AppSec Security Specialist

AppSec Security Specialist

Vollzeit 61650 - 75350 € / Jahr (geschätzt) Homeoffice (teilweise)
R

Auf einen Blick

  • Aufgaben: Unterstütze die Anwendungssicherheit und verbessere Sicherheitspraktiken in einem dynamischen Team.
  • Unternehmen: Rezdy, ein innovatives Unternehmen im Bereich Touren und Aktivitäten.
  • Vorteile: Flexible Arbeitszeiten, Weiterbildungsmöglichkeiten und ein unterstützendes Team.
  • Weitere Informationen: Wachstumsorientierte Kultur mit Fokus auf Zusammenarbeit und kontinuierliche Verbesserung.
  • Warum dieser Job: Gestalte die Zukunft der Sicherheit in einer aufregenden Branche mit echten Auswirkungen.
  • Qualifikationen: Mindestens 4 Jahre Erfahrung in Anwendungssicherheit oder verwandten Bereichen.

Das prognostizierte Gehalt liegt zwischen 61650 - 75350 € pro Jahr.

About Us

At Rezdy, we’re builders, doers, and difference-makers, driven by a shared mission to reshape the tours, activities, and experiences industry.

Alongside our sister brands, Checkfront and Regiondo, we power more than 20,000 businesses and support over $10B in bookings globally.

Our technology helps operators thrive while delivering unforgettable moments to travelers around the world.

We work in an industry built on adventure, energy, and human connection, and that same spirit fuels how we show up every day.

Spanning North America, Europe, and APAC, our teams are united by bold goals, a bias for action, and an unwavering commitment to delivering for our customers.

But our success starts with people.

Our teams are the engine behind everything we create.

We value self-starters who take ownership, embrace challenges, and raise the bar for themselves and those around them.

We believe in creating space to grow, take risks, and make a real impact, and we celebrate those who lead with curiosity, grit, and drive.

If you’re passionate about security, compliance, and helping teams work smarter and safer, this is your kind of place. Let’s build, grow, and win together.

About the Role

We are seeking an App Sec Security Specialist to support our growing security function, with a primary focus on application security, vulnerability management, and secure development practices across Checkfront and our sister brands.

This is a hybrid security role that combines hands‑on application security work with security operations support.

You will help identify and remediate risks across our web applications, APIs, cloud environments, and development workflows, while also supporting key security tools across endpoint protection, DLP, SIEM, SOAR, vulnerability management, and security awareness.

This role is ideal for someone who enjoys working with engineering teams, performing web application security scans, coordinating penetration testing activities, investigating security alerts, tracking remediation, and helping the business improve its overall security posture.

