Application Security Engineer

Job Locations
PT-11-Lisbon
Job area
IT & Digital
Employment type
Permanent
Workplace
Hybrid

Overview

Expleo is a trusted partner for your innovation journey. As a global engineering, technology and consulting service provider, we are ideally positioned to help you achieve your ambitions and future-proof your business. With a smart blend of bold thinking and reliable execution, we’re able to fast-track innovation through each step of your value chain.
We are strategically positioned to build value, with a global footprint across 30 countries.
We are as global and local as you need us to be, with strong best-in-class pan-European technological centres and unique best-shoring capabilities.
We leverage a network of high value-adding affiliates in consulting and industrial excellence, and leading partners across multiple sectors to provide you with the most comprehensive services and solutions in an ever-changing environment.

Responsibilities

- 5+ years of professional experience in software development and/or application architecture, with proven experience in Application Security.

- Define and promote Secure SDLC and Security-by-Design practices.

- Integrate security requirements into application architecture, design and development.

- Lead or facilitate Threat Modeling and application security reviews.

- Analyze and prioritize vulnerabilities identified through SAST, DAST, SCA, container scanning, vulnerability assessments and penetration tests.

- Coordinate penetration testing activities, including scope definition, external providers, findings validation and remediation follow-up.

- Provide hands-on support to development teams in vulnerability remediation and secure coding.

- Promote best practices around authentication, authorization, API security, data protection, cryptography and secrets management.

- Integrate security controls and automated security testing into CI/CD pipelines, supporting DevSecOps adoption.

- Develop security guidelines, standards and metrics, and promote security awareness through Secure Coding workshops and Security Champions.

Essential skills

- Strong understanding of OWASP Top 10, OWASP ASVS, Secure Coding and Threat Modeling.

- Practical knowledge of OAuth2, OpenID Connect, JWT, API Security, TLS, cryptography and secrets management.

- Strong development experience in Java/Spring Boot or C#/.NET, including REST APIs.

- Solid understanding of cloud environments, with real-world application deployment experience, preferably AWS and/or Azure.

- Good knowledge of Linux and shell scripting.

- Experience with application security tools such as SonarQube, Checkmarx, Fortify, Veracode, Snyk, Dependabot, OWASP ZAP, Burp Suite or Trivy.

- Ability to read and understand source code and application architecture and translate security findings into practical remediation.

- Strong communication and collaboration skills, with the ability to act as a technical advisor and security advocate for development teams.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share to social media

Can't find the job of your choice?
Upload your C.V. / Resume here for our recruiters to view.