Devoteam

Devoteam Cyber Trust | Application Security Engineer | Mobility Sector

Devoteam  •  Lisbon, PT (Onsite)  •  5 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located across EMEA, we aim to establish cybersecurity as an enabler of business success rather than a gatekeeper. We leverage an end-to-end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and medium-sized companies from all sectors and industries.

Since 2009, previously known as INTEGRITY, our team based in Portugal is specialised in providing cutting-edge Managed Security Services that combine its expertise and proprietary technology to consistently and effectively reduce the cyber risk of our clients.

The comprehensive service range includes Persistent Intrusion Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. ISO 27001 (Information Security) and ISO 9001 (Quality) certified, PCI-QSA, and member of CREST and CIS - Centre for Internet Security, we provide services to a considerable number of clients, operating in more than 20 countries.

Mission

Ensure that products and applications developed by the organization incorporate security principles from inception to operations, promoting secure development practices, coordinating vulnerability assessments and penetration tests, providing technical support to development teams for risk remediation, and contributing to the continuous evolution of application security maturity.

Responsibilities

Application Security

  • Define and promote Secure SDLC practices.

  • Integrate security requirements into the development lifecycle.

  • Participate in architecture reviews and solution designs.

  • Conduct threat modeling sessions.

  • Support teams in implementing authentication, authorization, and data protection mechanisms.

Vulnerability Management

  • Analyze results originating from:

    • Penetration Tests

    • Vulnerability Assessments

    • SAST / DAST

    • Dependency Scanning

    • Container Scanning

  • Classify and prioritize vulnerabilities.

  • Provide technical support during remediation.

  • Track remediation plans and their respective SLAs.

Penetration Testing Coordination

  • Define test scope.

  • Coordinate with external vendors.

  • Validate findings.

  • Ensure tracking and closure of recommendations.

Training & Enablement

  • Conduct Secure Coding workshops.

  • Promote OWASP Top 10 and secure development best practices.

  • Support the creation of Security Champions within teams.

  • Produce technical guidelines and standards.

DevSecOps

  • Integrate security controls into CI/CD pipelines

  • Promote automation of security checks.

  • Define application security metrics and key performance indicators (KPIs).

Qualifications

Professional Profile & Background

  • A professional with previous experience in software development and application architecture who has evolved into an Application Security role.

  • Ability to interact with development, architecture, operations, and corporate security teams, acting simultaneously as a technical consultant, facilitator, and advocate for best practices.

  • Capacity to understand code, architecture, and development processes, directly supporting the analysis and resolution of identified vulnerabilities.

Technical Skills

Software Development

Solid experience in at least one of the following stacks:

  • Java: Spring Boot; REST APIs; Maven

  • C# / .NET:NET Framework / .NET Core; ASP.NET

  • Frontend (Optional / Desirable): Angular (JavaScript / TypeScript)

Operating Systems & Cloud Infrastructure

  • Linux, Shell Scripting, and basic system hardening.

  • Required: Cloud knowledge with hands-on experience in production application deployments.

  • Desirable: Knowledge of major cloud platforms (AWS and/or Azure preferred; Google Cloud or others are relevant and transferable).

Application Security Expertise

Practical knowledge of:

  • OWASP Top 10, OWASP ASVS, and Secure Coding best practices

  • Threat Modeling

  • Authentication & Authorization (including OAuth2, OpenID Connect, and JWT)

  • API Security & Secure API Design

  • Applied Cryptography (TLS, key/certificate lifecycle, secure hashing)

  • Secrets Management (secret stores, secret rotation, preventing secrets in code)

Security Tooling

Experience with tools such as:

  • SonarQube, Checkmarx, Fortify, Veracode, Snyk, Dependabot, OWASP ZAP, Burp Suite, or Trivy

Behavioral Competencies & Soft Skills

  • Excellent communication skills.

  • Ability to influence without hierarchical authority.

  • Training and mentoring capability.

  • Pragmatic approach to risk management.

  • Ability to collaborate easily with development teams.

  • Strong analytical mindset.

Additional Information

The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.

Join us in our mission to safeguard our clients' critical digital assets by applying deep technical expertise to their most strategic projects.

Apply now to become a key technical leader in this pivotal engagement and make a tangible impact as a key member of our Cybersecurity Engineering Professional Services team!

Devoteam

About Devoteam

Devoteam is a AI-driven tech consulting firm specialised in cloud platforms, cyber, data, and sustainability.

Tech native for almost 30 years, Devoteam guides businesses through sustainable digital transformation to deliver value.

With over 11,000 tech architects in more than 25 countries across Europe, the Middle East, and Africa, Devoteam is committed to using technology to serve people.

Industry
Consulting & Advisory
Company Size
10,000+ employees
Headquarters
Levallois-Perret, FR
Year Founded
Unknown
Social Media