Application Security Engineer

AdvanceWorks

Lisboa

Híbrido

EUR 70 000 - 95 000

Tempo integral

Há 6 dias
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Mentorship program
Formal training
Cutting-edge tools
Flexible work

Resumo da oferta

AdvanceWorks is seeking an Application Security Engineer in Lisbon to strengthen the security of software across the full development lifecycle. You will collaborate with Development, Architecture and IT teams to identify risks, implement secure solutions and improve security practices across multiple markets.

The role sits at the intersection of Software Development, Application Security, Architecture and DevSecOps, with responsibilities spanning reviews, threat modelling, vulnerability

Qualificações

  • 3+ years of experience in Software Development, Application Security or DevSecOps.
  • Strong background in Java/Spring Boot or C#/NET.
  • Solid understanding of secure software development principles.
  • Experience with OWASP, Secure Coding and vulnerability management.
  • Knowledge of OAuth2, OpenID Connect, JWT and API Security.
  • Experience with secrets management and secure handling of sensitive data.
  • Hands-on security testing and vulnerability assessment.
  • Familiarity with tools such as SonarQube, Snyk, Burp Suite, ZAP, Checkmarx, Fortify.

Responsabilidades

  • Identify and mitigate application security risks with development and architecture teams.
  • Participate in security and architecture reviews, threat modelling and secure design activities.
  • Analyse and manage vulnerabilities from code analysis, dependency scanning, container analysis and pentesting.
  • Promote OWASP, Secure Coding and security best practices across development teams.
  • Deliver security awareness sessions and technical guidance to developers.
  • Support DevSecOps by integrating security controls into CI/CD pipelines.
  • Define and implement secure authentication, authorisation, API security and data protection measures.

Conhecimentos

Java/Spring Boot
C#/.NET
DevSecOps
OWASP
API Security
Threat modelling
Security testing
Cloud (AWS/Azure)
CI/CD pipelines
Communication

Ferramentas

SonarQube
Snyk
Burp Suite
ZAP
Checkmarx
Fortify

Descrição da oferta de emprego

At AdvanceWorks, we learn together, grow together, and have fun together. And we do all this while creating great software solutions for clients across many industries and geographies.

We are constantly challenging ourselves and each other to use the latest technologies and the best methodologies and make sure we walk the talk.

What will be your role

We are looking for an Application Security Engineer to join our team in Lisbon and contribute to the evolution of application security for a leading organization in the mobility and transportation sector, operating with business-critical technology solutions across different markets.

In this role, you’ll help bring security into the entire software development lifecycle, from application design and architecture through to production. You’ll work closely with Development, Architecture and IT teams, helping them identify security risks, implement secure solutions and continuously improve their security practices.

This is a hands-on and transversal role, sitting at the intersection of Software Development, Application Security, Architecture and DevSecOps.

Your responsibilities will include
  • Supporting development and architecture teams in identifying and mitigating application security risks
  • Participating in security and architecture reviews, threat modelling and secure design activities
  • Analysing and managing vulnerabilities identified through code analysis, dependency scanning, container analysis and penetration testing
  • Assessing security findings, prioritising risks and supporting development teams throughout remediation
  • Working with external penetration testing providers, including scope definition, findings analysis and remediation follow-up
  • Promoting OWASP, Secure Coding and security best practices across development teams
  • Delivering security awareness sessions, workshops and technical guidance to developers
  • Supporting the implementation of Security Champions initiatives
  • Contributing to DevSecOps practices by integrating security controls and automated checks into CI/CD pipelines
  • Supporting the definition and implementation of secure authentication, authorisation, API security and data protection mechanisms
  • Helping evolve application security processes, standards and practices across the organisation
  • Communicating security risks and technical recommendations clearly to both technical and non-technical stakeholders
What should you bring to the team
  • 3+ years of experience in Software Development, Application Security, DevSecOps or a closely related field
  • Strong software development background, particularly with Java/Spring Boot or C#/.NET
  • Solid understanding of application architecture and secure software development principles
  • Experience with OWASP, Secure Coding and vulnerability management
  • Knowledge of OAuth2, OpenID Connect, JWT and API Security
  • Experience with secrets management and secure handling of sensitive dataHands-on experience with security testing and vulnerability assessment
  • Familiarity with tools such as SonarQube, Snyk, Burp Suite, ZAP, Checkmarx, Fortify or similar
  • Experience working with APIs, Linux and Cloud environments, particularly AWS and/or Azure
  • Understanding of DevSecOps practices and CI/CD pipelines
  • Ability to analyse technical security issues and work directly with developers towards effective remediation
  • Strong communication skills and the ability to explain security concepts and risks to different audiences
  • Proactive, collaborative and pragmatic approach to application security
  • Availability to work in a hybrid model in Oeiras
  • Good level of English, both written and spoken
Nice to have
  • Experience with threat modelling and security architecture
  • Experience integrating SAST, DAST, SCA or container security controls into CI/CD pipelines
  • Knowledge of Security Champions programmes
  • Experience with cloud security practices
  • Relevant security certifications such as CSSLP, OSCP, CEH or similar
What is in it for you
  • An amazing informal culture of smart, hardworking, and friendly people who support and care about each other
  • A mentorship program from day one
  • Opportunity to work on business-critical applications and security initiatives
  • Formal training and certifications in security, cloud, architecture, and engineering excellence
  • Access to cutting-edge tools and technologies
  • A dynamic company where your ideas matter more than job titles
  • Flexibility with responsibility
  • A Rubber Duck to help you debug those tricky security problems
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Application Security Engineer | Lisbon | Hybrid
Application Security Engineer | Lisbon | Hybrid

Decskill • Lisboa

Presencial
EUR 90 000 - 130 000
Application Security
Application Security

WIRE IT • Porto

Híbrido
EUR 40 000 - 60 000
Health Insurance
22 days of paid vacation
4 extra days annually (Carnival, Christmas Eve, New Year's Eve, Birthday)
+6
Application Security Engineer
Application Security Engineer

emagine • Lisboa

Híbrido
EUR 65 000 - 95 000
Application Security
Application Security

WIREIT • Portugal

Híbrido
EUR 40 000 - 60 000
Health Insurance
22 days of paid vacation
4 extra vacation days
+5
Application Security Engineer — DevSecOps Champion
Application Security Engineer — DevSecOps Champion

AdvanceWorks • Lisboa

Híbrido
EUR 70 000 - 95 000
Mentorship program
Formal training
Cutting-edge tools
+1
Devoteam Cyber Trust | Application Security - Lead | Banking Sector
Devoteam Cyber Trust | Application Security - Lead | Banking Sector

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 40 000 - 60 000
Application Security Engineer
Application Security Engineer

IDW • Oeiras

Híbrido
EUR 45 000 - 65 000
Seguro de saúde
Subsídio de alimentação em cartão refe
Dias de férias adicionais
+1
Application Security Engineer
Application Security Engineer

Claranet limited • Porto

Presencial
EUR 40 000 - 60 000
Devoteam Cyber Trust | Application Security - Lead | Banking Sector
Devoteam Cyber Trust | Application Security - Lead | Banking Sector

Devoteam • Portugal

Presencial
EUR 40 000 - 60 000
Application Security Analyst
Application Security Analyst

PrimeIT • Porto

Híbrido
Health insurance
Extra salary benefits
Training and development plan
+3