At AdvanceWorks, we learn together, grow together, and have fun together. And we do all this while creating great software solutions for clients across many industries and geographies.
We are constantly challenging ourselves and each other to use the latest technologies and the best methodologies and make sure we walk the talk.
What will be your role
We are looking for an Application Security Engineer to join our team in Lisbon and contribute to the evolution of application security for a leading organization in the mobility and transportation sector, operating with business-critical technology solutions across different markets.
In this role, you’ll help bring security into the entire software development lifecycle, from application design and architecture through to production. You’ll work closely with Development, Architecture and IT teams, helping them identify security risks, implement secure solutions and continuously improve their security practices.
This is a hands-on and transversal role, sitting at the intersection of Software Development, Application Security, Architecture and DevSecOps.
Your responsibilities will include
- Supporting development and architecture teams in identifying and mitigating application security risks
- Participating in security and architecture reviews, threat modelling and secure design activities
- Analysing and managing vulnerabilities identified through code analysis, dependency scanning, container analysis and penetration testing
- Assessing security findings, prioritising risks and supporting development teams throughout remediation
- Working with external penetration testing providers, including scope definition, findings analysis and remediation follow-up
- Promoting OWASP, Secure Coding and security best practices across development teams
- Delivering security awareness sessions, workshops and technical guidance to developers
- Supporting the implementation of Security Champions initiatives
- Contributing to DevSecOps practices by integrating security controls and automated checks into CI/CD pipelines
- Supporting the definition and implementation of secure authentication, authorisation, API security and data protection mechanisms
- Helping evolve application security processes, standards and practices across the organisation
- Communicating security risks and technical recommendations clearly to both technical and non-technical stakeholders
What should you bring to the team
- 3+ years of experience in Software Development, Application Security, DevSecOps or a closely related field
- Strong software development background, particularly with Java/Spring Boot or C#/.NET
- Solid understanding of application architecture and secure software development principles
- Experience with OWASP, Secure Coding and vulnerability management
- Knowledge of OAuth2, OpenID Connect, JWT and API Security
- Experience with secrets management and secure handling of sensitive dataHands-on experience with security testing and vulnerability assessment
- Familiarity with tools such as SonarQube, Snyk, Burp Suite, ZAP, Checkmarx, Fortify or similar
- Experience working with APIs, Linux and Cloud environments, particularly AWS and/or Azure
- Understanding of DevSecOps practices and CI/CD pipelines
- Ability to analyse technical security issues and work directly with developers towards effective remediation
- Strong communication skills and the ability to explain security concepts and risks to different audiences
- Proactive, collaborative and pragmatic approach to application security
- Availability to work in a hybrid model in Oeiras
- Good level of English, both written and spoken
Nice to have
- Experience with threat modelling and security architecture
- Experience integrating SAST, DAST, SCA or container security controls into CI/CD pipelines
- Knowledge of Security Champions programmes
- Experience with cloud security practices
- Relevant security certifications such as CSSLP, OSCP, CEH or similar
What is in it for you
- An amazing informal culture of smart, hardworking, and friendly people who support and care about each other
- A mentorship program from day one
- Opportunity to work on business-critical applications and security initiatives
- Formal training and certifications in security, cloud, architecture, and engineering excellence
- Access to cutting-edge tools and technologies
- A dynamic company where your ideas matter more than job titles
- Flexibility with responsibility
- A Rubber Duck to help you debug those tricky security problems