Junior Application Security Engineer (all genders)
Company Description
ABOUT YOU is one of Europe’s fastest growing e-commerce companies. Based in Hamburg and Berlin, we operate at the intersection of fashion and technology. Our mission is to rethink online shopping and make it personal and seamless. This takes more than good ideas. It takes people who take initiative and challenge the status quo. We believe in flat hierarchies, direct communication, and pragmatic decisions. No long approval chains. Just ownership, trust, and clear responsibility. We work hard, but we also believe in enjoying the ride together - over team lunches, afterwork drinks, company events, or a quick coffee in between meetings. If this sounds like you, ABOUT YOU could be the right place to bring in your perspective.
Job Description
We are looking for a Junior Application Security Engineer (all genders) to join the Application Security circle of our IT-Security unit, dedicated to protecting our online shop, our corporate systems and our customers.
In this role, you will hack internal systems, design and implement security measures to safeguard our infrastructure, applications, and data. You will work closely with other security engineers, developers and IT teams to ensure security best practices, automate security processes, and respond to emerging threats. This position contains:
- Conduct regular penetration tests and code reviews
- Advise in the setup and maintenance of applications and infrastructure (usually hosted in AWS/Kubernetes)
- Triage and respond to monitoring events
- Optimization and automation of security auditing processes. This could also include setting up attack infrastructure, writing scripts in Python and implementing security scanning in Gitlab CI.
- Take part in some incident response activities within the SOC, which include occasional 24/7 on-call
Qualifications
- At least one year of application security experience
- Able to perform active application security assessments and penetration testing
Nice to have:
- Develop and script using Python (Required; PHP, JavaScript, or Go preferred)
- Architect secure systems using threat modeling and security engineering practices
- Conduct secure code reviews across cloud environments (AWS/GCP preferred; Azure a plus)
- Execute red teaming operations and offensive security strategies
- Certificates: e.g. OSCP, OSWP, etc.
- Knowledge of Laravel / PHP.
- Ability to read and understand JavaScript
- Ability to read and understand Go
- Experience with incident response activities
- Experience with web application firewalls, CDN providers, e.g. Cloudflare, Akamai
- Experience with Gitlab CI/CD Pipelines
Additional Information
All your information will be kept confidential according to EEO guidelines.
Your perks at a glance: Visit our benefits page.
Simply apply online via our career page - we will get back to you as soon as possible!
A Place Where You Can Be You
We take it as our responsibility to create an environment where everyone feels welcome, exactly as they are.
Different backgrounds and perspectives make us stronger and shape our culture in ways that matter.
What we stand for internally, we stand for as a brand: acceptance, inclusion, and a fairer approach to fashion.