Application Security Engineer

Jobtailor

Lisboa

Presencial

EUR 60 000 - 80 000

Tempo integral

Há 4 dias
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Jobtailor in Portugal is seeking an experienced security-focused engineer to define and promote Secure SDLC practices, integrating security into architecture and development. You will lead threat modeling, review security findings, and coordinate testing activities across teams.

You will guide remediation efforts, implement secure coding standards, and embed security into CI/CD pipelines. The role emphasizes collaboration with development teams and security advocacy across projects.

Qualificações

  • 5+ years of professional experience in software development or application security.
  • Strong knowledge of OWASP Top 10, OWASP ASVS, Secure Coding and Threat Modeling.
  • Experience with OAuth2, OpenID Connect, JWT, API Security and TLS.
  • Proficient in Java/Spring Boot or C#/ .NET with REST APIs.
  • Cloud deployment experience, preferably AWS or Azure.
  • Linux and shell scripting knowledge.
  • Experience with security tools such as SonarQube, Checkmarx, Fortify, Veracode, Snyk, Dependabot, OWASP ZAP, Burp Suite or Trivy.
  • Able to translate security findings into remediation.
  • Strong communication and collaboration as security advisor.

Responsabilidades

  • Define and promote Secure SDLC and Security-by-Design practices.
  • Integrate security requirements into application architecture, design and development.
  • Lead or facilitate Threat Modeling and application security reviews.
  • Analyze and prioritize vulnerabilities identified through SAST, DAST, SCA, container scanning, vulnerability assessments and penetration tests.
  • Coordinate penetration testing activities, including scope definition, external providers, findings validation and remediation follow-up.
  • Provide hands-on support to development teams in vulnerability remediation and secure coding.
  • Promote best practices around authentication, authorization, API security, data protection, cryptography and secrets management.
  • Integrate security controls and automated security testing into CI/CD pipelines, supporting DevSecOps adoption.
  • Develop security guidelines, standards and metrics.
  • Promote security awareness through Secure Coding workshops and Security Champions.

Conhecimentos

Application Security
Threat Modeling
Secure Coding
Java/Spring Boot
C#/ .NET
Cloud Environments
Linux
Shell Scripting
Communication
Security Advocacy
DevSecOps

Ferramentas

SonarQube
Checkmarx
Fortify
Veracode
Snyk
Dependabot
OWASP ZAP
Burp Suite
Trivy

Descrição da oferta de emprego

  • Define and promote Secure SDLC and Security-by-Design practices
  • Integrate security requirements into application architecture, design and development
  • Lead or facilitate Threat Modeling and application security reviews
  • Analyze and prioritize vulnerabilities identified through SAST, DAST, SCA, container scanning, vulnerability assessments and penetration tests
  • Coordinate penetration testing activities, including scope definition, external providers, findings validation and remediation follow-up
  • Provide hands-on support to development teams in vulnerability remediation and secure coding
  • Promote best practices around authentication, authorization, API security, data protection, cryptography and secrets management
  • Integrate security controls and automated security testing into CI/CD pipelines, supporting DevSecOps adoption
  • Develop security guidelines, standards and metrics
  • Promote security awareness through Secure Coding workshops and Security Champions
Requirements
  • 5+ years of professional experience in software development and/or application architecture, with proven experience in Application Security
  • Strong understanding of OWASP Top 10, OWASP ASVS, Secure Coding and Threat Modeling
  • Practical knowledge of OAuth2, OpenID Connect, JWT, API Security, TLS, cryptography and secrets management
  • Strong development experience in Java/Spring Boot or C#/.NET, including REST APIs
  • Solid understanding of cloud environments, with real-world application deployment experience, preferably AWS and/or Azure
  • Good knowledge of Linux and shell scripting
  • Experience with application security tools such as SonarQube, Checkmarx, Fortify, Veracode, Snyk, Dependabot, OWASP ZAP, Burp Suite or Trivy
  • Ability to read and understand source code and application architecture and translate security findings into practical remediation
  • Strong communication and collaboration skills, with the ability to act as a technical advisor and security advocate for development teams
Core Competencies

Demonstrates expertise in Secure SDLC, Threat Modeling, and Application Security, with a strong focus on integrating security practices into software development and architecture. Proficient in vulnerability analysis, secure coding, and promoting security awareness within development teams.

Highest-signal resume keywords
  • Application Security
  • Secure Coding
  • Threat Modeling
  • Java/Spring Boot Development
  • Cloud Environment Deployment
Hard Skills
  • OWASP Top 10
  • OAuth2
  • OpenID Connect
  • API Security
  • TLS
  • Cryptography
  • Java
  • C#
  • Linux
  • Shell Scripting
Soft Skills
  • Strong Communication
  • Collaboration Skills
  • Technical Advising
  • Security Advocacy
Industry Keywords
  • Secure SDLC
  • Security-by-Design
  • Vulnerability Assessment
  • Penetration Testing
  • DevSecOps
Tools & Technologies
  • SonarQube
  • Checkmarx
  • Fortify
  • Veracode
  • Snyk
  • Dependabot
  • OWASP ZAP
  • Burp Suite
  • Trivy
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Application Security Engineer
Application Security Engineer

Expleo • São Domingos de Benfica

Presencial
EUR 55 000 - 90 000
Lead Security Engineer
Lead Security Engineer

Jobtailor • Porto Salvo

Presencial
EUR 90 000 - 130 000
Security Analyst
Security Analyst

act digital EMEA - Alter Solutions • Lisboa

Presencial
EUR 50 000 - 70 000
Application Security Engineer
Application Security Engineer

LUZA Group • Porto

Híbrido
EUR 50 000 - 70 000
Remote work when possible
Equipment provided
Benefits plan
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Coimbra

Híbrido
EUR 95 000 - 138 000
Professional growth
Competitive compensation
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Lisboa

Híbrido
EUR 77 000 - 112 000
Professional growth
Competitive USD-based pay
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Porto

Híbrido
EUR 45 000 - 75 000
Professional growth
Competitive compensation
Exciting projects
+1
Senior DevSecOps & Product Security Engineer
Senior DevSecOps & Product Security Engineer

Doxis • Porto

Híbrido
EUR 70 000 - 110 000
Private healthcare
Udemy memberships
Udemy Business access
+1
AppSec Architect
AppSec Architect

Hexa People • Braga

Presencial
EUR 45 000 - 65 000
Application Security Engineer
Application Security Engineer

Claranet limited • Porto

Presencial
EUR 40 000 - 60 000