Application Security Engineer

Belsoftsolutions

Portugal

Remote

EUR 50,000 - 75,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Belsoftsolutions is seeking a security-minded engineer to audit SaaS apps and Belsoftsolutions' own products, ensuring deployments are secure before release.

You will run hands-on audits of tools built with Lovable, Bolt, Cursor, v0, and Replit; test authentication, access controls, and API routes; review dependencies; and turn findings into automated checks in DeployReady. Strong JavaScript/TypeScript, Node.js, and OWASP Top 10 knowledge are essential.

Qualifications

  • Solid understanding of the OWASP Top 10.
  • Experience reviewing npm packages and dependency risk.
  • Ability to explain vulnerabilities to non-security developers.
  • Proven track record reporting security issues.

Responsibilities

  • Perform hands-on security audits of SaaS products and apps.
  • Test authentication, access control, including IDOR, and API routes.
  • Review npm dependencies and supply-chain risk in Node.js projects.
  • Assess AI features for prompt injection and data leakage.
  • Review Belsoftsolutions' products before release.
  • Write findings reports with fixes and retest.
  • Turn recurring findings into automated checks in DeployReady.

Skills

JavaScript
TypeScript
Node.js
OWASP Top 10
Security testing
Communication

Tools

npm
lockfiles
Supabase
Firebase

Job description

AI coding tools let people ship in a weekend, along with exposed keys, open database rules, and API routes anyone can call. You'll audit those apps and established SaaS products, fix what you find alongside their builders, and make sure every product we build ourselves is secure before we sell it. What you learn feeds into our tooling, including DeployReady, our open-source scanner.

What you'll do
  • Run hands-on security audits of SaaS products and apps built with Lovable, Bolt, Cursor, v0, and Replit
  • Test auth, access control (including IDOR), Supabase/Firebase rules, and API routes
  • Review npm dependencies and supply-chain risk in Node.js and JavaScript projects
  • Assess AI features for prompt injection, data leakage, and over-permissioned tools
  • Review Belsoft's own products and client platforms before release
  • Write clear findings reports with exact fixes, then retest
  • Turn recurring findings into automated checks in our tooling, including DeployReady
What you bring
  • Strong JavaScript/TypeScript and Node.js
  • Solid understanding of the OWASP Top 10 and web application security testing
  • Experience reviewing npm packages, lockfiles, and dependency risk
  • Ability to explain a vulnerability clearly to a non-security developer
  • You've found and responsibly reported real security issues
Nice to have
  • Experience with Supabase, Firebase, or other backend-as-a-service platforms
  • Familiarity with Babel/AST tooling or static analysis
  • LLM security experience, bug bounties, or security certifications
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer for AI-Powered SaaS Apps
Security Engineer for AI-Powered SaaS Apps

Belsoftsolutions • Portugal

Remote
EUR 50,000 - 75,000
Senior Application Security Engineer
Senior Application Security Engineer

Signify Technology • Lisboa

On-site
EUR 70,000 - 110,000
Security Analyst
Security Analyst

act digital EMEA - Alter Solutions • Lisboa

On-site
EUR 50,000 - 70,000
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Coimbra

Remote
EUR 44,000 - 58,000
Professional growth
Competitive USD-based pay
Exciting projects
+1
Application Security Engineer - Hybrid - Lisbon - Mid/Senior
Application Security Engineer - Hybrid - Lisbon - Mid/Senior

La Fosse • Lisboa

On-site
EUR 85,000 - 110,000
Staff Product Security Engineer
Staff Product Security Engineer

Renesas Electronics • Portugal

On-site
EUR 65,000 - 85,000
Senior Application Security Engineer - AI Code Evaluation
Senior Application Security Engineer - AI Code Evaluation

Braintrust • Portugal

Remote
EUR 70,000 - 120,000
Application Security Engineer
Application Security Engineer

emagine • Lisboa

On-site
EUR 55,000 - 75,000
Python Engineer (AppSec) ID70123
Python Engineer (AppSec) ID70123

AgileEngine, LLC. • Aveiro

Hybrid
EUR 107,000 - 134,000
Professional growth
Competitive compensation
Exciting projects
+1
Security Engineer - Node.js Proactive Defense (remote work)
Security Engineer - Node.js Proactive Defense (remote work)

CloudLinux • Lisboa

On-site
EUR 75,000 - 110,000
Fully remote work with flexible hours
Education and training budget
Private medical insurance
+1