Application Security Engineer (M/F/D) - Porto
Descrição da Função
Triangle Talent Portugal is recruiting an Application Security Engineer with a strong technical focus for a client in Porto. This is an essentially operational role centered on technical execution and support. You will be responsible for executing Application Security and Secure SDLC activities, working in close collaboration with development, DevOps, and security teams within a regulated, cloud-native environment. Key Responsibilities 1. Technical Security Execution Perform vulnerability analysis, secure code reviews, and threat modeling to ensure application integrity. 2. Vulnerability Lifecycle Management Validate security controls and track vulnerabilities throughout their entire lifecycle, from identification to remediation. 3. Secure SDLC Integration Support the implementation of secure development best practices and integrate security controls directly into CI/CD pipelines. 4. Cloud-Native Security Support Provide technical security support for modern architectures (APIs, microservices) in cloud-native environments. 5. Compliance & Audit Support Assist with security audits and ensure all technical activities meet the strict regulatory requirements of the financial sector. Requirements • Professional Experience: Proven track record in Application Security, DevSecOps, or Cybersecurity roles. • Vulnerability Expertise: Solid knowledge of application vulnerabilities, including OWASP Top 10 and API Top 10. • Tooling Proficiency: Experience in analyzing and remediating findings using SAST, DAST, and SCA tools, as well as analyzing pentest results. • Cloud & Architecture: Experience with security in cloud environments (AWS and/or Azure) and modern architectures like APIs and microservices. • Language Skills: English C1 and Portuguese C1/C2. Technical & Soft Skills • Tools: Experience with tracking tools such as JIRA. • Communication: Ability to communicate effectively with technical teams. • Execution: High autonomy, attention to detail, and the ability to work in regulated, dynamic environments. • Soft Skills: Analytical and critical mindset, proactivity, collaboration, and strong organizational/priority management skills. Nice to Have • Advanced experience in threat modeling and secure code review. • Knowledge of OWASP ASVS and security testing automation. • Prior experience in the financial or highly regulated sectors. We offer • Salary commensurate with proven experience; • Opportunity to join a solid, growing company; • Hybrid work arrangement (2 days per week in the Porto office).
Localização
- Porto, Portugal