Tech Job Finder - Find Software, Tech Sales and Product Manager Jobs.
Sign In
OR continue with e-mail and password
E-mail address
Password
Don't have an account?
Reset password
Join Tech Job Finder
OR continue with e-mail and password
Username
E-mail address
Password
Confirm Password
How did you hear about us?
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Application Security Engineer

at Contentsquare

Back to all Cybersecurity jobs
Contentsquare logo
Industry not specified

Application Security Engineer

at Contentsquare

Mid LevelNo visa sponsorshipCybersecurity

Posted 19 hours ago

No clicks

Compensation
Not specified

Currency: Not specified

City
Not specified
Country
Spain

**Application Security Engineer** in Barcelona. Configure and maintain secure app environments. Apply threat modeling, secure coding, and OWASP standards. Use tools like OWASP ZAP, Burp Suite, and static application security testing (SAST). Bring 3+ years' experience, BSc in Cyber Security or related field. Join global leader in experience analytics, Contentsquare.

Department: Security Trust

Team: Corporate Security

Location: Barcelona

Type: Full-time

Contentsquare is the all-in-one experience intelligence platform designed to be easily used by anyone who cares about digital journeys. With our flexible and scalable platform, organizations quickly get a deep understanding of their customers’ whole online journey.
 
We are a global leader in the experience analytics space, with a growing presence across 15 offices worldwide. We’re here to stay—and we’re looking for team members who are excited to drive impact and help us scale even further.
 
Our aim is to create an inclusive workplace where everyone learns and succeeds. Contentsquare has built a community of individuals who are daring, understanding, and deliberate. We invite you to join us in making the complex simpler—for our customers, their customers, and each other.
 
Important note: Be careful of scammers pretending to be from Contentsquare. We will never ask for money or contact you through random texts. Any communication from our in house Talent Acquisition team will only ever come from our contentsquare.com or @contentsquare-ext.com domain. For more information, visit our careers blog.

The Contentsquare Security team is looking for an Application Security Engineer to join the offensive security / Red Team side of our Security organization. Your mission will be to continuously challenge the security of Contentsquare’s products, thinking and acting like an attacker to identify and exploit vulnerabilities across our web applications, APIs and cloud-native services.

Beyond finding vulnerabilities, you’ll work closely with Engineering teams, Product Managers and other security stakeholders, including bug bounty hunters, to turn offensive findings into actionable remediation and stronger secure coding practices, helping us make our products harder to break.

Contentsquare provides a globally leading SaaS service and commits to the highest security standards for its customers. We are ISO 27001 and ISO 27701 certified and maintain robust security initiatives (SOC 2 Type 2 report, private bug bounty program, SIEM, advanced security awareness, etc.). Working alongside other cybersecurity experts, your mission will be to ensure the security of Contentsquare’s products and keep Contentsquare’s users and customers safe. You will work out of our Barcelona office.

What you'll do

  • Conduct continuous, automated security audits of our global SaaS applications to identify misconfigurations and ensure strict adherence to industry-standard security benchmarks and internal best practices.

  • Serve as a strategic security consultant to product and engineering teams, facilitating complex threat modeling sessions and AppSec reviews during the design phase to proactively mitigate risks.

  • Perform deep-dive, security-focused code reviews and mentor developers on secure coding patterns to minimize the introduction of high-impact vulnerabilities.

  • Architect and manage the end-to-end vulnerability lifecycle, developing sophisticated automation for the triage, reporting, and remediation tracking of security flaws across cloud infrastructure and application layers.

  • Orchestrate and optimize AI-driven security workflows, leveraging LLMs and autonomous agents to conduct scaleable, proactive vulnerability discovery and validation within our CI/CD pipelines.

  • Lead "Shift-Left" initiatives by integrating security checkpoints into the automation stack, developing custom security-as-code tools that empower developers to own security outcomes.

  • Oversee the strategic direction of our private and public bug-bounty programs, ensuring high-quality engagement with the researcher community and rapid internal response to critical findings.

  • Coordinate specialized external penetration testing engagements and customer-driven security assessments, acting as the primary technical point of contact for complex security inquiries.

  • Drive the technical response to application-level security incidents, conducting root-cause analysis to prevent recurrence and enhance our defensive posture.

  • What you'll need

  • 3+ years of professional experience in Application Security Operations within a high-growth SaaS or cloud-native environment.

  • Advanced proficiency in securing modern technical stacks, with specific expertise in NestJS, Vue.js, and Angular frameworks.

  • Hands-on experience with enterprise security tooling, including Snyk, Datadog ASM/AppSec (WAF), Google SecOps, and Crowdstrike.

