Назад
Company hidden
1 день назад

Application Security Specialist

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Portugal
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Application Security Specialist (S-SDLC/CI/CD): Managing secure application development processes and enterprise security scanning across critical platforms with an accent on SAST, SCA, secret detection, cloud security, and vulnerability remediation. Focus on integrating security automation into multiple CI/CD ecosystems, coordinating penetration testing, and solving complex application security challenges.

Location: Porto, Portugal — hybrid. The development center is in Porto, with administrative support in Lisbon and collaboration across European cities.

Company

Technology services and consulting provider supporting enterprise projects and multicultural software delivery teams.

What you will do

  • Manage and integrate S-SDLC processes across enterprise platforms.
  • Orchestrate SAST, SCA, secret detection, and cloud security scanning tools.
  • Implement and maintain CI/CD security automation across GitHub Actions, GitLab, Jenkins, and Azure DevOps.
  • Lead vulnerability triage, tracking, and remediation workflows.
  • Conduct penetration testing and coordinate security assessments for critical applications.

Requirements

  • At least 3 years of experience in a similar application security role.
  • Strong experience with S-SDLC processes and secure application development.
  • Hands-on experience with Coverity, Polaris, Black Duck, GitGuardian, Wiz, OX Security, or Aikido.
  • Experience implementing security automation in CI/CD environments.
  • Fluent English and Portuguese required.

Nice to have

  • Experience with Jira Data Center and API integrations.
  • Knowledge of JFrog Artifactory and third-party component governance.
  • Experience with SBOM analysis and AppSec inventory management.
  • Ability to develop security standards, guidelines, and training for development teams.
  • Experience building custom security automation tools.

Culture & Benefits

  • Health insurance.
  • Personalized training plan with a dedicated training budget.
  • Continuous feedback and professional development support.
  • Remote onboarding process.
  • Semesterly team events, partner discounts, and a transparent culture where ideas and needs are valued.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →