About this role
Python Engineer (AppSec)
Morgan Stanley
DETAILS
ID71662
Developer
Python
Engineering
Python
Python
AppSec Tooling Expertise
Terraform
Full-time
Poland, Portugal, Ukraine, Bulgaria, Romania, Spain, Slovakia, Slovenia
Europe, Poland, Portugal, Ukraine, Bulgaria, Romania, Spain, Slovakia, Slovenia
3+ years of experience
Experience (Filter):
3–5 years
Experience (Search):
Middle Senior
Remote
TECH STACK
Python
AppSec Tooling Expertise
Terraform
CSPM
70123
About the role
We are looking for a Python Application Security Engineer to automate application security controls and integrate secure coding practices into software development and cloud workflows.
The mandatory requirements are 3+ years of experience in software engineering and security, Python, AppSec tool APIs, CSPM, IaC/Terraform checks and independent execution; upper-intermediate English is required. SAST/DAST/SCA, AI security, threat modeling and Java are a plus.
Must haves
- 3+ years of experience combining software engineering experience, security implementation and/or architecture experience.
- Strong coding and architectural proficiency in Python (for security automation and scripting).
- Hands-on experience or familiarity with Wiz, Prisma Cloud, or similar tools for cloud security posture management and threat detection.
- Implementation experience with deploy-time checks against Infrastructure as Code (IaC) / Terraform.
- Implementation experience with runtime checks through Cloud Security Posture Management (CSPM).
- Fully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks.
- Upper-intermediate English level.
Nice to haves
- Deep, hands-on expertise deploying and tuning modern application security testing tools (SAST, DAST, SCA) and integrating them into complex CI/CD orchestration ecosystems.
- Experience integrating LLMs, AI agents, or automated coding assistants to streamline vulnerability triaging or secure code generation.
- Advanced application threat modeling experience.
- Ability to confidently read, review and secure enterprise source Java code.
What you will do
- AppSec Engineering & Automation: Engineer and deploy AI-enabled secure code scanning capabilities and "Golden Images" to drive secure-from-the-start adoption.
- Technical Modernization: Automate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows.
- Security Tooling Integration: Architect the integration of continuous security scanning tools (SAST, DAST, SCA) into enterprise CI/CD pipelines, tuning them to eliminate noise.
- Cloud & Runtime Security: Implement runtime security checks via CSPM to maintain continuous cloud visibility and threat posture management.
- Developer Experience (DevEx): Act as a senior technical SME, reading and reviewing complex application code (Java/Python) to provide software engineers with highly specific, code-level remediation guidance.
Perks
- Growth without limits: build your skills through mentorship, internal TechTalks, challenging projects, and a dedicated annual learning budget
- Competitive compensation: get recognition that reflects your skills and impact, with regular performance and compensation reviews
- Flexibility: work 100% remotely with flexible hours that support focus, autonomy, and a healthy work rhythm
- Meaningful, modern projects: build impactful products using modern technologies alongside global teams and leading brands
- Collaborative culture: join a supportive environment with zero micromanagement where ideas are welcomed and contributions are recognized
- Well-being & support: access local well-being programs and people-focused support tailored to your location