Junior Application & Product Security Engineer
(based in Europe)
Assignment description
As a Junior Application & Product Security Engineer at our client, you will work closely with their CISO, Senior Security Engineer, and engineering teams to support the secure development side of their platform. You will play a vital, hands-on role in securing the application code, repositories, and dependencies. You will take direct ownership of the application-level vulnerability backlog across our GitHub repositories, ensuring code fixes are triaged, released, and compliant with SOC 2 SLA targets. By pairing a passion for security with an eagerness to learn, you will help triage findings, maintain CI/CD security gates, and empower our developers to safely leverage AI-assisted coding tools.
What you will do:
– Actively track, prioritize, and remediate application and dependency vulnerabilities (Dependabot, Aikido) across ~184 active GitHub repositories to hit strict SOC 2 SLA targets.
– Assist development teams with code-level security updates across npm, pnpm, Go, Ruby, Python, Dockerfiles, and GitHub Actions.
– Help investigate and resolve breaking dependency upgrades, CI failures, and build issues caused by security updates.
– Track merged security fixes through the release lifecycle to ensure they are successfully deployed and validated in production.
– Contribute to improving repository-level security workflows, automated scanning, and CI/CD security gates.
– Learn, help define, and monitor security guardrails for the safe use of AI-assisted development tools in product engineering.
– Collaborate closely with our Senior Cloud & Infrastructure Security Engineer to escalate complex code or architectural risks while continuously growing your technical security expertise.
About the team
You will work closely with the CISO and be part of a small, two-person team.
Must haves
– Foundational knowledge of application security concepts, secure coding practices, and common vulnerabilities (OWASP Top 10).
– Familiarity with at least one programming language (such as Python, Go, Ruby, or JavaScript/TypeScript) and a hands-on drive to test PRs, update libraries, and fix build breakages.
– Basic understanding of version control (GitHub), repository management, and CI/CD pipelines.
– A proactive, problem-solving mindset with a genuine enthusiasm for clearing security technical debt and learning modern AppSec practices.
– Interest in AI-assisted development and a basic awareness of AI-related code security risks (e.g., hallucinated packages, unsafe generated patterns).
– Confident, clear communication skills to collaborate effectively across development teams and foster a culture of shared security ownership.
– Professional English, both verbal and written.
Other requirements
– Personal projects, coursework, or internships involving security tooling, dependency management, or secure software development lifecycles (SDLC).
About the customer
Our client is a fast-growing technology company exploring how far we can take innovation to deliver the world’s best Unified Commerce Platform and Point of Sale. Our technology is used in more than 20 countries – a number that keeps growing thanks to our incredible team of developers. And we have no intention of slowing down.
Industries
Retail





