Start Your Search Here

Job Search

Enfint

pt / Global

application security engineer in application security

Job Description

Описание

Extia is a consulting company specialized in IT and digital sectors. Founded in 2007, it combines performance and workplace well-being and operates internationally with more than 2,500 employees.

Задачи

Contribute to the application security strategy and roadmap within the organization;

Mentor and support junior Application Security Engineers, promoting knowledge sharing and best practices;

Drive continuous improvement of the Secure Software Development Lifecycle (S-SDLC) framework;

Provide expert-level guidance to development teams on application security topics and secure development practices;

Lead vulnerability analysis, triage, remediation, and follow-up across applications and services;

Integrate security tools, including SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection, into CI/CD pipelines;

Lead security awareness initiatives, workshops, and developer training sessions;

Develop and maintain security documentation, standards, and best practice guidelines;

Define, monitor, and optimize security metrics, including KPIs, KRIs, and OKRs;

Conduct threat analysis and technological watch to identify emerging risks and security trends;

Propose and prototype innovative security solutions and improvements;

Support automation and continuous improvement of application security processes and tooling.

Требования

Strong leadership skills with the ability to manage initiatives independently;

Excellent communication skills and the ability to explain technical topics to diverse audiences;

Strong teaching and mentoring abilities for developer enablement;

Analytical and structured problem-solving mindset;

Ability to influence and drive adoption of security practices across teams;

Strong documentation and technical writing skills;

Proactive, autonomous, and improvement-oriented mindset;

Strong expertise in application security tools and practices, including SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection;

Experience integrating security controls into CI/CD pipelines;

Strong programming skills in Python, C++, C#, or similar languages;

Solid understanding of OWASP Top 10 and common application vulnerabilities;

Experience in vulnerability analysis, remediation, and false-positive management;

Knowledge of cloud security across public, private, hybrid, and regulated environments;

Familiarity with development frameworks such as Angular, Hadoop, or similar;

Understanding of secure SDLC and DevSecOps practices.

Условия

No conditions specified

#J-18808-Ljbffr

Candidatar-se Now

Similar Opportunities

View all jobs