Application Security Engineer (m/f/d)

Posted 2025-08-23
Remote, USA Full Time Immediate Start
<p><strong><span>Are you ready to be a security leader in the SaaS space? Join epilot!</span></strong></p><p><br>We are looking for a security-minded engineer who goes beyond finding vulnerabilities and focuses on building automated, resilient defenses into our AWS-powered products. You will combine technical expertise with a proactive security mindset to protect impactful software from the ground up.</p><p></p><p>epilot is building a SaaS product to sell complex products online, focusing first on solving ecommerce in the rapidly transforming energy market. Our mission: Make selling complex products as easy as selling a pair of shoes online.</p><p></p><p>As the <strong>Application Security Engineer</strong> at epilot you will be a driving force in ensuring our products are secure by design. What makes working in engineering at epilot so special? Our unique culture is defined by a few core principles that apply to all our engineers.<br><br></p><p>Among others, you can expect <strong>freedom and responsibility</strong> because we hire smart people we can trust. We operate by principles and expect everyone to cultivate a strategic mindset.<br><br></p><p>We believe in <strong>ownership: you secure it, you run it</strong>. You will work closely with development teams to integrate security into every stage of the lifecycle. There is no separate security silo to hand things off to, you’ll design, implement, and automate defenses that keep our AWS-powered products safe and scalable. This includes integrating vulnerability testing tools, supporting incident response, and participating in bug bounty triage.<br><br><br>You should always <strong>show, don’t tell</strong>: Deliver secure, working software early and frequently. We believe in the Agile principle of “Release early and release often,” with the added goal of ensuring security from the first release onward. Fast feedback loops between ourselves, our users, and our security systems help us manage risk and make better decisions.</p><p></p><p>Does this sound like an environment you want to work in? Then you could bet the right person to be an engineer at epilot!</p><p></p><p>Check out our promise to you: <a href="http://www.promise.epilot.cloud/"><span>promise.epilot.cloud</span></a></p><p><br>We "epilots" are a team of experts from the fields of software development, energy management, product management and sales. In order to bring our solution even faster and more secured to the top in the energy world, we are looking for you as a <strong> Security Engineer</strong> </p><br><p><strong>What awaits you</strong><br>As an Application Security Engineer at epilot, you’ll play a key role in building secure-by-default features and hardening the backbone of our cloud-native platform. You’ll work closely with engineers across the stack to shift security left and help us scale securely as we grow.<br>Here’s what you’ll do:<br></p><ul><li><p>Embed security into our development lifecycle by integrating SAST, DAST, and dependency scanning tools into CI/CD pipelines</p></li><li><p>Collaborate with engineering teams to identify vulnerabilities early and support remediation with actionable guidance</p></li><li><p>Build and maintain automation for security testing and compliance reporting</p></li><li><p>Work hands-on with AWS services to improve cloud security posture and advise on secure architecture</p></li><li><p>Drive threat modeling, participate in secure code reviews, and support bug bounty triage</p></li><li><p>Educate teams on secure coding practices and OWASP Top 10 risks in web and API development</p></li><li><p>Lead or support incident response efforts and post-incident reviews</p></li><li><p>Develop internal tooling or scripts to simplify and automate security operations<br></p></li></ul><p><strong>What you bring</strong><br>We’re looking for a security-minded engineer who thrives in a fast-paced, product-centric environment and has the following skills and mindset:<br><br><strong>Technical Foundation:</strong></p><ul><li><p>Proficient in any modern programming language (e.g. Python, JavaScript, Go, etc.)</p></li><li><p>Conceptual understanding of OWASP Top 10 for both web and API applications</p></li><li><p>Experience with security tooling: SAST, DAST, AWS security services (GuardDuty, IAM, CloudTrail, etc.)</p></li><li><p>Solid understanding of AWS infrastructure and cloud-native architectures</p></li><li><p>Background in scripting or automating processes in CI/CD environments<br></p></li></ul><p><strong>Bonus Points:</strong></p><ul><li><p>You were a software engineer before switching to security — that mindset is gold</p></li><li><p>Certifications like <strong>OSCP</strong> or <strong>AWS Certified Security – Specialty</strong></p></li><li><p>Familiarity with IaC (Terraform, CloudFormation) and Security-as-Code practices<br></p></li></ul><p><strong>Mindset:</strong></p><ul><li><p>You take ownership of initiatives, see them through to completion, and aren’t afraid to challenge the status quo</p></li><li><p>You’re pragmatic and collaborative — security is a team sport, not a gate</p></li><li><p>You love simplifying complex problems and turning them into scalable, automated solutions</p></li></ul><p></p><p><strong><span>What we offer you</span></strong></p><p>At epilot, we believe in rewarding performance, fostering growth, and creating an environment where you’ll thrive:</p><ul><li><p><strong>Impactful Work</strong>: Be part of a product-driven company that’s reshaping the energy sector.</p></li><li><p><strong>Startup Mentality</strong>: Enjoy a dynamic atmosphere with flat hierarchies and open communication.</p></li><li><p><strong>Flexibility</strong>: Work remotely or from our centrally located office in Cologne, with flexible working hours.</p></li><li><p><strong>Growth Opportunities</strong>: Your career will grow as fast as we do. Learn, experiment, and embrace a “Fail Fast and Often” mentality.</p></li><li><p><strong>Competitive Compensation</strong>: We take your desired salary seriously and value performance.</p></li><li><p><strong>Team Spirit</strong>: Join us for regular events like summer parties, company breakfasts, and our epic annual epilot summit, where you’ll connect with co-epilots worldwide.</p></li><li><p><strong>Transparency and Openness</strong>: Everything is open for discussion in our inclusive and supportive culture.<br></p></li></ul><p>We are looking forward to your application ^^<a href="https://www.kununu.com/de/epilot"><br></a><br></p><p><span><br></span></p>
Back to Job Board