  • Deep architectural understanding of AWS and Azure environments, including Kubernetes/Docker container security and Infrastructure as Code (Terraform).

  • Demonstrated ability to apply AI and LLM technologies to automate security tasks, such as automated vulnerability validation or code analysis at scale.

  • Expertise in scripting and development (Python, Node.js, Shell) to build custom security tooling and integrations.

  • Comprehensive knowledge of web protocols, OWASP Top 10, and advanced threat frameworks (MITRE ATT&CK, NIST CSF).

  • Proven track record in ethical hacking, CTF competitions, or bug bounty hunting, showcasing a high level of technical tenacity and analytical rigor.

  • Exceptional cross-functional collaboration skills, with the ability to articulate complex security risks to both technical and non-technical stakeholders.

  • Fluency in English is mandatory

  • Why you should join Contentsquare
    We invest in our people through career development, mentorship, social events, philanthropic activities, and competitive benefits. We are always assessing the perks we offer to ensure we’re aligned with the employees' needs.
     
    Here are a few we want to highlight:
    - Virtual onboarding, Hackathon, and various opportunities to interact with your team and global colleagues both on and offsite each year
    - Work flexibility: hybrid and remote work policies
    - Generous paid time-off policy (every location is different)
    - Lifestyle allowance
    - A Culture Crew in every country we’re based in to coordinate regular activities for employees to get to know each other and bond outside of work
    - Every full-time employee receives stock options, allowing them to share in the company’s success
    - We have multiple Employee Resource Groups, that offer a safe space for individuals who share common identities, life experiences, or allyship to connect, support one another, and passionately advocate for the issues close to their hearts
    - And more benefits tailored to each country
     
    Contentsquare is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to sex, gender identity or expression, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.
     
    Your personal data is used by Contentsquare for recruitment purposes only. Read our Job Candidate Privacy Notice to find out more about data protection at Contentsquare and your rights. You can exercise your rights by using our dedicated Data Subject Rights Portal here
     
    Your personal data will be securely stored in our hosting provider’s data center in Oregon (US west). We have implemented appropriate transfer mechanisms under applicable data protection laws.
     
    Contentsquare may use AI-assisted tools to help review and screen applications. All decisions involving hiring are made by human reviewers, and your personal data will be processed in accordance with our Candidate Privacy Policy.

    Application Security Engineer

    at Contentsquare

    Back to all Cybersecurity jobs
    Contentsquare logo
    Industry not specified

    Application Security Engineer

    at Contentsquare

    Mid LevelNo visa sponsorshipCybersecurity

    Posted 19 hours ago

    No clicks

    Compensation
    Not specified

    Currency: Not specified

    City
    Not specified
    Country
    Spain

    **Application Security Engineer** in Barcelona. Configure and maintain secure app environments. Apply threat modeling, secure coding, and OWASP standards. Use tools like OWASP ZAP, Burp Suite, and static application security testing (SAST). Bring 3+ years' experience, BSc in Cyber Security or related field. Join global leader in experience analytics, Contentsquare.

    Department: Security Trust

    Team: Corporate Security

    Location: Barcelona

    Type: Full-time

    Contentsquare is the all-in-one experience intelligence platform designed to be easily used by anyone who cares about digital journeys. With our flexible and scalable platform, organizations quickly get a deep understanding of their customers’ whole online journey.
     
    We are a global leader in the experience analytics space, with a growing presence across 15 offices worldwide. We’re here to stay—and we’re looking for team members who are excited to drive impact and help us scale even further.
     
    Our aim is to create an inclusive workplace where everyone learns and succeeds. Contentsquare has built a community of individuals who are daring, understanding, and deliberate. We invite you to join us in making the complex simpler—for our customers, their customers, and each other.
     
    Important note: Be careful of scammers pretending to be from Contentsquare. We will never ask for money or contact you through random texts. Any communication from our in house Talent Acquisition team will only ever come from our contentsquare.com or @contentsquare-ext.com domain. For more information, visit our careers blog.

    The Contentsquare Security team is looking for an Application Security Engineer to join the offensive security / Red Team side of our Security organization. Your mission will be to continuously challenge the security of Contentsquare’s products, thinking and acting like an attacker to identify and exploit vulnerabilities across our web applications, APIs and cloud-native services.

    Beyond finding vulnerabilities, you’ll work closely with Engineering teams, Product Managers and other security stakeholders, including bug bounty hunters, to turn offensive findings into actionable remediation and stronger secure coding practices, helping us make our products harder to break.

