# Application Security Engineer

[Tripleten](https://gurify.com/jobs?q=Tripleten) · Lisbon, Portugal · Posted yesterday

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://www.comeet.com/jobs/tripleten/98.008/application-security-engineer/62.378-DA.406)

## Job description

Nebius Academy (powered by TripleTen) provides assessments and training for tech companies and aspiring professionals worldwide, helping companies & individuals transform their lives through career development and acquiring the new skills needed as a tech professional.

Our focus on data science, machine learning, and generative AI helps tech-forward companies level up their employees' skills and drive innovation.

We are looking for an Application Security Engineer to own product security end to end — from threat modelling and secure design reviews to vulnerability management and security controls embedded into CI/CD.

You will work closely with product and platform teams to make security part of the engineering process, building secure defaults and helping prevent vulnerabilities from reaching production without slowing development down.

### What you will do

- Own application and product security end to end, from design reviews and threat modelling to vulnerability remediation and follow-up.

- Partner with product and platform teams to embed security into the development lifecycle rather than treat it as a final review step.

- Build and improve security controls in CI/CD, including SAST, dependency, secrets, container, and IaC scanning.

- Review application designs and code where security risk is meaningful, and turn recurring findings into secure defaults, shared libraries, lint rules, and CI gates.

- Drive vulnerability management across application code and cloud posture, including triage, risk-based prioritisation, remediation timelines, and external pentest findings.

- Strengthen security in multitenant B2B systems, including tenant isolation, authentication, authorization, RBAC / ABAC, and access controls.

- Work on cloud and Kubernetes security across AWS environments, including IAM, secrets management, network boundaries, and workload hardening.

- Help translate GDPR, SOC 2, and ISO 27001 requirements into practical engineering controls and system properties.

- Develop and support a security champions programme to help engineering teams adopt secure practices in their day-to-day work.

- Address security risks specific to AI and LLM-powered features, including prompt injection, data leakage, and untrusted model output.

### Requirements

- 5+ years of engineering experience, including at least 2 years focused on Application Security or Product Security.

- Strong software engineering background with the ability to read, review, and write production code; Python experience is highly preferred.

- Deep practical knowledge of web application security, including OWASP Top 10, ASVS, authentication and session management, OAuth2 / OIDC / SAML, and authorization issues such as IDOR and broken access control.

- Experience securing multitenant or B2B SaaS products, including tenant isolation, RBAC / ABAC, and access control models.

- Hands-on experience embedding security into CI/CD, including SAST, SCA, secrets scanning, container scanning, and IaC scanning.

- Strong experience with threat modelling, secure design reviews, and secure code reviews in collaboration with product and engineering teams.

- Experience managing vulnerabilities based on risk, criticality, and exploitability, including remediation prioritisation and escalation when needed.

- Working knowledge of AWS and Kubernetes security, including IAM, secrets management, network boundaries, and workload hardening.

- Strong communication skills and the ability to explain security risks clearly to engineers, product managers, and auditors.

- Fluent Russian and English at B2 level or above.

### Nice to have:

- Experience building a DevSecOps practice from scratch.

- Experience running or participating in a Security Champions programme.

- Hands-on penetration testing experience.

- Experience securing LLM-powered or AI products.

- Experience with SOC 2 or ISO 27001 from an engineering perspective.

- Knowledge of software supply chain security, including SBOMs, SLSA, image signing, or similar practices.

### What we can offer you

- A supportive and proactive work environment.

- Competitive compensation: 4000-6000 EUR Gross per month

- Fully remote and full-time collaboration.

- Modern digital tools for seamless collaboration.

- Tangible results measured by student success.

