Application Security Engineer - Hybrid - Lisbon - Mid/Senior

La Fosse

Lisboa

On-site

EUR 85,000 - 110,000

Full time

19 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

La Fosse is seeking a Senior Application Security Engineer to join a highly technical security engineering function protecting complex, cloud-native products. This hands-on role involves securing software from design through deployment, collaborating with software teams to build secure systems, and developing tooling to automate security across the SDLC.

You will mentor developers, lead security initiatives and shape the application security strategy for large-scale, cloud-native environments.

Qualifications

  • Hands-on application security experience.
  • Experience with cloud and containerised environments.
  • Strong understanding of OWASP Top 10 and web app security.
  • Experience threat modelling, security architecture reviews and CI/CD integration.

Responsibilities

  • Conduct vulnerability assessments and application security testing.
  • Review code and identify security vulnerabilities and design weaknesses.
  • Develop security tooling and automate security processes.
  • Integrate security tooling into development and CI/CD workflows.

Skills

Python
Go
Java
Application security
OWASP Top 10
Web app pentesting
Burp Suite
CI/CD security
Cloud security
Kubernetes
Docker
Threat modelling
Security architecture
Influence technical decisions

Education

CISSP
OSCP
SANS certifications

Tools

Burp Suite
Vulnerability scanners
Static analysis tools
SAST tools
Cloud APIs

Job description

We are looking for a Senior Application Security Engineer to join a highly technical security engineering function responsible for protecting complex, cloud-native products.

This is a hands-on engineering role for someone who enjoys getting into the code, architecture and technical detail of security problems.

You will work directly with software engineering teams to identify vulnerabilities, design secure systems, develop security tooling and improve security throughout the software development lifecycle.

The environment is particularly suited to someone who wants to build security solutions rather than simply operate security products.

The role

You will:

  • Drive improvements to application security across large-scale, cloud-native products.
  • Work directly with engineering teams on secure architecture and design.
  • Perform threat modelling and security design reviews.
  • Conduct vulnerability assessments and application security testing.
  • Review code and identify security vulnerabilities and design weaknesses.
  • Develop security tooling and automate security processes.
  • Integrate security tooling into development and CI/CD workflows.
  • Advise developers throughout the software development lifecycle.
  • Provide expertise across application security, cloud security and security architecture.
  • Assess security and privacy requirements for new products and services.
  • Help shape application security strategy and tooling.
  • Mentor developers and security engineers on secure development practices.
  • Lead complex security initiatives from conception through to implementation.
What we're looking for
  • Strong software engineering or application security background.
  • Strong programming capability in Python, Go, Java or a similar language.
  • Hands-on experience with application security.
  • Strong understanding of common web application vulnerabilities, including OWASP Top 10.
  • Experience with web application penetration testing.
  • Experience using tools such as Burp Suite, vulnerability scanners and static analysis tools.
  • Experience automating or integrating security tools.
  • Experience with cloud and containerised environments.
  • Knowledge of AWS, GCP, Kubernetes and/or Docker.
  • Experience with threat modelling, security architecture and design reviews.
  • Understanding of security within distributed systems.
  • Strong understanding of DevSecOps and secure software development.
  • Ability to work directly with developers and influence technical decisions.
  • Security qualifications such as CISSP, OSCP or SANS certifications.
  • Experience with data protection, ISO 27001 or PCI-DSS.
  • Experience working in financial services or another highly regulated environment.
  • Security research, blogging, presentations or open-source contributions.
  • Experience building security tooling or interacting with cloud APIs.
What makes this different?

Security is already deeply embedded in the engineering culture. Developers are technically strong and actively engage with the security team, meaning you can spend your time discussing architecture, code, vulnerabilities and implementation choices rather than trying to convince people that security matters.

The security team is collaborative rather than dogmatic. You will be expected to assess risk, understand the wider business context and prioritise the areas where engineering effort will create the greatest security benefit.

There is also significant greenfield work, giving you the opportunity to influence how security is designed rather than simply maintaining an inherited security stack.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security Engineer - Hybrid - Lisbon - Mid/Senior
Cloud Security Engineer - Hybrid - Lisbon - Mid/Senior

La Fosse • Lisboa

On-site
EUR 70,000 - 100,000
Senior Application Security Engineer
Senior Application Security Engineer

Signify Technology • Lisboa

On-site
EUR 70,000 - 110,000
Security Control Engineer - Lisbon - Hybrid
Security Control Engineer - Lisbon - Hybrid

La Fosse • Lisboa

On-site
EUR 50,000 - 75,000
Lisbon location
Onsite 4 days/week
Security Engineer (a)
Security Engineer (a)

Adnovum • Portugal

On-site
EUR 40,000 - 65,000
Flexible working hours
Continuous education and development
Possibility for part-time work
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Coimbra

Remote
EUR 44,000 - 58,000
Professional growth
Competitive USD-based pay
Exciting projects
+1
Python Engineer (AppSec) ID70123
Python Engineer (AppSec) ID70123

AgileEngine, LLC. • Coimbra

Hybrid
EUR 55,000 - 85,000
Professional growth
Competitive compensation
Exciting projects
+1
Application Security Engineer
Application Security Engineer

emagine • Lisboa

On-site
EUR 55,000 - 75,000
Application Security Engineer
Application Security Engineer

emagine • Portugal

Remote
EUR 45,000 - 65,000
Security certifications encouraged
Application Security Engineer - Cloud & DevOps
Application Security Engineer - Cloud & DevOps

Thought Machine Group Limited • Portugal

On-site
EUR 50,000 - 80,000
Highly competitive salary
Voluntary Pension Plan (match up to 5%)
Private Healthcare Insurance
+3
Security Engineer
Security Engineer

Shakers • Lisboa

On-site
EUR 40,000 - 60,000