Skip to main content
Devoteam

Senior Application Security Consultant

RemotePortugal only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Mid-size
Salary not disclosed
Check eligibility

Open to PT only. Set where you work from to check your eligibility.

No BS summary

Senior Application Security professional with 4+ years in AppSec or cybersecurity. Needs SDLC security, vulnerability remediation, AppSec tooling, CI/CD security controls, source-code analysis, cloud security, and fluent English. FinTech or Enterprise SaaS experience is a plus.

Core skills

Application SecurityDevSecOpsCI/CD security

Required skills

OWASP Top 10CWESASTDASTSCASnykSemgrepCheckmarxSonarQubeOWASP Dependency-CheckOWASP ZAPTrivyJenkins/GitHub Actions/GitLab CIJava/Python/GoAWS/Azure/GCP

Optional skills

SOC 2ISO 27001PCI DSSGenAILLMsSTRIDEDockerKubernetes

Required languages

English Fluent required: true

What you'll do

  • Drive application security initiatives across the software development lifecycle (SDLC).
  • Identify, assess, prioritize, and support the remediation of application security vulnerabilities.
  • Partner with engineering teams to promote secure coding practices and security-by-design principles.
  • Integrate security testing tools and controls into CI/CD pipelines.
  • Review source code and provide security recommendations during development.
  • Support secure design reviews and threat modeling activities.
  • Improve and automate security processes using modern AppSec and DevSecOps tools.
  • Contribute to the continuous evolution of the organization's application security program.

What they require

  • Minimum of 4 years of experience in Application Security or a related cybersecurity role.
  • Strong knowledge of Application Security fundamentals, including OWASP Top 10, Common Weakness Enumeration (CWE), Secure Design Principles, Web and API vulnerability remediation.
  • Experience with Application Security tooling such as SAST, DAST, SCA, Snyk, Semgrep, Checkmarx, SonarQube, OWASP Dependency-Check, OWASP ZAP, Trivy.
  • Experience integrating automated security controls into CI/CD pipelines using tools such as Jenkins, GitHub Actions, or GitLab CI.
  • Experience performing vulnerability analysis, triage, prioritization, and providing remediation guidance to development teams.
  • Ability to read and analyze source code with hands-on experience in at least one programming language such as Java, Python, or Go.
  • Working knowledge of cloud security concepts in AWS, Azure, or GCP, including IAM roles and permissions, Security Groups, VPCs, Common cloud configuration risks.
  • Fluent English (spoken and written).
  • Preferred: Experience working within FinTech or Enterprise SaaS environments.
  • Preferred: Knowledge of security compliance frameworks such as SOC 2, ISO 27001, PCI DSS.
  • Preferred: Experience leveraging GenAI/LLMs to improve Application Security processes or developer productivity.
  • Preferred: Practical experience conducting threat modeling using methodologies such as STRIDE.
  • Preferred: Hands-on experience with containerized environments using Docker and Kubernetes.
  • Preferred: Offensive security experience, including penetration testing, red teaming, bug bounty participation, Capture The Flag (CTF) competitions, or certifications such as OSCP or eJPT.
  • Strong analytical and problem-solving skills.
  • Excellent communication and stakeholder management abilities.
  • Collaborative mindset with experience working alongside software engineering teams.
  • Passion for secure software development and continuous improvement.
  • Ability to thrive in a remote, fast-paced, and technology-driven environme

Devoteam is a technology consulting company using technology and human-centric values to drive digital transformation, with over 25 years of passion for technology and a presence in 18+ countries across EMEA and beyond.

IT ConsultingMid-sizedevoteam.com

Details

Apply routeSmartrecruiters
Salary not disclosed