Unlock Full Resume Report

New offer - be the first one to apply!

September 2, 2026

Application Security Engineer

Senior • On-site

Lisbon, Portugal

Mission

Ensure that products and applications incorporate security principles from design through operation. Promote secure development practices, coordinate vulnerability assessments and penetration testing, support development teams with risk remediation, and contribute to the continuous evolution of application security maturity.

Intended Profile

Professional with previous experience in software development and application architecture who has evolved into application security functions. Able to work with development, architecture, operations and corporate security teams as a technical consultant, facilitator and promoter of good practices.

Able to understand code, architecture and development processes, and directly support the analysis and resolution of identified vulnerabilities.

Responsibilities

  • Define and promote Secure SDLC practices.
  • Integrate security requirements into the development cycle.
  • Participate in architecture reviews and solution design.
  • Conduct threat-modeling sessions.
  • Support teams in implementing authentication, authorization and data-protection mechanisms.
  • Analyze results from penetration tests, vulnerability assessments, SAST, DAST, dependency scanning and container scanning.
  • Classify and prioritize vulnerabilities.
  • Provide technical remediation support.
  • Monitor remediation plans and their SLAs.
  • Define the scope of penetration tests.
  • Coordinate with external vendors.
  • Deliver Secure Coding workshops.
  • Promote OWASP Top 10 and secure development best practices.
  • Integrate security controls into CI/CD pipelines.
  • Define application-security metrics and indicators.

Key Requirements

  • Solid experience in at least one of these stacks: Java, Spring Boot, REST APIs and Maven; or C#, .NET Framework/.NET Core and ASP.NET.
  • Required cloud knowledge, including experience with real application deployments.
  • Working knowledge of OWASP Top 10, OWASP ASVS and Secure Coding best practices.
  • Experience with tools such as SonarQube, Checkmarx, Fortify, Veracode and Snyk.
  • Strong communication and influence skills without hierarchical authority.
  • Training and mentoring skills.
  • Ability to work effectively with development teams.

Nice to Have

  • Frontend experience with Angular, JavaScript and TypeScript.
  • Knowledge of a major cloud platform, preferably AWS and/or Azure.
  • Strong analytical skills.
  • Pragmatic approach to risk management.

Similar jobs you might like