Application Security Engineer
Intermedia Intelligent Communications2 months ago
Remote, PortugalMid Level / Senior
Responsibilities
- Review designs and architectures for new features and recommend security requirements.
- Advise engineering and DevOps teams on application security features, secure coding, and SDLC best practices.
- Use static and dynamic security scanning tools, review findings, and coordinate remediation.
- Conduct ongoing manual application security assessments.
- Review external penetration-test results and communicate recommended fixes to development teams.
- Provide application security support, drive process improvements, and vet defects submitted by third-party security researchers through the Bug Bounty program.
Requirements
- Require 3–5 years of experience in application security.
- Require a bachelor’s or master’s degree in a related field.
- Knowledge of secure coding practices, OWASP, and applying security principles across programming languages.
- Familiarity with SDLC and DevSecOps, including hands-on implementation experience.
- Knowledge or hands-on experience identifying AI threats in security environments.
- Experience with static and dynamic security scanning tools such as BurpSuite, ZAP, and Snyk.
- Python experience is preferred.
- Ability to explain application security threats and mitigations to developers and project managers.
- Strong written and verbal English communication skills.
- Experience securing applications in AWS or Azure and in Docker or Kubernetes environments.
- Participation in CTF challenges and bug-bounty programs.