Devoteam Cyber Trust | Application Security Engineer | FinTech Sector
Devoteam · Lisbon, Portugal
Business Consulting and Services · 10,001+ employees
About the role
You will drive application security initiatives across the software development lifecycle and collaborate with engineering teams to remediate vulnerabilities. Additionally, you will integrate security testing tools into CI/CD pipelines and promote secure-by-design principles.
What they look for
Requirements
Candidates must have at least 4 years of experience in application security and strong knowledge of OWASP Top 10 and secure design principles. Proficiency in at least one programming language and experience with security tooling like SAST, DAST, and SCA is required.
Full description
Company Description
Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located across EMEA, we aim to establish cybersecurity as an enabler of business success rather than a gatekeeper. We leverage an end-to-end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and medium-sized companies from all sectors and industries.
Since 2009, previously known as INTEGRITY, our team based in Portugal is specialised in providing cutting-edge Managed Security Services that combine its expertise and proprietary technology to consistently and effectively reduce the cyber risk of our clients.
The comprehensive service range includes Persistent Intrusion Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. ISO 27001 (Information Security) and ISO 9001 (Quality) certified, PCI-QSA, and member of CREST and CIS - Centre for Internet Security, we provide services to a considerable number of clients, operating in more than 20 countries.
Job Description
We are looking for a Senior Application Security Consultant to join our Application Security team. In this role, you will help strengthen the security posture of modern applications by integrating security throughout the software development lifecycle. You will collaborate closely with engineering teams to identify, assess, and remediate security vulnerabilities while promoting secure development practices and DevSecOps principles.
This is an excellent opportunity for an experienced Application Security professional who enjoys working in a collaborative, cloud-native environment with a strong focus on automation and continuous improvement.
Key Responsibilities
- Drive application security initiatives across the software development lifecycle (SDLC).
- Identify, assess, prioritize, and support the remediation of application security vulnerabilities.
- Partner with engineering teams to promote secure coding practices and security-by-design principles.
- Integrate security testing tools and controls into CI/CD pipelines.
- Review source code and provide security recommendations during development.
- Support secure design reviews and threat modeling activities.
- Improve and automate security processes using modern AppSec and DevSecOps tools.
- Contribute to the continuous evolution of the organization's application security program.
Qualifications
- Minimum of 4 years of experience in Application Security or a related cybersecurity role.
- Strong knowledge of Application Security fundamentals, including:• OWASP Top 10
- Common Weakness Enumeration (CWE)
- Secure Design Principles
- Web and API vulnerability remediation
- Experience with Application Security tooling such as:• SAST
- DAST
- SCA
- Snyk
- Semgrep
- Checkmarx
- SonarQube
- OWASP Dependency-Check
- OWASP ZAP
- Trivy
- Experience integrating automated security controls into CI/CD pipelines using tools such as Jenkins, GitHub Actions, or GitLab CI.
- Experience performing vulnerability analysis, triage, prioritization, and providing remediation guidance to development teams.
- Ability to read and analyze source code with hands-on experience in at least one programming language such as Java, Python, or Go.
- Working knowledge of cloud security concepts in AWS, Azure, or GCP, including:• IAM roles and permissions
- Security Groups
- VPCs
- Common cloud configuration risks
- Fluent English (spoken and written).
Preferred Qualifications
- Experience working within FinTech or Enterprise SaaS environments.
- Knowledge of security compliance frameworks such as:• SOC 2
- ISO 27001
- PCI DSS
- Experience leveraging GenAI/LLMs to improve Application Security processes or developer productivity.
- Practical experience conducting threat modeling using methodologies such as STRIDE.
- Hands-on experience with containerized environments using Docker and Kubernetes.
- Offensive security experience, including penetration testing, red teaming, bug bounty participation, Capture The Flag (CTF) competitions, or certifications such as OSCP or eJPT.
What We're Looking For
- Strong analytical and problem-solving skills.
- Excellent communication and stakeholder management abilities.
- Collaborative mindset with experience working alongside software engineering teams.
- Passion for secure software development and continuous improvement.
- Ability to thrive in a remote, fast-paced, and technology-driven environme
Additional Information
The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.
Join us in our mission to safeguard our clients' critical digital assets by applying deep technical expertise to their most strategic projects.
Apply now to become a key technical leader in this pivotal engagement and make a tangible impact as a key member of our Cybersecurity Engineering Professional Services team!
- Contract type: Fixed-term contract