based pay with education, fitness, and team activity budgets.
- Exciting projects: Modern solutions with Fortune 500 and top product companies.
- Flextime: Flexible schedule with remote and office options.

Meet Our Recruitment Process
Application → Coding Challenge → Video Interview → Technical Interview or Hiring Manager Interview
Each step helps us understand your skills and overall fit.
If it’s a match, you’ll receive an offer.

Similar jobs

Application Security Engineer roles near Bucharest, Bucharest
2w
Save
Mark Applied
Hide
Senior Application Security Engineer
Bucharest or Cluj-Napoca or Sibiu or Targu Mures or Timisoara
OnsiteFull Time
Infosys
InfosysNYSE: INFY: Provides IT consulting, software development, and business outsourcing services.
10+ YOE10+ years application security experience with SAST/DAST/SCA, penetration and API testing, vulnerability management, secure SDLC advisory, and strong communication skills.
SAST, DAST, SCA, Burp Suite, HCL AppScan, Sonatype Nexus IQ/Lifecycle, Fortify, SonarQube, Black Duck, Azure, Azure DevOps, ServiceNow, Power BI, OWASP Top 10, MITRE ATT&CK
1mo
Save
Mark Applied
Hide
Application Security Engineer (relocation to Barcelona)
Bucharest or Barcelona or New York City or Israel or Ukraine
HybridFull Time
Commit
Commit: End-to-end software, cloud, and cybersecurity consulting and development.
4+ YOEMinimum 4 years in research/penetration testing; strong coding skills; experience with web, API, cloud-native, containers, Kubernetes; familiarity with SSDLC and CI/CD; experience with Burp Suite, Metasploit, fuzzing, and automated testing pipelines; LLM/AI penetration testing knowledge.
Burp Suite, Metasploit, Kubernetes, CI/CD pipelines, Secure Software Development Lifecycle (SSDLC), LLM