Devoteam Cyber Trust | Application Security Engineer | FinTech Sector
Devoteam · Lisboa · Remoto
Sobre a função
We are looking for a Senior Application Security Consultant to join our Application Security team. In this role, you will help strengthen the security posture of modern applications by integrating security throughout the software development lifecycle. You will collaborate closely with engineering teams to identify, assess, and remediate security vulnerabilities while promoting secure development practices and DevSecOps principles.
This is an excellent opportunity for an experienced Application Security professional who enjoys working in a collaborative, cloud-native environment with a strong focus on automation and continuous improvement.
Key Responsibilities
- Drive application security initiatives across the software development lifecycle (SDLC).
- Identify, assess, prioritize, and support the remediation of application security vulnerabilities.
- Partner with engineering teams to promote secure coding practices and security-by-design principles.
- Integrate security testing tools and controls into CI/CD pipelines.
- Review source code and provide security recommendations during development.
- Support secure design reviews and threat modeling activities.
- Improve and automate security processes using modern AppSec and DevSecOps tools.
- Contribute to the continuous evolution of the organization's application security program.
- Minimum of 4 years of experience in Application Security or a related cybersecurity role.
- Strong knowledge of Application Security fundamentals, including:
- OWASP Top 10
- Common Weakness Enumeration (CWE)
- Secure Design Principles
- Web and API vulnerability remediation
- Experience with Application Security tooling such as:
- SAST
- DAST
- SCA
- Snyk
- Semgrep
- Checkmarx
- SonarQube
- OWASP Dependency-Check
- OWASP ZAP
- Trivy
- Experience integrating automated security controls into CI/CD pipelines using tools such as Jenkins, GitHub Actions, or GitLab CI.
- Experience performing vulnerability analysis, triage, prioritization, and providing remediation guidance to development teams.
- Ability to read and analyze source code with hands-on experience in at least one programming language such as Java, Python, or Go.
- Working knowledge of cloud security concepts in AWS, Azure, or GCP, including:
- IAM roles and permissions
- Security Groups
- VPCs
- Common cloud configuration risks
- Fluent English (spoken and written).
Preferred Qualifications
- Experience working within FinTech or Enterprise SaaS environments.
- Knowledge of security compliance frameworks such as:
- SOC 2
- ISO 27001
- PCI DSS
- Experience leveraging GenAI/LLMs to improve Application Security processes or developer productivity.
- Practical experience conducting threat modeling using methodologies such as STRIDE.
- Hands-on experience with containerized environments using Docker and Kubernetes.
- Offensive security experience, including penetration testing, red teaming, bug bounty participation, Capture The Flag (CTF) competitions, or certifications such as OSCP or eJPT.
What We're Looking For
- Strong analytical and problem-solving skills.
- Excellent communication and stakeholder management abilities.
- Collaborative mindset with experience working alongside software engineering teams.
- Passion for secure software development and continuous improvement.
- Ability to thrive in a remote, fast-paced, and technology-driven environme
The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.
Join us in our mission to safeguard our clients' critical digital assets by applying deep technical expertise to their most strategic projects.
Apply now to become a key technical leader in this pivotal engagement and make a tangible impact as a key member of our Cybersecurity Engineering Professional Services team!