Trade Republic Bank GmbH Logo

Trade Republic Bank GmbH

Senior Security Engineer - Application Security

Posted 26 Days Ago
Be an Early Applicant
In-Office
London, Greater London, England, GBR
Senior level
In-Office
London, Greater London, England, GBR
Senior level
Lead application security efforts by embedding security into the SDLC, performing code reviews, threat modeling, pen tests, and vulnerability management. Build automated SAST/DAST/SCA testing in CI/CD, develop secure coding standards and libraries, run security training and a champions program, and support bug bounty and blockchain/mobile app security assessments.
The summary above was generated by AI

Please note that this position is based in Berlin or London. 


THE BEST WORK OF YOUR CAREER 

Trade Republic is the largest savings platform in Europe - we operate in 17 countries, serving +8 million customers who trusted us with over 100B in assets. But we’re striving for more.

We have a bold mission to empower everyone to build wealth with easy, safe, and free access to financial systems. You will have the opportunity to grow your career by collaborating with a team of outstanding talents and state of the art technology to build a lasting, positive future for millions.


WHAT YOU'LL BE DOING

As a Senior Security Engineer in our Application Security team, you'll safeguard Trade Republic's applications and development lifecycle through proactive security integration and engineering excellence. Your responsibilities include:

  • Partner with engineering teams to embed security into the software development lifecycle from design to deployment;
  • Conduct security code reviews, threat modeling sessions, and architecture reviews for critical applications and services;
  • Design and implement SAST, DAST, and SCA solutions to identify vulnerabilities early in the development process;
  • Build and maintain application security testing automation within CI/CD pipelines;
  • Develop secure coding standards, security libraries, and reusable security components for engineering teams;
  • Perform penetration testing and vulnerability assessments of web applications, APIs, and mobile applications;
  • Triage, prioritise, and remediate application vulnerabilities working closely with development teams;
  • Create security champions program and provide security training to engineering teams;
  • Research emerging application security threats and integrate defensive measures into the security architecture;
  • Contribute to bug bounty program management and coordinate with external security researchers

WHAT WE'RE LOOKING FOR

Core Experience:

  • 5+ years as a Security Engineer with 4+ years focused on application security
  • Deep understanding of web application security (OWASP Top 10, API security, authentication/authorization)
  • Hands-on experience with security testing tools (Burp Suite, OWASP ZAP, Semgrep, etc.)
  • Strong programming skills in modern languages (Python, Java, Kotlin, Go, or JavaScript)
  • Experience integrating security tooling into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins)
  • Expertise in secure architecture patterns for microservices, APIs, and distributed systems
  • Solid understanding of cryptography, secure session management, and identity/access management
  • Hands-on experience with security testing of cryptocurrency/blockchain infrastructure and applications is a major bonus
  • Experience with mobile application security (iOS/Android)
  • Knowledge of compliance frameworks (PCI-DSS, GDPR, MaRisk) is advantageous
  • Excellent communication skills to translate security concepts for engineering audience
 WHY YOU SHOULD APPLY NOW

Our culture rewards ownership, excellence, and high energy. We care deeply about outcomes and hold each other accountable - we’re here to win and fix one of the largest challenges Europeans face - closing the pension gap and democratising wealth. If this gets you fired up, reach out!

We believe it’s our team’s varied identities and backgrounds that make us sharper and stronger. We’re committed to creating an environment where everyone feels respected and has equal opportunity to thrive in their careers. For any questions on DEI during the interview process, reach out to your recruitment partner.

Trade Republic Bank GmbH London, England Office

London, United Kingdom

Similar Jobs

Yesterday
Remote or Hybrid
Expert/Leader
Expert/Leader
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
The Regional Partner Manager is responsible for building the partner community and driving revenue through recruitment, training, and GTM strategies. Duties include managing the partner program, coordinating with sales teams, and developing marketing tools specific to partners.
Yesterday
In-Office or Remote
Senior level
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Provides staff-level technical leadership for enterprise AI/ML platform infrastructure. Designs and operates AWS, Kubernetes, serverless, and containerized environments; develops infrastructure-as-code, CI/CD, observability, security, governance, and cost-optimization standards. Supports generative AI workloads, model routing, reliability, scalability, and performance. Partners with engineering, security, and operations teams, mentors engineers, reviews architecture, and drives platform maturity across multiple teams.
Top Skills: Amazon CloudwatchAmazon Ecs FargateAmazon EksAmazon OpensearchAmazon S3Application Load BalancerAWSAws BedrockAws LambdaAws Secrets ManagerAzure OpenaiCloudFormationDockerDynamoDBGitGithub ActionsGrafanaHelmIamKubernetesLangfuseLitellmLocustMwaaOidcPre-CommitPrometheusPythonTerraformVpc
Yesterday
Hybrid
Senior level
Senior level
Artificial Intelligence • Information Technology • Machine Learning • Natural Language Processing • Productivity • Software • Generative AI
Designs and maintains corporate security controls across identity, endpoints, SaaS platforms, and network infrastructure. The role leads Zero Trust architecture, AI security standards, vulnerability remediation, risk assessments, and security automation. It also supports insider risk, threat and vulnerability management, third-party risk, data protection, SaaS security posture management, and collaboration with Governance, Risk, and Compliance teams.
Top Skills: Ai SecurityCasbCoupaData Loss PreventionData Security Posture ManagementEndpoint ManagementIdentity And Access ManagementmacOSSaas Security Posture ManagementSalesforceThreat Detection And ResponseVpnVulnerability ManagementWindowsWorkdayZero TrustZtna

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account