**Live in Tripleten’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- JG [Application Security (AppSec) Engineer](https://gurify.com/job/application-security-appsec-engineer-at-joom-group-8fc35aa2afbe) Joom Group · Lisbon, Portugal · 4 weeks ago
- VE [Technical Program Manager, Application Security](https://gurify.com/job/technical-program-manager-application-security-at-veeamsoftware-34c12e4669e5) Veeamsoftware · Lisbon, Portugal · 5 days ago
- WR [Security engineer, application security (UK)](https://gurify.com/job/security-engineer-application-security-uk-at-writer-5099130c9e15) Writer · London, United Kingdom · last week
- TM [Application Security Engineer](https://gurify.com/job/application-security-engineer-at-thought-machine-53bc5ae8697e) Thought Machine · Portugal, Lisbon · 5 days ago
- AW [Application Security Engineer (f/m/d)](https://gurify.com/job/application-security-engineer-f-m-d-at-awin-fb24719a88c0) Awin · Berlin, Poland · 3 weeks ago
- ON [Application Security Engineer - ONE ZERO](https://gurify.com/job/application-security-engineer-one-zero-at-onezerobank-2e8386af9bda) Onezerobank · Tel Aviv-Yafo, Israel · 3 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Application Security Engineer","description":"\u003Cp\u003ENebius Academy (powered by TripleTen) provides assessments and training for tech companies and aspiring professionals worldwide, helping companies \u0026amp; individuals transform their lives through career development and acquiring the new skills needed as a tech professional.\u003C/p\u003E\u003Cp\u003EOur focus on data science, machine learning, and generative AI helps tech-forward companies level up their employees\u0026#39; skills and drive innovation.\u003C/p\u003E\u003Cp\u003EWe are looking for an Application Security Engineer to own product security end to end \u2014 from threat modelling and secure design reviews to vulnerability management and security controls embedded into CI/CD.\u003C/p\u003E\u003Cp\u003EYou will work closely with product and platform teams to make security part of the engineering process, building secure defaults and helping prevent vulnerabilities from reaching production without slowing development down.\u003C/p\u003E\u003Ch3\u003EWhat you will do\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EOwn application and product security end to end, from design reviews and threat modelling to vulnerability remediation and follow-up.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with product and platform teams to embed security into the development lifecycle rather than treat it as a final review step.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild and improve security controls in CI/CD, including SAST, dependency, secrets, container, and IaC scanning.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EReview application designs and code where security risk is meaningful, and turn recurring findings into secure defaults, shared libraries, lint rules, and CI gates.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDrive vulnerability management across application code and cloud posture, including triage, risk-based prioritisation, remediation timelines, and external pentest findings.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrengthen security in multitenant B2B systems, including tenant isolation, authentication, authorization, RBAC / ABAC, and access controls.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWork on cloud and Kubernetes security across AWS environments, including IAM, secrets management, network boundaries, and workload hardening.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHelp translate GDPR, SOC 2, and ISO 27001 requirements into practical engineering controls and system properties.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDevelop and support a security champions programme to help engineering teams adopt secure practices in their day-to-day work.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAddress security risks specific to AI and LLM-powered features, including prompt injection, data leakage, and untrusted model output.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ERequirements\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E5\u002B years of engineering experience, including at least 2 years focused on Application Security or Product Security.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong software engineering background with the ability to read, review, and write production code; Python experience is highly preferred.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDeep practical knowledge of web application security, including OWASP Top 10, ASVS, authentication and session management, OAuth2 / OIDC / SAML, and authorization issues such as IDOR and broken access control.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience securing multitenant or B2B SaaS products, including tenant isolation, RBAC / ABAC, and access control models.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands-on experience embedding security into CI/CD, including SAST, SCA, secrets scanning, container scanning, and IaC scanning.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong experience with threat modelling, secure design reviews, and secure code reviews in collaboration with product and engineering teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience managing vulnerabilities based on risk, criticality, and exploitability, including remediation prioritisation and escalation when needed.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWorking knowledge of AWS and Kubernetes security, including IAM, secrets management, network boundaries, and workload hardening.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong communication skills and the ability to explain security risks clearly to engineers, product managers, and auditors.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFluent Russian and English at B2 level or above.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENice to have:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience building a DevSecOps practice from scratch.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience running or participating in a Security Champions programme.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands-on penetration testing experience.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience securing LLM-powered or AI products.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with SOC 2 or ISO 27001 from an engineering perspective.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EKnowledge of software supply chain security, including SBOMs, SLSA, image signing, or similar practices.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhat we can offer you\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EA supportive and proactive work environment.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECompetitive compensation: 4000-6000 EUR Gross per month\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFully remote and full-time collaboration.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EModern digital tools for seamless collaboration.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETangible results measured by student success.\u003C/li\u003E\u003C/ul\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"application-security-engineer-at-tripleten-18e847d1f8e7"},"url":"https://gurify.com/job/application-security-engineer-at-tripleten-18e847d1f8e7","datePosted":"2026-09-28","validThrough":"2026-11-13T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Tripleten","sameAs":"https://www.comeet.com/jobs/tripleten"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"PT","addressLocality":"Lisbon"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Portugal","item":"https://gurify.com/jobs/portugal"},{"@type":"ListItem","position":3,"name":"Application Security Engineer","item":"https://gurify.com/job/application-security-engineer-at-tripleten-18e847d1f8e7"}]}
```
