Start Your Search Here

Job Search

Enfint

Portugal / Global

application security engineer in application security

Job Description

Описание

Extia is a consulting company specialized in IT and digital sectors. Founded in 2007, it combines performance and workplace well-being and operates internationally with more than 2,500 employees.

Задачи

- Contribute to the application security strategy and roadmap within the organization;

- Mentor and support junior Application Security Engineers, promoting knowledge sharing and best practices;

- Drive continuous improvement of the Secure Software Development Lifecycle (S-SDLC) framework;

- Provide expert-level guidance to development teams on application security topics and secure development practices;

- Lead vulnerability analysis, triage, remediation, and follow-up across applications and services;

- Integrate security tools, including SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection, into CI/CD pipelines;

- Lead security awareness initiatives, workshops, and developer training sessions;

- Develop and maintain security documentation, standards, and best practice guidelines;

- Define, monitor, and optimize security metrics, including KPIs, KRIs, and OKRs;

- Conduct threat analysis and technological watch to identify emerging risks and security trends;

- Propose and prototype innovative security solutions and improvements;

- Support automation and continuous improvement of application security processes and tooling.

Требования

- Strong leadership skills with the ability to manage initiatives independently;

- Excellent communication skills and the ability to explain technical topics to diverse audiences;

- Strong teaching and mentoring abilities for developer enablement;

- Analytical and structured problem-solving mindset;

- Ability to influence and drive adoption of security practices across teams;

- Strong documentation and technical writing skills;

- Proactive, autonomous, and improvement-oriented mindset;

- Strong expertise in application security tools and practices, including SAST, DAST, SCA, container scanning, IaC scanning, and secrets detection;

- Experience integrating security controls into CI/CD pipelines;

- Strong programming skills in Python, C++, C#, or similar languages;

- Solid understanding of OWASP Top 10 and common application vulnerabilities;

- Experience in vulnerability analysis, remediation, and false-positive management;

- Knowledge of cloud security across public, private, hybrid, and regulated environments;

- Familiarity with development frameworks such as Angular, Hadoop, or similar;

- Understanding of secure SDLC and DevSecOps practices.

Условия

No conditions specified

#J-18808-Ljbffr

Candidatar-se Now

Similar Opportunities

View all jobs