Application Security Engineer
Expleo Lisbon, Portugal
IT Services and IT Consulting · 10,001+ employees
About the role
You will define and promote secure development practices while integrating security requirements into application architecture and CI/CD pipelines. Additionally, you will lead threat modeling, conduct security reviews, and provide hands-on support to development teams for vulnerability remediation.
What they look for
Requirements
The role requires at least 5 years of professional experience in software development or application architecture with a focus on application security. Candidates must possess strong knowledge of OWASP standards, cloud environments, and proficiency in Java/Spring Boot or C#/.NET.
Full description
Overview
Expleo is a trusted partner for your innovation journey. As a global engineering, technology and consulting service provider, we are ideally positioned to help you achieve your ambitions and future-proof your business. With a smart blend of bold thinking and reliable execution, we’re able to fast-track innovation through each step of your value chain.We are strategically positioned to build value, with a global footprint across 30 countries.We are as global and local as you need us to be, with strong best-in-class pan-European technological centres and unique best-shoring capabilities.We leverage a network of high value-adding affiliates in consulting and industrial excellence, and leading partners across multiple sectors to provide you with the most comprehensive services and solutions in an ever-changing environment.
Responsibilities
- 5+ years of professional experience in software development and/or application architecture, with proven experience in Application Security.
- Define and promote Secure SDLC and Security-by-Design practices.
- Integrate security requirements into application architecture, design and development.
- Lead or facilitate Threat Modeling and application security reviews.
- Analyze and prioritize vulnerabilities identified through SAST, DAST, SCA, container scanning, vulnerability assessments and penetration tests.
- Coordinate penetration testing activities, including scope definition, external providers, findings validation and remediation follow-up.
- Provide hands-on support to development teams in vulnerability remediation and secure coding.
- Promote best practices around authentication, authorization, API security, data protection, cryptography and secrets management.
- Integrate security controls and automated security testing into CI/CD pipelines, supporting DevSecOps adoption.
- Develop security guidelines, standards and metrics, and promote security awareness through Secure Coding workshops and Security Champions.
Essential skills
- Strong understanding of OWASP Top 10, OWASP ASVS, Secure Coding and Threat Modeling.
- Practical knowledge of OAuth2, OpenID Connect, JWT, API Security, TLS, cryptography and secrets management.
- Strong development experience in Java/Spring Boot or C#/.NET, including REST APIs.
- Solid understanding of cloud environments, with real-world application deployment experience, preferably AWS and/or Azure.
- Good knowledge of Linux and shell scripting.
- Experience with application security tools such as SonarQube, Checkmarx, Fortify, Veracode, Snyk, Dependabot, OWASP ZAP, Burp Suite or Trivy.
- Ability to read and understand source code and application architecture and translate security findings into practical remediation.
- Strong communication and collaboration skills, with the ability to act as a technical advisor and security advocate for development teams.
Similar roles
-
Information System Security Engineer III
TRISTAR INC Bloomington, Indiana, United States
-
Information System Security Engineer II
TRISTAR INC Bloomington, Indiana, United States
-
Network & Cybersecurity Engineer | C-sUAS
Sherpa 6 Alexandria, Virginia, United States · $165K–$200K/yr
-
Senior Cybersecurity Engineer
WSI (Warehouse Specialists, LLC) Town of Grand Chute, Wisconsin, United States
-
Associate Security Engineer
JPMorgan Chase & Co. Dublin, Leinster, Ireland
-
Cloud Security Engineer
Security Risk Advisors Philadelphia, Pennsylvania, United States · $90K–$130K/yr