Application Security Engineer - Vice President

iCapital Network

Lisboa

Híbrido

EUR 120 000 - 180 000

Tempo integral

Há 2 dias
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

iCapital Network in Lisbon seeks an Application Security Engineer - Vice President to own secure design practices and drive shift-left security across the org.

You will lead API security efforts, work with developers on SAST/SCA remediation, and build scalable security automation in Python. The role requires deep expertise in threat modeling, OWASP Top 10, and cloud-native environments, with strong collaboration across engineering and product teams.

Qualificações

  • Hands-on experience across secure design, threat modeling, API security, and offensive security.
  • Penetration testing experience and solid understanding of real-world attack patterns.
  • OWASP Top 10 familiarity in practice.
  • API security depth with REST and GraphQL APIs.
  • Proficiency in Python, able to build automation tools.
  • Experience in shift-left programs: security in CI/CD and developer enablement.
  • Comfort reading code across languages and working with engineering teams.
  • Exposure to AI-assisted security tooling or LLM security is a differentiator.
  • Developer background; fluency in Ruby, Python, Scala is a plus.

Responsabilidades

  • Help build and mature the Secure Design and Threat Modeling program, defining methodology and review standards.
  • Drive shift-left security initiatives and embed security earlier in the development lifecycle.
  • Own API security as a discipline and lead related initiatives.
  • Support offensive security activities and vulnerability management.
  • Build and maintain security automation in Python and scalable tooling.
  • Collaborate with developers on SAST/SCA remediation and feedback loop optimization.
  • Contribute to AI-assisted security pipelines and establish escalation paths.

Conhecimentos

Secure design
Threat modeling
API security
Offensive security
Penetration testing
OWASP Top 10
CI/CD security
Python
Cloud-native
Architecture depth
Ruby
Scala

Ferramentas

SAST tooling
SCA tooling

Descrição da oferta de emprego

Application Security Engineer - Vice President

Lisbon, Portugal

About the role:

We are looking for a technically strong Senior Application Security practitioner ready to take on real ownership. You will work directly with the Head of AppSec, contributing to the Secure Design practice and helping drive shift-left security across the organization.

What You'll Do

  • Help build and mature the Secure Design and Threat Modeling program by defining methodology, review standards, and sign-off criteria across the organization
  • Drive shift-left security initiatives, embedding security earlier in the development lifecycle through design reviews, developer enablement, and security gating in CI/CD
  • Own API security as a discipline
  • Support offensive security initiatives
  • Build and maintain security automation in Python, tooling that scales AppSec capacity
  • Work directly with developers on SAST and SCA remediation, scan optimization, and reducing friction in the security feedback loop
  • Contribute to AI-assisted security pipelines; define escalation paths, SLAs, and accountability structures for vulnerability management

What We're Looking For

  • Hands-on experience across secure design, threat modeling, API security, and offensive security
  • Offensive security capability with penetration testing experience and solid understanding of real-world attack and API exploitation patterns
  • Deep familiarity with OWASP Top 10 in practice
  • API security depth, experience assessing REST and GraphQL APIs
  • Python proficiency, comfortable building automation tools that others will depend on
  • Experience in shift-left programs: security in CI/CD, developer enablement, design review processes
  • Understanding of web application and API security
  • Comfortable reading code across languages and engaging with engineering teams at technical depth
  • Familiarity with cloud-native environments and attack surface management
  • Demonstrated ability to influence across engineering and product and operate at architecture level
  • Relevant certifications are a plus: OSCP, OSWE, GWEB, CSSLP, CISSP, CEH
  • Exposure to AI-assisted security tooling or LLM security is a differentiator
  • Experience as a developer and fluency in Ruby, Python, and Scala are a plus

We believe the best ideas and innovation happen when we are together. Employees in this role will work in the office four days, with the flexibility to work remotely one day (Friday).

iCapital offers a comprehensive benefits package that includes a total compensation program consisting of competitive salary, annual performance bonus, and equity for all full-time employees; healthcare with 100% employer-paid health and dental insurance; and generous paid time off (PTO).

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

VP of Application Security & Secure Design
VP of Application Security & Secure Design

iCapital Network • Lisboa

Híbrido
EUR 120 000 - 180 000
Application Security Engineer | Lisbon | Hybrid
Application Security Engineer | Lisbon | Hybrid

Decskill • Lisboa

Presencial
EUR 90 000 - 130 000
Application Security Engineer
Application Security Engineer

emagine • Lisboa

Híbrido
EUR 65 000 - 95 000
Senior AppSec Engineer — Lisbon Onsite 4x/Week
Senior AppSec Engineer — Lisbon Onsite 4x/Week

Thought Machine • Lisboa

Presencial
EUR 60 000 - 80 000
Highly competitive salary
Voluntary Pension Plan (match up to 5%)
Private Healthcare Insurance
+7
Application Security Engineer
Application Security Engineer

ITDS • Porto

Híbrido
EUR 60 000 - 90 000
Application Security
Application Security

WIRE IT • Porto

Híbrido
EUR 40 000 - 60 000
Health Insurance
22 days of paid vacation
4 extra days annually (Carnival, Christmas Eve, New Year's Eve, Birthday)
+6
Application Security Engineer: Secure SDLC & DevSecOps
Application Security Engineer: Secure SDLC & DevSecOps

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 45 000 - 65 000
Application Security Engineer
Application Security Engineer

Claranet limited • Porto

Presencial
EUR 40 000 - 60 000
Application Security Engineer
Application Security Engineer

Movilges • Porto

Híbrido
EUR 40 000 - 64 000
Health insurance
Life insurance
Birthday day
+2
Application Security Engineer — Cloud & DevSecOps
Application Security Engineer — Cloud & DevSecOps

Thought Machine • Lisboa

Presencial
EUR 50 000 - 75 000
Highly competitive salary
Voluntary Pension Plan
Private Healthcare Insurance
+3