Application Security Engineer (Berlin/hybrid) at ETERNO | Berlin, DEU | Rezi

Application Security Engineer (Berlin/hybrid) at ETERNO

Application Security Engineer (Berlin/hybrid)

ETERNO · Berlin, DEU

1 months ago

Application Security Engineer (Berlin/hybrid)

ETERNO · Berlin, DEU

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

You are the main AppSec owner inside engineering, working closely with ISMS, Cloud Platform, and Tech Leads to make application security actionable in product development.

Responsibilities

  • Secure development workflows across product engineering, from PR checks to CI/CD security gates
  • SAST, DAST, dependency scanning, and IaC scanning that help teams find issues early
  • Threat modeling, auth/authz reviews, secure API design, and permission model reviews for new and existing features
  • Multi-tenant SaaS isolation, permission models, and healthcare data handling across product workflows
  • Vulnerability management from finding and prioritization to remediation and closure
  • Pentests with external partners, including scope, coordination, findings, remediation, and follow-up
  • Technical security controls and evidence for ISO 27001, GDPR, risk management, and the ISMS
  • Security monitoring and cloud security findings in close collaboration with Cloud Platform and Tech Leads
  • Security guidance that helps teams ship safely without turning security into unnecessary process

Requirements

  • Security that is built into engineering workflows, not added at the end
  • Clear ownership for vulnerabilities, risks, findings, and follow-up work
  • Practical standards that help teams make good security decisions independently
  • Protecting sensitive healthcare data through strong product, platform, and access controls
  • Working closely with ISMS, Cloud Platform, Tech Leads, and product engineering
  • Reducing risk without creating unnecessary friction for teams

Skills

  • Application Security
  • Secure SDLC
  • AWS
  • SAST/DAST
  • Threat Modeling
  • Vulnerability Management
  • ISO 27001
  • GDPR

Location

  • Berlin

Work Type

  • Hybrid

Salary/Compensations

  • Competitive salary

Benefits

  • Company pension with a 20% top-up
  • Monthly budget for benefits like Urban Sports Club, vouchers, or public transport
  • Attractive corporate benefits
  • Refer-a-Friend bonus
  • Access to ETERNO Spaces for quick doctor visits & health check-ups
  • JobRad leasing
  • Language courses in German & English

About the Company

  • We build ETERNO Cloud, the operating system for modern medical practices. It brings the core workflows of a medical practice into one cloud SaaS platform.
  • The product handles sensitive healthcare data in a regulated, GDPR-compliant, and ISO 27001-certified environment, so security needs to be part of how we build, ship, and operate software.
  • Make a real impact – Help us transform healthcare with bold, hands-on solutions for real challenges. Your contribution counts from day one – with responsibility, speed, and room for your own ideas.
  • Join an ambitious team that challenges and supports you. Whether leadership or deep dive: develop both professionally and personally through regular feedback, open exchange, and language courses in German & English.
  • Meet driven, inspiring people. Whether Monthly All-Hands, team offsites, or spontaneous office vibes – we celebrate success together and push each other as a team.

Equal Opportunity

  • At ETERNO, we promote equal opportunities and diversity. We are committed to creating a diverse and inclusive environment for every one of us. We reject any form of discrimination based on ethnicity, skin color, physical or mental disability, religion, marital status, age, national origin, ancestry, health status, pregnancy, gender, sexual orientation, gender identity, or any other personal characteristics.
  • If you require any accommodations during the application process, please contact us in advance at careers@eterno.health. We are happy to support you.