Senior Application Security Engineer – DevSecOps and Cloud Security
4 410 - 5 250
EUR
(B2B)
2 300 - 2 600
EUR
net (Permanent Contract)
Unleash Cybersecurity Excellence — Lead the Future of Application Security in a Dynamic Banking Environment!
Porto-based opportunity with hybrid work model (up to 3 days remote).
As a Senior Application Security Engineer, you will be working for a leading international financial institution committed to innovative banking solutions and robust security practices. You will spearhead application security initiatives, mentor technical teams, and shape strategic security frameworks to safeguard critical digital assets across global regions.
Your main responsibilities:
- Contribute to the development and execution of the application security strategy and roadmap.
- Mentor and guide junior AppSec engineers, fostering a culture of continuous improvement.
- Lead complex vulnerability analysis, remediation efforts, and security assessments within development squads.
- Integrate advanced security tools (SAST, SCA, DAST, IaC scanning) into CI/CD pipelines for streamlined DevSecOps workflows.
- Conduct technical workshops, open sessions, and produce comprehensive documentation to promote security awareness.
- Monitor security KPIs/KRIs/OKRs, optimizing security metrics and drive innovation through emerging threat research.
- Engage in technological watch, propose innovative security solutions, and participate in proof-of-concept projects.
- Lead community-building efforts by facilitating training sessions and fostering a security-first mindset.
You're ideal for this role if you have:
- A minimum of 5 years’ experience in cybersecurity, application security, or DevSecOps, ideally within the international banking ecosystem.
- Proven leadership experience in managing security projects and mentoring teams.
- Master’s degree in Engineering, Computer Science, or related field.
- Fluent command of English and Portuguese.
- Strong programming skills in Python, C++, or C#, with familiarity in development frameworks such as Hadoop or Angular.
- Deep knowledge of OWASP Top 10 vulnerabilities and advanced vulnerability analysis & remediation techniques.
- Extensive experience with security tools such as SAST, SCA, container image scanning, DAST, and IaC scanning solutions.
- Comprehensive cloud security expertise across private, public, and hybrid environments.
It is a strong plus if you have:
- Certifications such as CISSP, CISA, or related.
- Experience with cloud security management in regulated and hybrid environments.
- Knowledge of French language.
Language Required for the role:
- Fluent in English and Portuguese.
Eligibility for the role:
- Only candidates with an existing legal right to work in the European Union will be considered.
#MAKEYourCareerBETTER
Interested? Apply now and include your CV (preferably in English) along with a statement confirming your consent to the processing and storage of your personal data.
Internal number #9780
Benefits
ITDS Clubs
Access to medical insurance
Meal Card
Access to Pluralsight & Udemy
Integrational Events
Your criteria