CO

Application Security Research Engineer

COMMIT

Barcelona, ESonsitePosted Aug 10, 2026
Posting intelligenceActively listed

Skills

kubernetescicdllm

About the role

We are looking for an Application Security Research Engineer in Barcelona. In this role, you will work with a team of researchers and ethical hackers focused on offensive security testing, automated exploit discovery, and advanced application security research. Your work will directly influence the security posture of company products and help scale secure-by-design principles. This is a hands-on technical role with a strong emphasis on offensive security, code exploitation, automation, and innovation.

Responsibilities:

Help to reshape the company's Product Security

Plan and execute advanced penetration testing campaigns.

Develop tools and frameworks for scalable security testing and fuzzing.

Lead Security innovation by building and managing penetration testing tools \ AI Agents

Analyze vulnerabilities, perform root cause analysis, and develop proofs of concept.

Identify systemic product weaknesses and help define long-term mitigations.

Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.

Contribute to security research publications, CVE submissions, and industry knowledge sharing.

Continuously evolve internal testing capabilities using modern tooling and AI-assisted approaches.

Requirements:

Requirements:

5+ year experience in Research and penetration testing.

Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies.

AI and LLM Penetration testing knowldge and Experience

Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and Custom Security Tools development.

Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes).

Familiarity with secure software architecture and typical attack vectors.

Demonstrated ability to lead security testing engagements and report technical findings effectively.

Experience building or integrating automated PT or fuzzing pipelines is a strong advantage.

Knowledge and hands-on experience with SSDLC tools and CI/CD pipelines,

Publications or open-source contributions in the security domain are a plus.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on COMMIT's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Research Engineer roles in Spain varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Research Engineer hub for Spain medians across recent openings.

You never touch the form - the application is filled and submitted for you on COMMIT's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.