Application Security Engineer - Porto / Hybrid

Indeed

Company

Job typeFull-time
Workplace typeOnsite
Experience levelNo experience limit
Education levelNo degree limit

Description

Job Summary: Noesis is seeking an Application Security Engineer with strong technical skills and practical experience in Application Security and Secure SDLC to join the client's Cybersecurity team. Key Highlights: 1. Execute and support Application Security activities 2. Analyze and manage vulnerabilities from SAST, DAST, SCA, and pen tests 3. Promote secure development practices and contribute to Secure SDLC initiatives **Description:** ---------------- Noesis is looking for an Application Security Engineer with strong technical expertise and hands-on experience in Application Security and Secure SDLC to join the client’s Cybersecurity team. **Key Responsibilities:** * Execute and support Application Security activities, including: * Application security assessments; * Secure code reviews; * Threat modelling; * Validation of security controls; * Analyze and manage vulnerabilities and findings from: * SAST, DAST, and SCA; * Internal and external penetration tests; * Support the integration and continuous improvement of security controls in CI/CD pipelines, promoting shift\-left security practices. * Collaborate directly with development teams to: * Clearly and practically explain security findings; * Support remediation correction and validation; * Promote secure development best practices; * Track vulnerabilities throughout their lifecycle, ensuring: * Accurate risk classification; * Appropriate prioritization; * Closure within defined SLAs; * Contribute to Secure SDLC initiatives, including defining and improving guidelines, standards, and best practices. * Support security activities in modern architectures, including: * Cloud\-native applications; * Microservices and APIs; * Use tools such as JIRA (or equivalents) to log and track activities and vulnerabilities. * Support audits, security reviews, and applicable regulatory requirements in the financial context. **Requirements:** * Professional experience in Application Security, DevSecOps, Cybersecurity, or similar technical roles; * Solid knowledge of application vulnerabilities (e.g., OWASP Top 10, OWASP API Top 10\); * Solid understanding of Secure Software Development Lifecycle (SSDLC); * Experience analyzing and tracking: vulnerabilities, security findings, remediation actions; * Practical experience or strong familiarity with SAST / DAST / SCA; * Penetration testing (consumption and analysis of results); * Knowledge of cloud environment security (AWS and/or Azure); * Understanding of modern application architectures (APIs, microservices); * Experience with tracking tools such as JIRA; * Ability to communicate effectively with technical teams (developers, DevOps, security engineers); * Strong attention to detail, autonomy, and sense of responsibility; * Ability to work in a regulated, dynamic environment with multiple priorities; * English C1\. **Nice to Have:** * Threat modelling frameworks; * Advanced secure code review; * OWASP ASVS; * Security testing automation; * Prior experience in financial or highly regulated environments. **Soft Skills:** * Analytical and critical mindset; * Proactivity and continuous improvement orientation; * Strong collaboration ability; * Good organization and priority management. **Work Model: Hybrid — 2 days per week in Porto.** If you meet these criteria and would like to join an innovative organization that consistently invests in developing its talent, send us your application. **Join us. Let's innovate together!** All our recruitment and selection processes are based on equal opportunity, valuing the competence and potential of each individual and ensuring that no candidate is discriminated against on the basis of gender, ethnicity, sexual orientation, age, religion, or physical condition. * Job posting issued under Law No. 4 / 2019, of January 10 **Requirements:** -----------------

Some content was automatically translated

Posted by

João Santos

Indeed · HR

Location

Similar jobs

Application Security Engineer - Porto / Hybrid by Indeed in 2026 | ok.com