Expleo

Application Security Engineer

Expleo Lisbon, Portugal

IT Services and IT Consulting · 10,001+ employees

19 h ago
security Senior (5-10 yrs) Full-time Portugal
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will define and promote secure development practices while integrating security requirements into application architecture and CI/CD pipelines. Additionally, you will lead threat modeling, conduct security reviews, and provide hands-on support to development teams for vulnerability remediation.

What they look for

Application Security Secure SDLC Threat Modeling SAST DAST SCA Java Spring Boot C# .NET AWS Azure Linux OAuth2 OpenID Connect DevSecOps

Requirements

The role requires at least 5 years of professional experience in software development or application architecture with a focus on application security. Candidates must possess strong knowledge of OWASP standards, cloud environments, and proficiency in Java/Spring Boot or C#/.NET.

Full description

Overview

Expleo is a trusted partner for your innovation journey. As a global engineering, technology and consulting service provider, we are ideally positioned to help you achieve your ambitions and future-proof your business. With a smart blend of bold thinking and reliable execution, we’re able to fast-track innovation through each step of your value chain.We are strategically positioned to build value, with a global footprint across 30 countries.We are as global and local as you need us to be, with strong best-in-class pan-European technological centres and unique best-shoring capabilities.We leverage a network of high value-adding affiliates in consulting and industrial excellence, and leading partners across multiple sectors to provide you with the most comprehensive services and solutions in an ever-changing environment.

Responsibilities

- 5+ years of professional experience in software development and/or application architecture, with proven experience in Application Security.

- Define and promote Secure SDLC and Security-by-Design practices.

- Integrate security requirements into application architecture, design and development.

- Lead or facilitate Threat Modeling and application security reviews.

- Analyze and prioritize vulnerabilities identified through SAST, DAST, SCA, container scanning, vulnerability assessments and penetration tests.

- Coordinate penetration testing activities, including scope definition, external providers, findings validation and remediation follow-up.

- Provide hands-on support to development teams in vulnerability remediation and secure coding.

- Promote best practices around authentication, authorization, API security, data protection, cryptography and secrets management.

- Integrate security controls and automated security testing into CI/CD pipelines, supporting DevSecOps adoption.

- Develop security guidelines, standards and metrics, and promote security awareness through Secure Coding workshops and Security Champions.

Essential skills

- Strong understanding of OWASP Top 10, OWASP ASVS, Secure Coding and Threat Modeling.

- Practical knowledge of OAuth2, OpenID Connect, JWT, API Security, TLS, cryptography and secrets management.

- Strong development experience in Java/Spring Boot or C#/.NET, including REST APIs.

- Solid understanding of cloud environments, with real-world application deployment experience, preferably AWS and/or Azure.

- Good knowledge of Linux and shell scripting.

- Experience with application security tools such as SonarQube, Checkmarx, Fortify, Veracode, Snyk, Dependabot, OWASP ZAP, Burp Suite or Trivy.

- Ability to read and understand source code and application architecture and translate security findings into practical remediation.

- Strong communication and collaboration skills, with the ability to act as a technical advisor and security advocate for development teams.

Similar roles