Devoteam Cyber Trust | Application Security Engineer | Mobility Sector

Devoteam


Job Location:

Lisbon - Portugal

Monthly Salary: Not Disclosed
Posted on: 7 hours ago
Vacancies: 1 Vacancy

Job Summary

Mission

Ensure that products and applications developed by the organization incorporate security principles from inception to operations promoting secure development practices coordinating vulnerability assessments and penetration tests providing technical support to development teams for risk remediation and contributing to the continuous evolution of application security maturity.

Responsibilities

Application Security

  • Define and promote Secure SDLC practices.

  • Integrate security requirements into the development lifecycle.

  • Participate in architecture reviews and solution designs.

  • Conduct threat modeling sessions.

  • Support teams in implementing authentication authorization and data protection mechanisms.

Vulnerability Management

  • Analyze results originating from:

    • Penetration Tests

    • Vulnerability Assessments

    • SAST / DAST

    • Dependency Scanning

    • Container Scanning

  • Classify and prioritize vulnerabilities.

  • Provide technical support during remediation.

  • Track remediation plans and their respective SLAs.

Penetration Testing Coordination

  • Define test scope.

  • Coordinate with external vendors.

  • Validate findings.

  • Ensure tracking and closure of recommendations.

Training & Enablement

  • Conduct Secure Coding workshops.

  • Promote OWASP Top 10 and secure development best practices.

  • Support the creation of Security Champions within teams.

  • Produce technical guidelines and standards.

DevSecOps

  • Integrate security controls into CI/CD pipelines.

  • Promote automation of security checks.

  • Define application security metrics and key performance indicators (KPIs).


Qualifications :

Professional Profile & Background

  • A professional with previous experience in software development and application architecture who has evolved into an Application Security role.

  • Ability to interact with development architecture operations and corporate security teams acting simultaneously as a technical consultant facilitator and advocate for best practices.

  • Capacity to understand code architecture and development processes directly supporting the analysis and resolution of identified vulnerabilities.

Technical Skills

Software Development

Solid experience in at least one of the following stacks:

  • Java: Spring Boot; REST APIs; Maven

  • C# / .NET: .NET Framework / .NET Core;

  • Frontend (Optional / Desirable): Angular (JavaScript / TypeScript)

Operating Systems & Cloud Infrastructure

  • Linux Shell Scripting and basic system hardening.

  • Required: Cloud knowledge with hands-on experience in production application deployments.

  • Desirable: Knowledge of major cloud platforms (AWS and/or Azure preferred; Google Cloud or others are relevant and transferable).

Application Security Expertise

Practical knowledge of:

  • OWASP Top 10 OWASP ASVS and Secure Coding best practices

  • Threat Modeling

  • Authentication & Authorization (including OAuth2 OpenID Connect and JWT)

  • API Security & Secure API Design

  • Applied Cryptography (TLS key/certificate lifecycle secure hashing)

  • Secrets Management (secret stores secret rotation preventing secrets in code)

Security Tooling

Experience with tools such as:

  • SonarQube Checkmarx Fortify Veracode Snyk Dependabot OWASP ZAP Burp Suite or Trivy

Behavioral Competencies & Soft Skills

  • Excellent communication skills.

  • Ability to influence without hierarchical authority.

  • Training and mentoring capability.

  • Pragmatic approach to risk management.

  • Ability to collaborate easily with development teams.

  • Strong analytical mindset.


Additional Information :

The Devoteam Group works for equal opportunities promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.

 

Join us in our mission to safeguard our clients critical digital assets by applying deep technical expertise to their most strategic projects.

Apply now to become a key technical leader in this pivotal engagement and make a tangible impact as a key member of our Cybersecurity Engineering Professional Services team!


Remote Work :

No


Employment Type :

Full-time

MissionEnsure that products and applications developed by the organization incorporate security principles from inception to operations promoting secure development practices coordinating vulnerability assessments and penetration tests providing technical support to development teams for risk remedi...

About Company

Company Logo

Devoteam is a AI-driven tech consulting firm specialised in cloud platforms, cyber, data, and sustainability. Tech native for almost 30 years, Devoteam guides businesses through sustainable digital transformation to deliver value. With over 11,000 tech architects in more than 25 co ... View more

View Profile View Profile