AppSec Engineer

Remote - European Region
Engineering – Security /
Full-time /
Hybrid
Coinspaid Dev is the engineering brand behind the technology, infrastructure, and R&D expertise built within Coinspaid. With more than 120 engineers and over 11 years of industry experience, Coinspaid Dev brings together software engineering, infrastructure, security and R&D teams with experience building distributed systems and blockchain infrastructure operating across more than 20 blockchain networks.

Coinspaid Dev emerges as an independent engineering brand with a straightforward mission: to advance blockchain infrastructure engineering and contribute practical expertise back to the industry. The structure is new. The experience behind it is not.

Responsibilities:

  • Support and continuously improve the company's Vulnerability Management process.

  • Perform vulnerability triage, risk assessment, prioritization, and remediation tracking.

  • Work with engineering teams to ensure timely remediation of identified vulnerabilities.

  • Analyze findings from multiple security tools and sources and reduce noise through effective prioritization.

  • Monitor vulnerability remediation SLAs and provide visibility into security posture through reporting and metrics.

  • Participate in threat modeling activities for new systems, services, and significant architectural changes.

  • Conduct security risk assessments and provide actionable recommendations.

  • Define and maintain application security requirements in collaboration with engineering teams.

  • Support Secure SDLC initiatives and help integrate security practices into development workflows.

  • Provide guidance to developers and DevOps engineers on vulnerability remediation and secure design practices.

Requirements:

  • 4+ years of experience in Application Security, Product Security, Vulnerability Management, or a related security discipline.

  • Hands-on experience managing and prioritizing vulnerabilities across applications, infrastructure, containers, and cloud environments.

  • Strong understanding of OWASP Top 10, CWE, CVSS, EPSS, MITRE ATT&CK, and risk-based vulnerability management approaches.

  • Experience with security testing technologies such as SAST, DAST, SCA, Container Security, and Cloud Security tools.

  • Experience conducting threat modeling and security risk assessments.

  • Understanding of modern software development practices and CI/CD pipelines.

  • Familiarity with Kubernetes and cloud platforms (AWS, GCP, or Azure).

  • Ability to analyze security findings and make risk-based remediation recommendations.

  • Strong stakeholder management and communication skills.

Why join CryptoProcessing by Coinspaid

You’ll be joining a company that is actively shaping its space – with enough scale to matter and enough room to make an impact.

At Coinspaid, people are expected to think, contribute, and take ownership – and are supported in doing so.

We focus on flexibility, wellbeing, and long-term growth – without overcomplicating how benefits work.

Flexible Benefits

Benefit Bar – up to €230/month
A flexible monthly budget you can use for what matters most to you – from sports and mental health to coworking, home office, or medical-related expenses.

Work & Flexibility

  • Fully remote work from almost anywhere

  • Optional offices and relocation support

  • Flexible, async-friendly environment

Growth & Learning

  • Budget for courses, certifications, and professional development

  • Language learning support

  • Cross-team learning and knowledge sharing

Wellbeing & Support

  • Medical insurance or reimbursement depending on location

  • Access to mental health support

  • Financial support for important life events

Extras

  • Merch shop with rewards system

  • Team offsites and company events

Sounds good? Well then, we can’t wait to see your resume!