What You Will Do

  • Application Security
  • Support application security across Checkfront, Rezdy, Regiondo, and related platforms.
  • Perform web application security scans and help validate, prioritize, and track findings through remediation.
  • Support vulnerability management processes, including scanning, prioritization, reporting, and remediation tracking.
  • Use and support application security tools such as SAST, DAST, SCA, and manage security findings.
  • Coordinate with penetration testing vendors, including scoping, scheduling, evidence collection, findings review, and remediation follow-up.
  • Work with engineering/dev teams to validate security findings, reduce risk, and improve secure development practices.
  • Help identify and reduce risk across web applications, APIs, cloud services, and third‑party components.
  • Support secure software development practices, including clear guidance on remediation, secure coding, and risk reduction.
  • Security Operations
  • Support day‑to‑day security operations across endpoint protection, DLP, SIEM, SOAR, and vulnerability management tools.
  • Monitor and triage security alerts from tools such as Crowd Strike and related security platforms.
  • Assist with incident response activities, including investigation, documentation, escalation, and follow‑up actions.
  • Help tune alerts, workflows, automations, and reporting to reduce noise and improve security visibility.
  • Support security logging, monitoring, and detection improvement initiatives.
  • Security Awareness and Training
  • Manage and support the Know Be4 security awareness platform.
  • Coordinate phishing simulations, training campaigns, reporting, and follow‑up actions.
  • Help improve employee security awareness through clear communication, practical guidance, and targeted training.
  • Track training completion and support reporting related to security education.
  • Collaboration and Communication
  • Partner with security, IT, engineering, legal, privacy, and business teams to support security outcomes.
  • Translate security requirements into clear, actionable tasks.
  • Communicate findings, risks, and remediation needs to both technical and non‑technical stakeholders.
  • Help build a security culture focused on ownership, transparency, and continuous improvement.
  • What We Are Looking For
  • 4+ years of experience in application security, security operations, IT security, vulnerability management, or a related field.
  • Experience with web application security testing, vulnerability scanning, remediation tracking, or secure software development practices.
  • Experience with security tools such as EDR, DLP, SIEM, SOAR, vulnerability management, web application scanning, or security awareness platforms.
  • Familiarity with Crowd Strike, Know Be4, vulnerability scanners, ticketing systems, web application scanning tools, and GRC platforms is an asset.
  • Ability to investigate security alerts, document findings, and upscale issues appropriately.
  • Ability to work with engineering and IT teams to validate findings, track remediation, and reduce risk.
  • Strong attention to detail and the ability to track findings, risks, and remediation items through to completion.
  • Strong written and verbal communication skills with both technical and non‑technical audiences.
  • Comfort working in a fast‑moving Saa S environment with multiple brands, systems, and stakeholders.
  • A practical, curious, and ownership‑driven approach to security.
  • Nice to Have
  • Working knowledge of security and compliance frameworks such as SOC 2, ISO 27001, PCI DSS, GDPR, or similar standards.
  • Experience supporting audit preparation, evidence collection, control testing, or ongoing compliance tracking.
  • Experience supporting customer security questionnaires, vendor risk assessments, due diligence requests, or RFP security responses.
  • Experience supporting Saa S, fintech, travel technology, or other regulated technology environments.
  • Familiarity with cloud platforms, secure software development practices, and infrastructure security.
  • Experience coordinating external penetration tests or working with third‑party security vendors.
  • Certifications such as CISSP, Security+, CSSLP, or similar are an asset.
  • Experience with privacy, data protection, or AI governance requirements is an asset.
  • What You Can Expect

When you join our team, you’re stepping into a culture built on momentum, ownership, and connection.

We move fast, think big, and focus hard without losing sight of the people behind the work.

Across all our brands, we’re united by a belief that impact comes from empowered teams, clear priorities, and a shared commitment to our customers and each other.

  • High trust, high impact: We give our people the autonomy to take ownership, solve problems, and make meaningful contributions.
  • Curiosity is encouraged: We value learning, asking questions, and pushing boundaries, not just getting things done, but doing them better.
  • Collaboration over ego: We work as one team across geographies and brands. Success is shared, and support is a given.
  • Space to grow: Whether you’re deepening your security skills, expanding into compliance, or learning new tools, you’ll be backed to grow.
  • Progress over perfection: We embrace change, move quickly, and are constantly iterating to improve how we work and what we deliver.
  • You’ll be joining a global team that’s passionate about building something that matters and having a good time while doing it.

We’d love for you to join us on this exciting journey. Together, let’s shape the future of the leisure and tourism industry.

#J-18808-Ljbffr

AppSec Security Specialist Arbeitgeber: Rezdy

Rezdy ist ein hervorragender Arbeitgeber, der eine dynamische und unterstützende Arbeitsumgebung bietet, in der Mitarbeiter die Möglichkeit haben, ihre Fähigkeiten im Bereich Anwendungssicherheit weiterzuentwickeln. Mit einem starken Fokus auf Teamarbeit und persönlichem Wachstum fördert das Unternehmen eine Kultur des Lernens und der Zusammenarbeit, während es gleichzeitig innovative Lösungen für die Tourismusbranche entwickelt. Die hybride Arbeitsweise ermöglicht es den Mitarbeitern, flexibel zu arbeiten und gleichzeitig an bedeutenden Projekten teilzuhaben, die einen echten Einfluss auf die Branche haben.

R

Kontaktdaten:

Rezdy Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so AppSec Security Specialist erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Rezdy kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Rezdy zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Rezdy.

Wir glauben, dass du diese Fähigkeiten brauchst, um AppSec Security Specialist mit Bravour zu bestehen

Anwendungssicherheit
Schwachstellenmanagement
Sichere Softwareentwicklung
Webanwendungssicherheitstests
SAST
DAST
SCA

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei Rezdy vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Rezdy könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Rezdy sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird Rezdy auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!