Skip to content

Senior Application Security Engineer (m/f/d)

  • Remote, Hybrid
    • Köln, Nordrhein-Westfalen, Germany
  • €85,000 - €110,000 per year
  • Tech

Job description

Are you ready to be a security leader in the SaaS space? Join epilot!


We are looking for a senior security-minded engineer who goes beyond finding vulnerabilities and focuses on building automated, resilient defenses into our AWS-powered products. You will combine technical expertise with a proactive security mindset to protect impactful software from the ground up.

epilot is building a SaaS product to sell complex products online, focusing first on solving ecommerce in the rapidly transforming energy market. Our mission: Make selling complex products as easy as selling a pair of shoes online.

As the Application Security Engineer at epilot you will be a driving force in ensuring our products are secure by design. What makes working in engineering at epilot so special? Our unique culture is defined by a few core principles that apply to all our engineers.

Among others, you can expect freedom and responsibility because we hire smart people we can trust. We operate by principles and expect everyone to cultivate a strategic mindset.

We believe in ownership: you secure it, you run it. You will work closely with development teams to integrate security into every stage of the lifecycle. There is no separate security silo to hand things off to, you’ll design, implement, and automate defenses that keep our AWS-powered products safe and scalable. This includes integrating vulnerability testing tools, supporting incident response, and participating in bug bounty triage.


You should always show, don’t tell: Deliver secure, working software early and frequently. We believe in the Agile principle of “Release early and release often,” with the added goal of ensuring security from the first release onward. Fast feedback loops between ourselves, our users, and our security systems help us manage risk and make better decisions.

Does this sound like an environment you want to work in? Then you could bet the right person to be an engineer at epilot!

Check out our promise to you: promise.epilot.cloud


We "epilots" are a team of experts from the fields of software development, energy management, product management and sales. In order to bring our solution even faster and more secured to the top in the energy world, we are looking for you as a Security Engineer

Job requirements

What awaits you
As an Application Security Engineer at epilot, you’ll play a key role in building secure-by-default features and hardening the backbone of our cloud-native platform. You’ll work closely with engineers across the stack to shift security left and help us scale securely as we grow.

Here’s what you’ll do:

  • Embed security into our development lifecycle by integrating SAST, DAST, and dependency scanning tools into CI/CD pipelines

  • Collaborate with engineering teams to identify vulnerabilities early and support remediation with actionable guidance

  • Build and maintain automation for security testing and compliance reporting

  • Work hands-on with AWS services to improve cloud security posture and advise on secure architecture

  • Drive threat modeling, participate in secure code reviews, and support bug bounty triage

  • Educate teams on secure coding practices and OWASP Top 10 risks in web and API development

  • Lead or support incident response efforts and post-incident reviews

  • Develop internal tooling or scripts to simplify and automate security operations

What you bring:

We’re looking for a senior security-minded engineer who thrives in a fast-paced, product-centric environment and has the following skills and mindset:

Technical Foundation:

  • Proficient in any modern programming language (e.g. Python, JavaScript, Go, etc.)

  • Conceptual understanding of OWASP Top 10 for both web and API applications

  • Experience with security tooling: SAST, DAST, AWS security services (GuardDuty, IAM, CloudTrail, etc.)

  • Solid understanding of AWS infrastructure and cloud-native architectures

  • Background in scripting or automating processes in CI/CD environments

Bonus Points:

  • You were a software engineer before switching to security — that mindset is gold

  • Certifications like OSCP or AWS Certified Security – Specialty

  • Familiarity with IaC (Terraform, CloudFormation) and Security-as-Code practices

Mindset:

  • You take ownership of initiatives, see them through to completion, and aren’t afraid to challenge the status quo

  • You’re pragmatic and collaborative — security is a team sport, not a gate

  • You love simplifying complex problems and turning them into scalable, automated solutions

What we offer you

At epilot, we believe in rewarding performance, fostering growth, and creating an environment where you’ll thrive:

  • Impactful Work: Be part of a product-driven company that’s reshaping the energy sector.

  • Startup Mentality: Enjoy a dynamic atmosphere with flat hierarchies and open communication.

  • Flexibility: Work remotely or from our centrally located office in Cologne, with flexible working hours.

  • Growth Opportunities: Your career will grow as fast as we do. Learn, experiment, and embrace a “Fail Fast and Often” mentality.

  • Competitive Compensation: We take your desired salary seriously and value performance.

  • Team Spirit: Join us for regular events like summer parties, company breakfasts, and our epic annual epilot summit, where you’ll connect with co-epilots worldwide.

  • Transparency and Openness: Everything is open for discussion in our inclusive and supportive culture.

We are looking forward to your application ^^


Remote, Hybrid
  • Köln, Nordrhein-Westfalen, Germany
€85,000 - €110,000 per year
Tech

or

Apply with Linkedin unavailable
Apply with Indeed unavailable

epilot insights

Who should know better what it's like to work at epilot than our epilots themselves?

Perks

Continuous education

We support you in your personal development!

Flexible working hours and remote work

You have an important appointment in the morning? No problem! You decide where and when you want to work.







Fitness Studio Subscription

Stay fit and work out at the gym (with a pool and sauna) 5 minutes from the office.

Regular team events

We celebrate our successes together at regular events at carnival, in the summer, at Christmas and also in between.

JobRad

Do something for the environment and your health and lease your JobRad.

More perks

Refreshing drinks, fruit, language courses, relocation service and other benefits are waiting for you!

Become part of a great and awarded team!

Meet the team

Pictures say more than 1000 words. Here is a little look behind the scenes of epilot. Whether meetups, carnivals, summer parties or even co-working in Portugal - working @ epilot is more than sitting in front of the screen from 9 to 5!

Questions left?

Reach out directly to us!

Köln

(Senior) Project Manager (m/w/d)
Hybrid
  • Köln, Nordrhein-Westfalen, Germany
Account Executive (w/m/d) - SaaS/B2B
Hybrid
  • Köln, Nordrhein-Westfalen, Germany
Customer Support Manager (m/w/d)
Hybrid
  • Köln, Nordrhein-Westfalen, Germany
Event Marketing Manager (m/w/d)
On-site, Hybrid
  • Köln, Nordrhein-Westfalen, Germany
Head of Marketing (m/w/d)
On-site, Hybrid
  • Köln, Nordrhein-Westfalen, Germany
Revenue Operations Manager (m/w/d)
On-site, Hybrid
  • Köln, Nordrhein-Westfalen, Germany
Senior Application Security Engineer (m/f/d)
Remote, Hybrid
  • Köln, Nordrhein-Westfalen, Germany
Werkstudent/Praktikant (m/w/d) Sales - SaaS/B2B
On-site
  • Köln, Nordrhein-Westfalen, Germany

epilot HQ

Our office is located in the heart of Cologne, with cool cafes, restaurants and bars just around the corner. The park, right behind the office, invites you to have lunch or take a walk, especially in summer.

Address Im Mediapark 8a, 50670 Cologne, Germany