Application Security Engineer
Summary
Drive secure software development by integrating security into CI/CD, performing assessments, and mentoring teams on secure coding and threat modeling.
Emagine is seeking an Application Security Engineer to join a collaborative and dynamic project environment in Portugal. This role is ideal for a professional with a strong software development background who has transitioned into Application Security, looking to drive Secure SDLC practices, improve application security maturity, and support development teams in building secure applications by design.
You will work closely with Software Engineers, Architects, DevOps teams, and Cybersecurity specialists to integrate security throughout the software development lifecycle, perform security assessments, coordinate penetration testing activities, and promote secure coding best practices across the organization.
What You'll Be Working On
Promote and implement Secure SDLC practices across software development teams.
Review application architectures and participate in threat modelling activities.
Analyse and prioritize vulnerabilities identified through Pentests, SAST, DAST, dependency scanning, and container scanning.
Support development teams in the remediation of security vulnerabilities and implementation of secure coding practices.
Coordinate penetration testing activities with external partners and validate remediation actions.
Integrate security controls into CI/CD pipelines and contribute to DevSecOps initiatives.
Deliver secure coding workshops, create technical guidelines, and help establish Security Champions across development teams.
Collaborate with cross-functional teams to continuously improve application security processes and standards.
What We're Looking For
Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or a related field.
Previous experience in Software Development followed by Application Security responsibilities.
Strong knowledge of Secure SDLC methodologies and secure software development principles.
Practical experience with OWASP Top 10, OWASP ASVS, Threat Modelling, and Secure Coding practices.
Experience analysing vulnerabilities generated through SAST, DAST, Dependency Scanning, Container Scanning, and Penetration Testing.
Knowledge of Authentication and Authorization protocols including OAuth2, OpenID Connect, JWT, and API Security.
Experience with Java (Spring Boot) and/or C# (.NET Framework / .NET Core / ASP.NET).
Experience working with Linux environments and basic shell scripting.
Cloud experience, preferably with AWS and/or Azure.
Experience integrating security into CI/CD pipelines and supporting DevSecOps initiatives.
Strong analytical, communication, mentoring, and stakeholder management skills.
Professional level of English.
Nice to Have
Experience with Angular, JavaScript, or TypeScript.
Experience using tools such as SonarQube, Checkmarx, Fortify, Veracode, Snyk, OWASP ZAP, Burp Suite, Trivy, or Dependabot.
Knowledge of cryptography, TLS, secret management, and secure API design.
Experience defining security metrics and application security governance.
Location & Eligibility
Candidates must be based in Portugal.
Hybrid working model - 2/3x per week, Lisbon.
About emagine
At emagine, we value diversity, inclusion, and equal opportunities. We believe that different perspectives drive innovation and create stronger teams, and we are committed to fostering an inclusive environment where everyone can thrive. We work with leading international clients on innovative and high-impact projects, offering opportunities to grow both professionally and personally.
If you are interested in this opportunity, we encourage you to apply and become part of a dynamic and forward-thinking environment.
To learn more about us, visit our website: