About the role:
As an AppSec Engineer you will play a crucial role in ensuring the security of our software practices. Working closely with development and engineering teams you will be responsible for implementing and maintaining secure development practices reviewing security vulnerabilities and enhancing our security posture across the organization. Your goal will be to help developers understand and integrate security concepts while fostering a culture of security within the company. You will also contribute to automation tooling and security guidance to mitigate risks and improve our security processes.
What would you do at Fever
On your first month in Fever:
- You will be fully integrated into the team. You will participate in planning and followup meetings with other areas.
- You will have met the departments of Fever.
- You will get familiar with Fevers technological structure and ecosystem (applications infrastructure architecture etc.)
- You will gain an understanding of our security processes tools and overall security landscape.
After 3 months in Fever:
- You will collaborate with developers to provide security guidance and best practices.
- You will assist in triaging and analyzing vulnerabilities from static and dynamic application security testing (SAST/DAST) tools.
- You will start contributing to security automation in CI/CD pipelines.
- You will contribute to the evaluation and selection of new security tools and processes.
On your 6th month in Fever:
- You will design and define requirements for change management in development processes.
- You will perform threat modeling to assess and mitigate potential security risks.
- You will implement and refine SDLC methodology for secure software development.
- You will take ownership of security automation and SSDLC initiatives within the company..
Key responsibilities
- Execute the SSDLC strategy across the organization.
- Maintain and optimize SSDLC tools ensuring highquality vulnerability detection.
- Implement and automate security controls in CI/CD pipelines (Jenkins GitHub Actions etc.).
- Support teams in identifying and resolving software security vulnerabilities.
- Conduct security code reviews and design assessments.
- Develop security tools libraries and automation mechanisms.
- Perform proactive research on emerging security threats and trends.
- Educate engineers on security best practices through training and documentation.
About you
Must have:
- Strong knowledge of secure development workflows and CI/CD tools (Jenkins GitHub Actions etc).
- Proven experience with SSDLC tooling and understanding of microservices architecture APIs and secure development practices.
- Proficiency in programming languages (Python JavaScript etc).
- Familiarity with security frameworks and standards (OWASP NIST etc).
- Experience with application security concepts such as threat modeling risk assessments and secure coding practices.
- Strong problemsolving skills and ability to manage multiple tasks effectively.
- 4 years of experience in software development or security engineering.
- Bachelor or Masters Degree in Computer Science Information Security or another similar relevant degree (or equivalent experience in a technical security role).
- Fluent in English.
- Good communication skills.
It would be a plus if you have:
- Security certifications such as CISSP CSSLP or equivalent.
- Experience contributing to opensource security projects.
- Handson experience with penetration testing or bug bounties.
Benefits & Perks
- Opportunity to have a real impact in a highgrowth global category leader
- 40% discount on all Fever events and experiences
- Position based in Madrid home office friendly.
- Relocation package for international candidates
- Responsibility from day one and professional and personal growth
- Great work environment with a young international team of talented people to work with!
- Health insurance and other benefits such as Flexible remuneration with a 100% tax exemption through Cobee.
- English Lessons
- Gympass Membership
- Possibility to receive in advance part of your salary by Payflow.
- Attractive compensation package consisting of base salary and the potential to earn a significant bonus for top performance.