application security engineer in fintech

HireHi

Portugal

Híbrido

EUR 90 000 - 130 000

Tempo integral

Há 2 dias
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Destaca-te para esta função — cria um currículo personalizado e uma carta de apresentação em cerca de um minuto.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Health and dental insurance
Equity
Paid time off

Resumo da oferta

HireHi is seeking a technically strong Senior Application Security practitioner to own and mature the Secure Design program. You will work with the Head of AppSec to drive shift-left initiatives, review design, and integrate security into CI/CD.

You will own API security, assist with offensive security, and build Python-based automation to scale AppSec capacity. You will collaborate with developers on SAST/SCA remediation, optimize scans, and help define AI-assisted security pipelines and

Qualificações

  • Hands-on experience across secure design, threat modeling, API security, and offensive security.
  • Penetration testing experience with real-world API exploitation patterns.
  • Deep familiarity with OWASP Top 10 in practice.
  • Experience assessing REST and GraphQL APIs.
  • Proficiency in Python; able to build automation tools.
  • Experience in shift-left programs (CI/CD, developer enablement, and design reviews).
  • Understanding of web application and API security; read code across languages.
  • Familiarity with cloud-native environments and attack surface management.
  • Ability to influence across engineering and product at architecture level.
  • Nice-to-have: OSCP, OSWE, GWEB, CISSP, CEH; exposure to AI-assisted security tooling.

Responsabilidades

  • Build and mature the Secure Design and Threat Modeling program by defining methodology, review standards, and sign-off criteria across the organization
  • Drive shift-left security initiatives by embedding security earlier in the development lifecycle through design reviews, developer enablement, and security gating in CI/CD
  • Own API security as a discipline
  • Support offensive security initiatives
  • Build and maintain security automation in Python to scale AppSec capacity
  • Work directly with developers on SAST and SCA remediation, scan optimization, and reducing friction in the security feedback loop
  • Contribute to AI-assisted security pipelines and define escalation paths, SLAs, and accountability structures for vulnerability management

Conhecimentos

Secure design
Threat modeling
API security
Offensive security
Penetration testing
OWASP Top 10
REST/GraphQL
Python automation
CI/CD security

Ferramentas

Python Automation Tools

Descrição da oferta de emprego

Описание

We are looking for a technically strong Senior Application Security practitioner ready to take on real ownership. You will work directly with the Head of AppSec, contributing to the Secure Design practice and helping drive shift-left security across the organization.

Задачи
  • Build and mature the Secure Design and Threat Modeling program by defining methodology, review standards, and sign-off criteria across the organization
  • Drive shift-left security initiatives by embedding security earlier in the development lifecycle through design reviews, developer enablement, and security gating in CI/CD
  • Own API security as a discipline
  • Support offensive security initiatives
  • Build and maintain security automation in Python to scale AppSec capacity
  • Work directly with developers on SAST and SCA remediation, scan optimization, and reducing friction in the security feedback loop
  • Contribute to AI-assisted security pipelines and define escalation paths, SLAs, and accountability structures for vulnerability management
Требования
  • Hands-on experience across secure design, threat modeling, API security, and offensive security
  • Penetration testing experience and a solid understanding of real-world attack and API exploitation patterns
  • Deep familiarity with OWASP Top 10 in practice
  • Experience assessing REST and GraphQL APIs
  • Proficiency in Python and ability to build automation tools others can depend on
  • Experience in shift-left programs, including security in CI/CD, developer enablement, and design review processes
  • Understanding of web application and API security
  • Ability to read code across languages and engage with engineering teams at technical depth
  • Familiarity with cloud-native environments and attack surface management
  • Ability to influence across engineering and product and operate at architecture level
  • Будет плюсом: OSCP, OSWE, GWEB, CSSLP, CISSP, or CEH certifications, exposure to AI-assisted security tooling or LLM security, experience as a developer, fluency in Ruby, Python, and Scala
Условия
  • Employees in this role work in the office four days and remotely one day (Friday)
  • Competitive salary, annual performance bonus, and equity for full-time employees
  • 100% Employer-paid health and dental insurance
  • Generous paid time off (PTO)
Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

application security engineer in application security
application security engineer in application security

Enfint • Lisboa

Presencial
EUR 70 000 - 90 000
application security engineer for cloud software
application security engineer for cloud software

Enfint • Lisboa

Presencial
EUR 55 000 - 75 000
Senior Application Security Engineer
Senior Application Security Engineer

Signify Technology • Lisboa

Presencial
EUR 70 000 - 110 000
security engineer in AI products
security engineer in AI products

HireHi • Lisboa

Presencial
EUR 45 000 - 75 000
Apple hardware ecosystem
Annual bonus
Health and life insurance
+7
application security engineer
application security engineer

Enfint • Lisboa

Presencial
EUR 45 000 - 65 000
security engineer in fintech
security engineer in fintech

HireHi • Lisboa

Híbrido
EUR 60 000 - 90 000
Hybrid Work Policy
Green Transportation Budget
Electric bikes
+4
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Lisboa

Híbrido
EUR 77 000 - 112 000
Professional growth
Competitive USD-based pay
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Porto

Presencial
EUR 45 000 - 75 000
Professional growth
Competitive compensation
Exciting projects
+1
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Coimbra

Presencial
EUR 95 000 - 138 000
Professional growth
Competitive compensation
Exciting projects
+1
python developer in DevSecOps
python developer in DevSecOps

Enfint • Lisboa

Presencial
EUR 77 000 - 103 000
USD pay
Education budget
Fitness budget
+2