Application Security Engineer - Hybrid - Lisbon - Mid/Senior
RemoteLisbon, PortugalEUR 50k–75kseniorFull-time
- Posted
- today
- Source
- LinkedIn (remote, Europe)
- Field
- Engineering, Security
Skills
Penetration TestingKubernetesSecurityPythonDockerCI/CDJavaAWSGCPGo
Description
Location: Lisbon, Portugal
Working pattern: 4 days per week onsite
Salary: Mid level €50,000 - €75,000
Salary: Senior €75,000 - €95,000
We are looking for a Senior Application Security Engineer to join a highly technical security engineering function responsible for protecting complex, cloud-native products.
This is a hands-on engineering role for someone who enjoys getting into the code, architecture and technical detail of security problems.
You will work directly with software engineering teams to identify vulnerabilities, design secure systems, develop security tooling and improve security throughout the software development lifecycle.
The environment is particularly suited to someone who wants to build security solutions rather than simply operate security products.
The role
You will:
- Drive improvements to application security across large-scale, cloud-native products.
- Work directly with engineering teams on secure architecture and design.
- Perform threat modelling and security design reviews.
- Conduct vulnerability assessments and application security testing.
- Perform web application penetration testing.
- Review code and identify security vulnerabilities and design weaknesses.
- Develop security tooling and automate security processes.
- Integrate security tooling into development and CI/CD workflows.
- Advise developers throughout the software development lifecycle.
- Provide expertise across application security, cloud security and security architecture.
- Assess security and privacy requirements for new products and services.
- Help shape application security strategy and tooling.
- Mentor developers and security engineers on secure development practices.
- Lead complex security initiatives from conception through to implementation.
What we're looking for
Essential:
- Strong software engineering or application security background.
- Strong programming capability in Python, Go, Java or a similar language.
- Hands-on experience with application security.
- Strong understanding of common web application vulnerabilities, including OWASP Top 10.
- Experience with web application penetration testing.
- Experience using tools such as Burp Suite, vulnerability scanners and static analysis tools.
- Experience automating or integrating security tools.
- Experience with cloud and containerised environments.
- Knowledge of AWS, GCP, Kubernetes and/or Docker.
- Experience with threat modelling, security architecture and design reviews.
- Understanding of security within distributed systems.
- Strong understanding of DevSecOps and secure software development.
- Ability to work directly with developers and influence technical decisions.
Desirable:
- Security qualifications such as CISSP, OSCP or SANS certifications.
- Experience with data protection, ISO 27001 or PCI-DSS.
- Experience working in financial services or another highly regulated environment.
- Security research, blogging, presentations or open-source contributions.
- Experience building security tooling or interacting with cloud APIs.
What makes this different?
Security is already deeply embedded in the engineering culture. Developers are technically strong and actively engage with the security team, meaning you can spend your time discussing architecture, code, vulnerabilities and implementation choices rather than trying to convince people that security matters.
The security team is collaborative rather than dogmatic. You will be expected to assess risk, understand the wider business context and prioritise the areas where engineering effort will create the greatest security benefit.
There is also significant greenfield work, giving you the opportunity to influence how security is designed rather than simply maintaining an inherited security stack.
JobMatch aggregates public listings. Always apply through the original posting.