×
Hier anmelden um sich kostenlos auf Stellen zu bewerben oder Stellenanzeigen aufzugeben. X

Cyber Security Staff Engineer - Application Security

in 10115, Berlin, Berlin, Deutschland
Unternehmen: Solaris
Vollzeit position
Verfasst am 2026-08-07
Berufliche Spezialisierung:
  • IT/Informationstechnik
    Cyber-Sicherheit, Informationssicherheit & Datenschutz
Gehalts-/Lohnspanne oder Branchenbenchmark: 85000 - 110000 EUR pro Jahr EUR 85000.00 110000.00 YEAR
Stellenbeschreibung

Solaris
is Europe's leading embedded finance platform. Solaris’ full German banking license and proprietary modular B2B tech stack empowers its partners – from SMEs to large, multinational, non-financial companies – to offer compliant, customer‑centric banking services, providing seamless experiences to customers across all industries. Founded in 2016, Solaris pioneered the Banking‑as‑a‑Service market with an unparalleled combination of tech and banking. Solaris is headquartered in Berlin and employs 300 people in Europe.

Your

Role
  • Integrate security seamlessly into the Software Development Lifecycle (SDLC) and Dev Sec Ops  pipelines by automating security gates (SAST, DAST, SCA, and container scanning).
  • Conduct thorough threat modeling and architectural security reviews for complex applications, APIs, and microservices prior to deployment.
  • Perform deep‑dived manual and automated secure code reviews across various codebases to identify logic flaws and subtle implementation vulnerabilities.
  • Build and maintain "secure‑by‑default" internal libraries, frameworks, and developer tools to systematically eliminate entire classes of vulnerabilities.
  • Take ownership of the application vulnerability lifecycle, including triaging, validating, and prioritizing vulnerabilities originating from internal testing, penetration tests, and external bug bounty programs.
  • Act as a strategic partner to product and engineering teams, providing pragmatic mitigation guidance that balances product velocity with security assurance.
  • Design and deliver modern, hands‑on secure coding training and security awareness initiatives for engineering teams (e.g., addressing OWASP Top 10, LLM/AI security risks).
  • Support incident response and detection teams during application‑level security incidents or potential data breaches, leading post‑mortem analysis for software flaws.
  • Ensure application security controls remain fully compliant with relevant financial data protection regulations, fintech standards, and internal tech policies.
  • Owners of this function make sure that they follow the defined Policies & Procedures for the institution (which includes explicit processes defined for Tech, which are properly defined in the respective confluence spaces).
  • Take ownership of the tech responsibilities as described in our Change Management Policies.
We'd love to see

Depending on your level of experience, your responsibilities and scope of role will range. We don’t care much about fancy titles, but rather about real personal and professional development, as laid out in our learning framework. Let’s figure together out how you can contribute to our team.

  • A degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or equivalent professional experience.
  • 6+ years of experience in dedicated Application Security, Dev Sec Ops , or Software Engineering roles with a strong focus on security in high‑growth cloud environments (Fintech or highly regulated environment is a plus).
  • Proven experience analyzing and securing code written in our core tech stack/modern languages (e.g., Java, Go, Python, Type Script, or Rust).
  • Deep understanding of web application vulnerabilities, API security, and exploitation techniques (OWASP Top 10, CWE).
  • Hands‑on experience integrating security testing tools into modern CI/CD pipelines (e.g., Git Hub Actions, Git Lab CI, Jenkins, Snyk, Semgrep).
  • Experience with cloud computing infrastructure (AWS, GCP, or Azure), containerization (Docker), and orchestration (Kubernetes).
  • Experience managing or triaging external penetration testing reports and crowdsourced bug bounty programs.
  • Understands agile workflows and lean principles.
  • Experience by doing threat modeling.
  • Individual Contributor, technical mentorship focus.
  • Business proficient written and spoken English. German is a plus.
  • Ability to translate complex cryptographic or technical security vulnerabilities into business risk for non‑technical stakeholders and actionable fixes for developers.
  • Empathic collaborator who builds bridges between security goals and engineering targets, avoiding the "department of No" stereotype.
  • Strong analytical mindset capable of finding…
Bitte beachten Sie, dass derzeit keine Bewerbungen aus Ihrem Zuständigkeitsbereich für diese Stelle über diese Jobseite akzeptiert werden. Die Präferenzen der Kandidaten liegen im Ermessen des Arbeitgebers oder des Personalvermittlers und werden ausschließlich von diesen bestimmt.
Um nach Stellen zu suchen, sie anzusehen und sich zu bewerben, die Bewerbungen aus Ihrem Standort oder Land akzeptieren, klicken Sie hier, um eine Suche zu starten:
 
 
 
Suchen Sie hier nach weiteren Stellen:
(nach Beruf, Fähigkeit)
Standort
Suchradius erweitern (Meilen)
0
200
Filter
Mindest-Bildungsgrad für die Stelle
Mindest-Berufserfahrung für die Stelle
Veröffentlicht in den letzten:
Gehalt