Senior Security Engineer
RemoteLisbon, PortugalseniorFull-time
- Posted
- yesterday
- Source
- LinkedIn (remote, Europe)
- Field
- Engineering, Security
Skills
Penetration TestingCommunicationCybersecurityJavaScriptSecurityDevOpsAzureCI/CDAgileJavaAWSGCPAI
Description
Hexa Consulting is looking for a Senior Security Engineer to join our Client's team in a hybrid work model from Lisbon.
JOB DETAILS
Lisbon, Portugal | Hybrid | Luxury Goods & Digital Commerce Sector
MANDATORY REQUIREMENTS
- At least 4 years of professional experience as a Security Engineer, ideally in digital platforms, e-commerce or software-driven environments.
- Bachelor's or Master's degree in Computer Science, Software Engineering or a related field.
- Strong knowledge of information security principles, IT security and web application security across Internet, Extranet and Intranet environments.
- Hands-on experience with vulnerability scanning, penetration testing, security controls and incident response.
- Solid understanding of OWASP Top 10, secure coding principles and common web application vulnerabilities.
- Experience supporting security hardening, vulnerability remediation and secure deployment practices.
- Understanding of security integration into Agile software development and CI/CD processes.
- Strong analytical and problem-solving skills, with the ability to make pragmatic security decisions.
- Ability to work independently and coordinate security activities across development, operations, cybersecurity and external partner teams.
- Excellent communication skills and experience collaborating with multinational, cross-functional teams.
- Proactive, self-driven mindset and willingness to continuously learn and improve.
- Professional working proficiency in English.
NICE TO HAVE
- Previous experience in digital commerce or e-commerce environments.
- Exposure to security intelligence reviews and related assessment activities.
TECHNOLOGY STACK
- Application Security: Web & Mobile Application Security, OWASP Top 10, Secure Coding.
- Security Testing: Vulnerability Scanning, Penetration Testing, Security Assessments.
- DevSecOps: GitLab, SonarQube, Snyk, CI/CD Security Testing.
- Identity & Access Management: OIDC, OpenFGA, AWS IAM Policies.
- Cloud Platforms: AWS, Azure, GCP.
- Programming: Java, JavaScript.
- Security Operations: Incident Response, Security Hardening, Vulnerability Management.
- Methodologies: Agile Delivery, Secure Software Development Practices.
KEY RESPONSIBILITIES
- Act as the security reference for digital product teams, coordinating cybersecurity initiatives with IT, development, operations and external partners.
- Support the implementation, maintenance and continuous improvement of security controls across digital platforms and services.
- Ensure digital solutions comply with applicable security policies, standards and secure design principles.
- Plan, coordinate and follow up on security testing activities, including penetration testing, vulnerability scanning and security intelligence reviews.
- Collaborate with development and operations teams to identify, prioritize and remediate security vulnerabilities.
- Promote secure coding, secure design and secure deployment practices throughout the software development lifecycle.
- Work closely with DevOps and QA teams to strengthen automated security testing within CI/CD pipelines.
- Define, document and promote security hardening procedures for web infrastructure, applications and middleware components.
- Participate in security audits and assessments covering data protection, e-commerce and digital platform security requirements.
- Maintain and improve security processes, technical controls and incident management procedures.
- Provide technical guidance, training and coaching to internal teams and external partners on security best practices.
- Coordinate security-related activities across multiple stakeholders and contribute to continuous cybersecurity improvement.
WHAT WE OFFER
- Work Model: Hybrid.
- A culture where each person is encouraged to act as a Builder, contributing with ownership, responsibility and impact.
- A collaborative environment built on Honesty, Mutual Support and Agility.
- Continuous learning and certification support throughout your journey.
- Private health insurance from day one, with optional family extension.
- Confidential mental health support through TEAM 24, including psychological support, content and live sessions.
- Childcare vouchers and practical family support measures.
- Opportunities to grow through exposure to quality management, information security, AI governance and cybersecurity best practices.
EQUAL OPPORTUNITY
Hexa is committed to equal opportunity, inclusion and fair access to professional growth. We value diverse backgrounds, perspectives and experiences, and we support the principles of the Portuguese Diversity Charter in the way we build teams and opportunities.
HEXA LIFE
Life at Hexa means being part of a community of Builders. We work with transparency, support each other across projects and geographies, and stay focused on learning, adapting and delivering work that creates real impact.
If you meet the above criteria and are ready for an exciting opportunity in a dynamic environment, please send your CV!
JobMatch aggregates public listings. Always apply through the original posting.