Rooted
Back to jobs
CO
Open role

Codewerk

Application Security Engineer

Karlsruhe, Germany· HYBRID

Hacker+ signal

About the role

You work alongside the development teams rather than auditing them from outside. That means reviewing architecture proposals before they are built, reviewing code before it ships, and maintaining the automated security scanning in the build pipeline. A large part of the role is turning recurring problems into checks or libraries so the same class of bug stops reaching production.

What you will do

  • Review code and designs for security consequences
  • Own the scanning pipeline and keep its noise down
  • Turn each recurring finding into a guardrail

What they ask for

  • Reads and writes production code in at least one language
  • Knows the common vulnerability classes by mechanism, not by name
  • Has shipped a fix somebody else had to maintain

Nice to have

  • Threat modelling
  • Semgrep or CodeQL rules
  • Open source contributions

What applying with Rooted means

This role accepts applications with Rooted context. Instead of sending only a resume, you can attach a verifiable credential with your proofs, rank, and technical evidence.

Your application includes your Rooted credential: rank, verified proofs, and supporting evidence.

You can read this role without an account. To apply you need a Rooted credential.

This role is curated by Rooted. Rooted is not the hiring company unless explicitly stated. The hiring company is Codewerk. Confirm the final details with the original source or during the application process.

Posted 2026-08-13