Application Security Engineer

Expleo

São Domingos de Benfica

Presencial

EUR 55 000 - 90 000

Tempo integral

Há 5 dias
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Expleo is seeking a seasoned Application Security Expert in Portugal to join its engineering and consulting practice. You will define and promote Secure SDLC, lead threat modeling, and help integrate security into CI/CD.

The role requires 5+ years in software development or application architecture with security focus, hands-on experience with OAuth2, OWASP, and cloud deployments (AWS/Azure), and hands-on use of tools like SonarQube, Checkmarx, and Burp Suite.

Qualificações

  • 5+ years of experience in software development and/or application architecture with security focus.
  • Strong knowledge of OWASP Top 10 and secure coding practices.
  • Experience with threat modeling and security reviews.

Responsabilidades

  • Define and promote Secure SDLC and Security-by-Design practices.
  • Lead threat modeling and security reviews for applications.
  • Identify and remediate vulnerabilities from SAST/DAST/IAST and pentests.
  • Integrate security controls into CI/CD pipelines for DevSecOps.
  • Provide guidance to development teams on secure coding and data protection.

Conhecimentos

OWASP Top 10
OAuth2/OpenID Connect
Java/Spring Boot
C#/ASP.NET
Cloud: AWS/Azure
Security tools: Snyk/Veracode/ZAP

Ferramentas

SonarQube
Checkmarx
Fortify
Veracode
OWASP ZAP
Burp Suite
Trivy

Descrição da oferta de emprego

Overview

Expleo is a trusted partner for your innovation journey. As a global engineering, technology and consulting service provider, we are ideally positioned to help you achieve your ambitions and future-proof your business. With a smart blend of bold thinking and reliable execution, we’re able to fast-track innovation through each step of your value chain.We are strategically positioned to build value, with a global footprint across 30 countries.We are as global and local as you need us to be, with strong best-in-class pan-European technological centres and unique best-shoring capabilities.We leverage a network of high value-adding affiliates in consulting and industrial excellence, and leading partners across multiple sectors to provide you with the most comprehensive services and solutions in an ever-changing environment.

Responsibilities
  • 5+ years of professional experience in software development and/or application architecture, with proven experience in Application Security.
  • Define and promote Secure SDLC and Security-by-Design practices.
  • Integrate security requirements into application architecture, design and development.
  • Lead or facilitate Threat Modeling and application security reviews.
  • Analyze and prioritize vulnerabilities identified through SAST, DAST, SCA, container scanning, vulnerability assessments and penetration tests.
  • Coordinate penetration testing activities, including scope definition, external providers, findings validation and remediation follow-up.
  • Provide hands‑on support to development teams in vulnerability remediation and secure coding.
  • Promote best practices around authentication, authorization, API security, data protection, cryptography and secrets management.
  • Integrate security controls and automated security testing into CI/CD pipelines, supporting DevSecOps adoption.
  • Develop security guidelines, standards and metrics, and promote security awareness through Secure Coding workshops and Security Champions.
Essential skills
  • Strong understanding of OWASP Top 10, OWASP ASVS, Secure Coding and Threat Modeling.
  • Practical knowledge of OAuth2, OpenID Connect, JWT, API Security, TLS, cryptography and secrets management.
  • Strong development experience in Java/Spring Boot or C#/.NET, including REST APIs.
  • Solid understanding of cloud environments, with real-world application deployment experience, preferably AWS and/or Azure.
  • Good knowledge of Linux and shell scripting.
  • Experience with application security tools such as SonarQube, Checkmarx, Fortify, Veracode, Snyk, Dependabot, OWASP ZAP, Burp Suite or Trivy.
  • Ability to read and understand source code and application architecture and translate security findings into practical remediation.
  • Strong communication and collaboration skills, with the ability to act as a technical advisor and security advocate for development teams.
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Application Security Engineer
Application Security Engineer

Jobtailor • Lisboa

Presencial
EUR 60 000 - 80 000
AI Security Specialist/Architect
AI Security Specialist/Architect

Expleo Group • Lisboa

Presencial
EUR 45 000 - 65 000
Senior AppSec Engineer: Secure SDLC & DevSecOps
Senior AppSec Engineer: Secure SDLC & DevSecOps

Expleo • São Domingos de Benfica

Presencial
EUR 55 000 - 90 000
Security Analyst
Security Analyst

act digital EMEA - Alter Solutions • Lisboa

Presencial
EUR 50 000 - 70 000
AI Security Specialist/Architect
AI Security Specialist/Architect

Expleo • Lisboa

Presencial
EUR 60 000 - 90 000
AI Security Engineer
AI Security Engineer

Expleo • São Domingos de Benfica

Presencial
EUR 65 000 - 95 000
AI Security Engineer
AI Security Engineer

Expleo Group • Lisboa

Presencial
EUR 70 000 - 110 000
Application Security Engineer
Application Security Engineer

LUZA Group • Porto

Híbrido
EUR 50 000 - 70 000
Remote work when possible
Equipment provided
Benefits plan
Application Security Engineer
Application Security Engineer

emagine • Lisboa

Híbrido
EUR 65 000 - 95 000
application security engineer in application security
application security engineer in application security

Enfint • Lisboa

Presencial
EUR 70 000 - 90 000