Why This Role Stands Out
This hybrid role offers an exciting opportunity to protect a leading European e-commerce platform, with a competitive salary range of EUR 65,000 - 75,000 and significant potential for skills development in application security and automation. You'll thrive here if you're a proactive mid-senior engineer eager to collaborate with innovative teams and make a real impact on a rapidly growing company. Apply now to join a dynamic environment where your expertise in safeguarding systems will be highly valued.
Quick Overview
Job Description
ABOUT YOU is one of Europe’s fastest growing e-commerce companies. Based in Hamburg and Berlin, we operate at the intersection of fashion and technology. Our mission is to rethink online shopping and make it personal and seamless. This takes more than good ideas. It takes people who take initiative and challenge the status quo. We believe in flat hierarchies, direct communication, and pragmatic decisions. No long approval chains. Just ownership, trust, and clear responsibility. We work hard, but we also believe in enjoying the ride together - over team lunches, afterwork drinks, company events, or a quick coffee in between meetings. If this sounds like you, ABOUT YOU could be the right place to bring in your perspective.
We are looking for an Application Security Engineer (all genders) to join the Application Security circle of our IT-Security unit, dedicated to protecting our online shop, our corporate systems and our customers.
In this role, you will hack internal systems, design and implement security measures to safeguard our infrastructure, applications, and data. You will work closely with other security engineers, developers and IT teams to ensure security best practices, automate security processes, and respond to emerging threats.
Conduct regular penetration tests and code reviews
Advise in the setup and maintenance of applications and infrastructure (usually hosted in AWS/Kubernetes)
Triage and respond to monitoring events
Optimization and automation of security auditing processes. This could also include setting up attack infrastructure, writing scripts in Python and implementing security scanning in Gitlab CI
Take part in some incident response activities within the SOC, which include occasional 24/7 on-call
Application security
Security engineering
Technical Project Management skills
Threat modeling
Penetration testing
Secure code review
Cloud experience: AWS, Bonus: GCP, Azure
Programming experience: Python required, Bonus: PHP, JavaScript, Go
Red teaming is a plus
Nice to have
Certificates:
Offensive Security certificates; e.g. OSCP, OSWP, etc.
Knowledge of Laravel / PHP.
Ability to read and understand JavaScript
Ability to read and understand Go
Experience with incident response activities
Experience with web application firewalls, CDN providers, e.g. Cloudflare, Akamai
Experience with Gitlab CI/CD Pipelines
Your perks at a glance: Visit our benefits page.
Simply apply online via our career page - we will get back to you as soon as possible!
A Place Where You Can Be You
We take it as our responsibility to create an environment where everyone feels welcome, exactly as they are.
Different backgrounds and perspectives make us stronger and shape our culture in ways that matter.
What we stand for internally, we stand for as a brand: acceptance, inclusion, and a fairer approach to fashion.