Expleo is a trusted partner for your innovation journey. As a global engineering, technology and consulting service provider, we are ideally positioned to help you achieve your ambitions and future-proof your business. With a smart blend of bold thinking and reliable execution, we’re able to fast-track innovation through each step of your value chain.
We are strategically positioned to build value, with a global footprint across 30 countries.
We are as global and local as you need us to be, with strong best-in-class pan-European technological centres and unique best-shoring capabilities.
We leverage a network of high value-adding affiliates in consulting and industrial excellence, and leading partners across multiple sectors to provide you with the most comprehensive services and solutions in an ever-changing environment.
- 5+ years of professional experience in software development and/or application architecture, with proven experience in Application Security.
- Define and promote Secure SDLC and Security-by-Design practices.
- Integrate security requirements into application architecture, design and development.
- Lead or facilitate Threat Modeling and application security reviews.
- Analyze and prioritize vulnerabilities identified through SAST, DAST, SCA, container scanning, vulnerability assessments and penetration tests.
- Coordinate penetration testing activities, including scope definition, external providers, findings validation and remediation follow-up.
- Provide hands-on support to development teams in vulnerability remediation and secure coding.
- Promote best practices around authentication, authorization, API security, data protection, cryptography and secrets management.
- Integrate security controls and automated security testing into CI/CD pipelines, supporting DevSecOps adoption.
- Develop security guidelines, standards and metrics, and promote security awareness through Secure Coding workshops and Security Champions.
- Strong understanding of OWASP Top 10, OWASP ASVS, Secure Coding and Threat Modeling.
- Practical knowledge of OAuth2, OpenID Connect, JWT, API Security, TLS, cryptography and secrets management.
- Strong development experience in Java/Spring Boot or C#/.NET, including REST APIs.
- Solid understanding of cloud environments, with real-world application deployment experience, preferably AWS and/or Azure.
- Good knowledge of Linux and shell scripting.
- Experience with application security tools such as SonarQube, Checkmarx, Fortify, Veracode, Snyk, Dependabot, OWASP ZAP, Burp Suite or Trivy.
- Ability to read and understand source code and application architecture and translate security findings into practical remediation.
- Strong communication and collaboration skills, with the ability to act as a technical advisor and security advocate for development teams.