    Contentsquare provides a globally leading SaaS service and commits to the highest security standards for its customers. We are ISO 27001 and ISO 27701 certified and maintain robust security initiatives (SOC 2 Type 2 report, private bug bounty program, SIEM, advanced security awareness, etc.). Working alongside other cybersecurity experts, your mission will be to ensure the security of Contentsquare’s products and keep Contentsquare’s users and customers safe. You will work out of our Barcelona office.

    What you'll do

  • Conduct continuous, automated security audits of our global SaaS applications to identify misconfigurations and ensure strict adherence to industry-standard security benchmarks and internal best practices.

  • Serve as a strategic security consultant to product and engineering teams, facilitating complex threat modeling sessions and AppSec reviews during the design phase to proactively mitigate risks.

  • Perform deep-dive, security-focused code reviews and mentor developers on secure coding patterns to minimize the introduction of high-impact vulnerabilities.

  • Architect and manage the end-to-end vulnerability lifecycle, developing sophisticated automation for the triage, reporting, and remediation tracking of security flaws across cloud infrastructure and application layers.

  • Orchestrate and optimize AI-driven security workflows, leveraging LLMs and autonomous agents to conduct scaleable, proactive vulnerability discovery and validation within our CI/CD pipelines.

  • Lead "Shift-Left" initiatives by integrating security checkpoints into the automation stack, developing custom security-as-code tools that empower developers to own security outcomes.

  • Oversee the strategic direction of our private and public bug-bounty programs, ensuring high-quality engagement with the researcher community and rapid internal response to critical findings.

  • Coordinate specialized external penetration testing engagements and customer-driven security assessments, acting as the primary technical point of contact for complex security inquiries.

  • Drive the technical response to application-level security incidents, conducting root-cause analysis to prevent recurrence and enhance our defensive posture.

  • What you'll need

  • 3+ years of professional experience in Application Security Operations within a high-growth SaaS or cloud-native environment.

  • Advanced proficiency in securing modern technical stacks, with specific expertise in NestJS, Vue.js, and Angular frameworks.

  • Hands-on experience with enterprise security tooling, including Snyk, Datadog ASM/AppSec (WAF), Google SecOps, and Crowdstrike.

  • Deep architectural understanding of AWS and Azure environments, including Kubernetes/Docker container security and Infrastructure as Code (Terraform).

  • Demonstrated ability to apply AI and LLM technologies to automate security tasks, such as automated vulnerability validation or code analysis at scale.

  • Expertise in scripting and development (Python, Node.js, Shell) to build custom security tooling and integrations.

  • Comprehensive knowledge of web protocols, OWASP Top 10, and advanced threat frameworks (MITRE ATT&CK, NIST CSF).

  • Proven track record in ethical hacking, CTF competitions, or bug bounty hunting, showcasing a high level of technical tenacity and analytical rigor.

  • Exceptional cross-functional collaboration skills, with the ability to articulate complex security risks to both technical and non-technical stakeholders.

  • Fluency in English is mandatory

  • Why you should join Contentsquare
    We invest in our people through career development, mentorship, social events, philanthropic activities, and competitive benefits. We are always assessing the perks we offer to ensure we’re aligned with the employees' needs.
     
    Here are a few we want to highlight:
    - Virtual onboarding, Hackathon, and various opportunities to interact with your team and global colleagues both on and offsite each year
    - Work flexibility: hybrid and remote work policies
    - Generous paid time-off policy (every location is different)
    - Lifestyle allowance
    - A Culture Crew in every country we’re based in to coordinate regular activities for employees to get to know each other and bond outside of work
    - Every full-time employee receives stock options, allowing them to share in the company’s success
    - We have multiple Employee Resource Groups, that offer a safe space for individuals who share common identities, life experiences, or allyship to connect, support one another, and passionately advocate for the issues close to their hearts
    - And more benefits tailored to each country
     
    Contentsquare is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to sex, gender identity or expression, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.
     
    Your personal data is used by Contentsquare for recruitment purposes only. Read our Job Candidate Privacy Notice to find out more about data protection at Contentsquare and your rights. You can exercise your rights by using our dedicated Data Subject Rights Portal here
     
    Your personal data will be securely stored in our hosting provider’s data center in Oregon (US west). We have implemented appropriate transfer mechanisms under applicable data protection laws.
     
    Contentsquare may use AI-assisted tools to help review and screen applications. All decisions involving hiring are made by human reviewers, and your personal data will be processed in accordance with our Candidate Privacy Policy.

    SIMILAR OPPORTUNITIES

    No similar jobs available at the moment.