- Company: Get A Job.ai
- Location: Remote job
- Salary: Pay not listed
- Work type: Remote
Website Get A Job.ai
Represented by Get A Job.ai
About This Opportunity
We are representing a fast-growing global travel technology company in their search for a Senior Application Security Engineer. This is a rare greenfield opportunity to build an application security practice from the ground up within an organization that operates a high-volume B2B marketplace connecting transportation providers across 70+ countries with major online retailers.
As their first dedicated AppSec hire, you will own secure development practices for approximately 150 engineers, working with real production attack surfaces including public partner-facing APIs, payment workflows, and active bug bounty programs. You will see the impact of your work in production within weeks.
This is a fully remote position with an international team, though the company maintains headquarters in Berlin for those who wish to collaborate in person.
Responsibilities
- Lead threat modeling and secure design reviews for high-risk code changes, partner integrations, and payment processing flows
- Implement, tune, and enforce security gates within CI/CD pipelines (SAST, SCA, secrets scanning, DAST) while minimizing developer friction
- Serve as primary technical owner for triaging, reproducing, and prioritizing findings from bug bounties, partner penetration tests, and automated security scanners
- Collaborate hands-on with DevOps to implement cloud organizational policies, IAM least-privilege architectures, and WAF/rate-limiting configurations
- Establish a security champions network across engineering squads and leverage automation and AI-assisted tooling to scale code review capabilities
- Build the "paved road" for secure development that enables engineers to ship safely at velocity
What We're Looking For
- 5+ years in Application Security (or 3+ years with a strong software engineering or web penetration testing background), demonstrating true ownership of security outcomes
- Ability to read and write production code in languages such as Python, Go, TypeScript, or Ruby; deep understanding of web frameworks, CI/CD systems, and Kubernetes
- Deep expertise in web and API security, including authentication/authorization models (OAuth2, JWT), rate limiting, tenant isolation, IDOR, and XSS vulnerabilities
- Strong cloud security fundamentals (GCP preferred), particularly around public exposure risks, secrets hygiene, and WAF rule configuration
- Risk-based prioritization skills: you propose pragmatic trade-offs rather than demanding perfection, and communicate complex security risks clearly to both engineers and leadership
- Bonus: Experience securing high-volume, multi-tenant B2B APIs and utilizing AI tooling to accelerate security triage and code review
How We Work With You
When you apply through Get A Job.ai, our recruiting team will review your profile and conduct an initial screening call to understand your background and goals. If there is a strong match, we will submit your candidacy to our client for consideration. Please apply exclusively through our platform—direct contact with the employer may disqualify your application.
Our talent team will guide you through each stage of the interview process and provide feedback and coaching along the way.
Pay
Compensation details will be discussed during the screening process and are competitive within the European travel technology market.
Equal Opportunity: Get A Job.ai is committed to inclusive hiring practices. We welcome applicants of all backgrounds and work with clients who share our commitment to building diverse teams.
Apply with Get A Job.ai
A recruiter will review your profile and submit you to the client. Do not contact the client directly.
Apply through Get A Job.ai. A recruiter will review your profile and submit you. Do not contact the client directly.
Apply through Get A Job.ai. A recruiter will review your profile and submit you.
Explore Get A Job.ai online
Working in Remote job
Job details above are provided by the employer/source. The sections on this page are compiled from public data sources with AI assistance.
Accommodations: if you need a workplace accommodation to apply for or perform this job, see ADA.gov or EEOC.gov for guidance on your rights and how to request one.
Listing facts
- Role Senior Application Security Engineer (all genders)
- Employer Get A Job.ai
- Location Remote job · Remote-friendly
- Type Full Time
- Pay (from listing) Pay not listed
- Posted September 7, 2026
- Apply by October 7, 2026
- Overview Full job description on this page (497 words)
Facts above come from this job record on Get A Job.AI — not copied from third-party review sites.
Limited public data for this employer
We only show facts we can ground in public sources (Wikidata, O*NET, news/discussion links, or this listing). We do not invent Glassdoor-style ratings, salaries, or testimonials when data is thin. Use the listing facts, occupation context, and related openings below while we continue researching.
Explore related openings
Occupation family: Application Security Engineer
Keep exploring on Get A Job.ai
Not quite the right fit? Your next opportunity is a click away.
- Browse all jobs
- More jobs by category
- Remote jobs you can do from anywhere
- Research typical pay for this role
- Set a job alert so new matches reach you first
- Upload your resume to apply faster
Hiring instead? Post a job and reach candidates searching right now.
