Posted today · be early
Senior Application Security Engineer (all genders)
Distribusion Technologies GmbH
WorldwideremotePosted 1 day ago
Skill Required
Application-Security-EngineerApplication-SecuritySecurity-EngineeringCybersecurityInfosecSenior-Application-Security-EngineerLead-Application-Security-EngineerApplication-Security-LeadApplication-Security-ArchitectSenior-DevSecOps-EngineerSecurity-EngineerSenior-Information-Security-EngineerSenior-Cloud-Security-Software-EngineerSenior-Principal-Security-EngineerSecurity EngineerApplication Developersecuritysoftware engineeringCloud SecurityEngineeringTypeScriptKubernetesautomationGitHub Actionsbuildingetc.)PythondesignDevOpsGitOAuthCI/CDCloudRubyAPIsOWASPGCPIAMJWTandGoFulltime
Key highlights
- Competitive salary
- 5+ years AppSec experience (or 3+ years with strong software engineering/web‑pentesting background)
- Remote‑first flexible work policy
- Build the AppSec practice from the ground up
- Work on public partner‑facing APIs, payment flows, and active bug bounty program
- GCP preferred cloud security expertise
Role overview
Distribusion is the world’s leading ground transportation marketplace, offering seamless access to bus, rail, and ferry services online. Backed by leading venture capital investors and recently funded with $80 M Series C, the Berlin‑based startup is expanding globally. We are looking for our first dedicated Application Security Engineer to build our AppSec practice from the ground up, owning secure development, defining review criteria, implementing security gates, and delivering visible impact within weeks.
Responsibilities
- Lead threat modeling and secure design reviews for high‑risk changes, partner integrations, and payment flows.
- Implement, tune, and enforce security gates in GitLab CI/CD (SAST, SCA, secrets scanning, and DAST) while minimizing developer friction.
- Act as the primary technical owner for triaging, reproducing, and prioritizing findings from bug bounties, partner pentests, and automated scanners.
- Work hands‑on with the DevOps team to implement GCP organizational policies, IAM least‑privilege architectures, and Cloud Armor (WAF/rate limiting).
- Establish a security‑champions network across engineering squads and leverage automation/AI‑assisted tooling to scale code reviews effectively.
Requirements
- 5+ years in Application Security (or 3+ years plus a strong software engineering/web‑pentesting background), with a track record of true ownership.
- Ability to read and write production code (Python, Go, TypeScript, Ruby, etc.) and deep understanding of web frameworks, CI/CD, and Kubernetes.
- Deep knowledge of web and API security, specifically authentication/authorization models (OAuth2, JWT), rate limiting, tenant isolation, IDOR, and XSS.
- Strong cloud security fundamentals (GCP preferred), specifically regarding public exposure, secrets hygiene, and WAF rules.
- Ability to prioritize by real‑world risk, propose trade‑offs rather than demanding perfection, and communicate complex risks plainly to engineers and leadership.
Nice to have
- Experience securing high‑volume, multi‑tenant B2B APIs.
- Utilizing AI tooling to accelerate triage and review.
Benefits
- Competitive salary.
- Remote‑first flexible work policy with international opportunities.
- Flat organizational structure and fast‑paced travel‑tech environment.
- Ownership and responsibility with direct impact on company success.
- International team of talented and driven people with a clear mission.
- Opportunity to work from Berlin HQ or any location worldwide.
Additional details
- Distribusion connects bus, rail and ferry operators in 70+ countries with major online retailers like Google Maps and Booking.com.
- Company headquartered in Berlin, Germany, with teams located around the globe.
- Backed by venture capital investors including TQ Ventures, Lightrock, Creandum, and Northzone.
- Recently completed an $80 M Series C funding round.
- Hiring team: Talent Partner Lorena Rebenciuc and Hiring Manager Ilya Isakov.
- Originally posted on Himalayas.