Назад
Company hidden
2 дня назад

Application Security Engineer - Vice President

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Portugal
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer - Vice President (API Security): Building and maturing secure design, threat modeling, API security, and shift-left security capabilities across the organization with an accent on application security architecture, penetration testing, and developer enablement. Focus on automating AppSec workflows in Python, securing REST and GraphQL APIs, integrating security gates into CI/CD, and developing AI-assisted vulnerability management pipelines.

Location: Lisbon, Portugal; office-based four days per week with remote work available on Fridays.

Company

hirify.global is hiring for an application security role supporting organization-wide secure design and shift-left security initiatives.

What you will do

  • Build and mature the Secure Design and Threat Modeling program, including methodology, review standards, and sign-off criteria.
  • Drive shift-left security through design reviews, developer enablement, and security gates in CI/CD.
  • Own API security and assess REST and GraphQL APIs.
  • Support offensive security initiatives, including penetration testing and API exploitation analysis.
  • Build scalable security automation and tooling in Python.
  • Partner with developers on SAST and SCA remediation, scan optimization, and AI-assisted vulnerability management pipelines.

Requirements

  • Hands-on experience with secure design, threat modeling, API security, and offensive security.
  • Practical knowledge of the OWASP Top 10, web application security, API exploitation, and penetration testing.
  • Strong API security experience with REST and GraphQL.
  • Proficiency in Python and experience building automation tools.
  • Experience embedding security into CI/CD, conducting design reviews, and enabling developers.
  • Ability to read code across languages, influence engineering and product teams, and operate at architecture level.

Nice to have

  • Relevant certifications such as OSCP, OSWE, GWEB, CSSLP, CISSP, or CEH.
  • Exposure to AI-assisted security tooling or LLM security.
  • Development experience and fluency in Ruby, Python, and Scala.
  • Familiarity with cloud-native environments and attack surface management.

Culture & Benefits

  • Four days working from the office and one remote day on Friday.
  • Competitive salary, annual performance bonus, and equity for full-time employees.
  • 100% employer-paid health and dental insurance.
  • Generous paid time off.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →