Application Security Engineer

IQVIA, Inc.

Portugal

Presencial

EUR 60 000 - 80 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

IQVIA, Inc. seeks an Application Security / DevSecOps Specialist in Portugal, responsible for enhancing security practices within the software development lifecycle. This hands-on role involves collaboration with various teams to implement CI/CD security controls and support secure application development.

The ideal candidate will have 6-8 years of relevant experience and a Bachelor's degree in Computer Science or similar. The role demands experience with cloud environments, CI/CD tooling, and a strong understanding of secure coding and application security practices.

Qualificações

  • Minimum 6-8 years in Application Security, DevSecOps, Software Engineering, or related fields.
  • Experience with CI/CD pipelines and integrating security into deployment workflows.
  • Knowledge of secure coding principles and application security testing techniques.

Responsabilidades

  • Drive adoption of CI/CD security controls.
  • Support application security assessments and security design reviews.
  • Act as a security point of contact for development teams.

Conhecimentos

Application Security
DevSecOps
CI/CD pipelines
Cloud Security
Python scripting
Kubernetes
Secure coding practices

Formação académica

Bachelor's degree in Computer Science or related field

Ferramentas

SAST
DAST
Infrastructure-as-code security
Microsoft Azure
Amazon AWS

Descrição da oferta de emprego

Role and Responsibilities

The Application Security / DevSecOps Specialist role presents a hands on opportunity to support and scale IQVIA's global Application Security and DevSecOps capabilities. We are deepening our DevSecOps capabilities, maturing AI security governance, and embedding security earlier into the software development lifecycle across a complex global environment - including cloud-native platforms, containerized workloads, third‑party SaaS, and AI‑enabled systems. This role is for a technically strong, practitioner‑level leader who can operate at the intersection of engineering and security architecture. You will not only assess and advise – you will build, automate, and drive adoption of secure‑by‑design practices across IQVIA's global delivery teams. You will sit within the global Information Security organization, collaborating closely with Security Architecture, Cloud Security, Vulnerability Management, and DevOps platform teams, as well as directly with product engineering and delivery teams across business units and regions.

  • Drive adoption and ownership of CI/CD security controls across product engineering teams, including tooling configuration, findings triage, pipeline onboarding, and remediation follow‑through.
  • Provide follow‑up support for CI/CD security requests, including assisting teams with pipeline security tooling, configuration issues, findings remediation, and onboarding to DevSecOps services.
  • Support application security assessments and security design reviews, working with delivery and architecture teams to identify risks, define mitigations, and track remediation actions.
  • Act as a security point of contact for development teams, providing consultancy and guidance on secure coding practices, SDLC requirements, and secure architecture patterns.
  • Review and assess application architectures, including cloud‑native, microservices, APIs, containerized workloads, and event-driven systems, with an architectural security mindset.
  • Support cloud application deployments and architecture patterns across Microsoft Azure and Amazon AWS, focusing on secure configuration, identity, network controls, and workload security.
  • Contribute to the implementation and operationalization of DevSecOps practices, including SAST, DAST, SCA, container scanning, secret detection, and infrastructure‑as‑code security.
  • Develop and maintain Python scripts and automations to support security checks, data analysis, reporting, or CI/CD integrations where appropriate.
  • Support and contribute to AI Security for Development, including guidance on securing AI/ML architectures, protecting training pipelines, managing model risks, securing LLM prompt workflows, and addressing data leakage, model abuse, and agentic system risks.
  • Assist in defining and maintaining security standards, requirements, and guidance related to application security, DevSecOps, cloud development, and AI-enabled systems.
  • Collaborate closely with Security Architecture, Cloud Security, Vulnerability Management, and DevOps platform teams to ensure alignment with IQVIA security frameworks and toolsets.
  • Track, follow up, and support security findings remediation, ensuring issues identified through assessments or pipeline tools are addressed effectively by delivery teams.
  • Help promote Security by Design and Shift-Left principles, supporting teams early in design and development phases rather than late-stage security enforcement.
Required Experience and Qualifications
  • Minimum of 6‑8 years of professional experience in Application Security, DevSecOps, Software Engineering, Cloud Engineering, or related technical security roles.
  • Hands on experience with CI/CD pipelines and DevSecOps tooling, including integrating security controls into build and deployment workflows.
  • Working knowledge of application security testing techniques such as SAST, DAST, SCA, container scanning, and infrastructure-as-code security.
  • Experience with cloud environments (Microsoft Azure and/or Amazon AWS), including deploying and securing applications in IaaS and PaaS platforms.
  • Experience with containerized and modern application architectures, including Kubernetes, microservices, APIs, and event driven systems.
  • Practical scripting experience, preferably in Python, for automation, integrations, or security tooling support.
  • Knowledge of secure software development practices, OWASP Top 10, common application attack patterns, and secure coding principles.
  • Foundational to intermediate knowledge of AI and ML security considerations, including Agent development, model risk, data protection, pipeline security, and misuse/abuse scenarios.
  • Bachelor’s degree in Computer Science, Software Engineering, Information Security, or equivalent practical experience is preferred.
  • Security or cloud certifications (such as CSSLP, GWAPT, AWS/Azure Security, CKAD/CKS, or equivalent) are preferred but not mandatory.
  • Working knowledge of security frameworks and standards such as NIST, OWASP, ISO 27001, or similar is an advantage.
  • Strong communication skills, with the ability to work directly with engineering teams and explain security concepts in a practical, delivery focused manner.

At IQVIA, we believe that diversity, inclusion, and belonging empower our mission to accelerate innovation for a healthier world. We create a culture of belonging by valuing the perspectives of all talented employees worldwide and providing them with the opportunity to power smarter healthcare for everyone, everywhere. When our talented employees bring their authentic selves and their diverse experiences to work, they enable us to accomplish extraordinary things. Multifaceted thought processes spark innovation. Multi-talented collaboration harnesses innovation to deliver superior outcomes. Likewise, as part of this culture, IQVIA is committed to ensuring effective equality between women and men, integrating it as a strategic principle in its corporate and human resources policies.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Application Security Engineer
Application Security Engineer

IQVIA LLC • Porto

Presencial
EUR 45 000 - 70 000
Diversity & Inclusion programs
Professional development opportunities
Health benefits
Associate Director, Security Architect
Associate Director, Security Architect

IQVIA, Inc. • Portugal

Híbrido
EUR 80 000 - 120 000
Associate Director, Security Architect
Associate Director, Security Architect

IQVIA • Oeiras

Presencial
EUR 80 000 - 100 000
DevSecOps & Application Security Engineer (Cloud & AI)
DevSecOps & Application Security Engineer (Cloud & AI)

IQVIA, Inc. • Portugal

Presencial
EUR 60 000 - 80 000
Associate Director, Security Architect
Associate Director, Security Architect

IQVIA LLC • Porto

Presencial
EUR 80 000 - 120 000
Senior DevSecOps & Application Security Engineer
Senior DevSecOps & Application Security Engineer

IQVIA LLC • Porto

Presencial
EUR 45 000 - 70 000
Diversity & Inclusion programs
Professional development opportunities
Health benefits
Senior Security Engineer: AI & DevSecOps
Senior Security Engineer: AI & DevSecOps

act digital • Portugal

Presencial
EUR 70 000 - 120 000
.Net Software Architect
.Net Software Architect

IQVIA • Oeiras

Presencial
EUR 70 000 - 110 000
Security Architect
Security Architect

Chain IQ • Portugal

Presencial
EUR 70 000 - 90 000
AI Security Engineer
AI Security Engineer

Planck Technologies • Lisboa

Presencial
EUR 70 000 - 100 000