Devoteam Cyber Trust | Application Security Engineer | Mobility Sector

Devoteam
Portugal
Workplace: HybridFull timeFunction: CybersecuritySkills: ["Communication","Risk management","Collaboration","Analytical mindset","Training","Mentoring","Influence without authority"]

Ensure products and applications are secure from inception through operations by defining Secure SDLC practices, integrating security requirements into the development lifecycle, and supporting architecture reviews and threat modeling. You’ll analyze vulnerability findings from penetration tests, SAST/DAST, dependency and container scanning, prioritize and support remediation with SLAs, and coordinate penetration testing with external vendors. You’ll also drive DevSecOps by integrating security controls into CI/CD pipelines and deliver secure coding training aligned with OWASP.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Devoteam
Devoteam
4 days ago

Devoteam Cyber Trust | Application Security Engineer | Mobility Sector

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 21 hours agoStatus: Live

Job Summary

Ensure products and applications are secure from inception through operations by defining Secure SDLC practices, integrating security requirements into the development lifecycle, and supporting architecture reviews and threat modeling. You’ll analyze vulnerability findings from penetration tests, SAST/DAST, dependency and container scanning, prioritize and support remediation with SLAs, and coordinate penetration testing with external vendors. You’ll also drive DevSecOps by integrating security controls into CI/CD pipelines and deliver secure coding training aligned with OWASP.
Location: Portugal
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Define and promote Secure SDLC practices, integrating security requirements into the development lifecycle.
  • •Participate in architecture reviews and solution designs, and conduct threat modeling sessions.
  • •Analyze vulnerability findings from penetration tests, vulnerability assessments, SAST/DAST, dependency scanning, and container scanning; classify and prioritize vulnerabilities.
  • •Provide technical support during remediation, track remediation plans and SLAs, and coordinate penetration testing scope and vendor activities.
  • •Drive DevSecOps by integrating security controls into CI/CD pipelines, automating security checks, defining security metrics/KPIs, and running secure coding workshops aligned with OWASP.

Key Requirements

  • •Previous experience in software development and application architecture transitioning into an Application Security role.
  • •Ability to understand code, architecture, and development processes to analyze and resolve vulnerabilities.
  • •Solid experience with at least one stack: Java (Spring Boot, REST APIs, Maven) or C#/.NET (including ASP.NET).
  • •Practical application security expertise including OWASP Top 10/ASVS, threat modeling, authentication/authorization (OAuth2, OpenID Connect, JWT), and API security.
  • •Experience with security tooling such as SonarQube, Checkmarx, Fortify, Veracode, Snyk, Dependabot, OWASP ZAP, Burp Suite, or Trivy.
Experience:Application securityDevSecOpsCybersecurity
Skills:CommunicationRisk managementCollaborationAnalytical mindsetTrainingMentoringInfluence without authority
Languages:English
Tech Stack:JavaSpring BootREST APIsMavenC#.NET Framework.NET CoreASP.NETAngularJavaScriptTypeScriptLinuxShell ScriptingAWSAzureGoogle CloudOWASP Top 10OWASP ASVSThreat modelingOAuth2

Company Brief

Devoteam
Devoteam is an IT consulting firm specializing in digital transformation, cloud, cybersecurity, and data solutions for enterprise clients across Europe and the Middle East, combining technology partnerships with management consulting services.
Industry: Consulting
Company Size: Enterprise (1,001+ employees)
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Paris, France
Founded: 1995
WebsiteLinkedIn