7 days ago
Lisbon, PortugalStaff+
Responsibilities
- Build and mature the Secure Design and Threat Modeling program, including methodology, review standards, and sign-off criteria.
- Drive shift-left security through design reviews, developer enablement, and security gating in CI/CD.
- Own API security as an organizational discipline and assess REST and GraphQL APIs.
- Support offensive security initiatives, including penetration testing and API exploitation assessment.
- Build and maintain Python-based security automation tools to scale AppSec capacity.
- Partner with developers on SAST and SCA remediation, scan optimization, and security feedback-loop improvements.
- Contribute to AI-assisted security pipelines and define vulnerability-management escalation paths, SLAs, and accountability structures.
- Influence engineering and product teams and operate at the architecture level.
Requirements
- Hands-on experience in secure design, threat modeling, API security, and offensive security.
- Penetration testing experience and understanding of real-world attack and API exploitation patterns.
- Deep practical familiarity with the OWASP Top 10.
- Strong API security experience, including REST and GraphQL APIs.
- Proficiency in Python and experience building dependable automation tools.
- Experience with shift-left programs, CI/CD security, developer enablement, and design-review processes.
- Understanding of web application and API security, cloud-native environments, and attack surface management.
- Ability to read code across languages and engage engineering teams at technical depth.
- Relevant certifications such as OSCP, OSWE, GWEB, CSSLP, CISSP, or CEH are a plus.
- Developer experience and fluency in Ruby and Scala are a plus.
- Exposure to AI-assisted security tooling or LLM security is a differentiator.
Benefits
- Comprehensive benefits package including competitive salary, annual performance bonus, and equity for full-time employees.
- Healthcare with 100% employer-paid health and dental insurance.
- Generous paid time off.
- Hybrid schedule with four days in the office and remote work available one day per week on Friday.
