Emagine is seeking an Application Security Engineer to join a collaborative and dynamic project environment. This is an opportunity for an experienced application security professional to strengthen application security practices through penetration testing, security assessments, and the integration of security tools into CI/CD pipelines.
What You\'ll Be Working On
- Plan and conduct penetration tests on internal applications and deliver clear, detailed reports.
- Produce security assessment reports covering risk assessment, vulnerability impact, exploitation steps, and actionable remediation guidance.
- Integrate SAST, DAST, and SCA scanning into CI/CD pipelines and support developers in using these tools effectively.
- Troubleshoot and resolve CI/CD issues related to security scanning, including Jenkins configuration, scanner failures, authentication issues, and pipeline execution errors.
- Support development teams with threat modelling, security reviews, and pre-release security assessments.
- Help development teams resolve security blockers before application releases.
- Define and standardise security engagement procedures and promote secure development practices.
- Act as a trusted security partner to engineering teams, providing practical and constructive security guidance.
What We\'re Looking For
- Proven experience performing penetration tests on web applications and APIs.
- Hands-on experience with SAST, DAST, and SCA tools and their integration into CI/CD pipelines.
- Working knowledge of CI/CD platforms, ideally Jenkins, including troubleshooting pipeline and security scanner integration issues.
- Experience with threat modelling and secure design reviews.
- Strong understanding of common vulnerability classes, including OWASP Top 10, and remediation techniques.
- Excellent written communication skills, with the ability to produce clear and structured security reports for technical and non-technical audiences.
- Ability to train and collaborate with developers and explain security issues in a practical and constructive way.
- Strong autonomy and initiative when identifying and addressing security challenges.
- Professional fluency in English.
- Short availability to start the project.
Nice to Have
- Security certifications such as OSCP, GWAPT, CEH, or CSSLP.
- Experience defining or improving security processes and governance.
- Scripting or programming skills such as Python or Bash for automation.
- Familiarity with cloud and containerised environments.
Location & Eligibility
- Candidates must be based in Portugal.
- Remote working model with flexible working hours.
- 8-9 month project
- Candidates should be available to start ASAP.
About Emagine
At emagine, we value diversity, inclusion, and equal opportunities. We believe that different perspectives drive innovation and create stronger teams, and we are committed to fostering an inclusive environment where everyone can thrive. We work with leading international clients on innovative and high-impact projects, offering opportunities to grow both professionally and personally. If you are interested in this opportunity, we encourage you to apply and become part of a dynamic and forward-thinking environment.
To learn more about us, visit our website: www.emagine-consulting.com