Application Security Engineer (Remote)
emagine · Portugal ·
- Work mode
- Remote
- Seniority
- Senior
- Employment
- Contract
- Category
- Security
emagine · Portugal ·
allwynuk · Watford, England, United Kingdom
NDA Recruitment · UA
gen-digital · CZE - Prague
teliogroup · Hamburg
An Application Security Engineer who runs penetration tests and vulnerability assessments on internal web apps and APIs, integrates SAST/DAST/SCA scanning into Jenkins CI/CD pipelines, and writes security reports while coaching developers on threat modeling and secure coding. Fully remote with flexible hours.
We are seeking an experienced Application Security Engineer to enhance our application security posture. The ideal candidate will possess a proven track record in performing penetration tests and vulnerability assessments, with hands-on experience integrating security tools into CI/CD pipelines. This role requires strong communication skills to produce clear security reports and guide development teams in secure coding practices.
Plan and conduct penetration tests on internal applications, and deliver clear, detailed reports.
Produce security assessment reports covering risk assessment, vulnerability impact, exploitation steps, and actionable remediation guidance for development teams.
Integrate SAST, DAST, and SCA scanning into CI/CD pipelines, and train developers to use these tools effectively.
Troubleshoot and resolve CI/CD issues related to security scanning, including Jenkins configuration, scanner failures, authentication problems, and pipeline execution errors.
Support development teams with threat modeling, security reviews, and pre-release security assessments, helping resolve security blockers before launch.
Define and standardize security engagement procedures so teams know how and when to involve Security.
Act as a trusted security partner to engineering teams, promoting secure development practices.
Proven experience performing penetration tests on web applications and APIs.
Hands-on experience with SAST, DAST, and SCA tools and their integration into CI/CD pipelines.
Working knowledge of CI/CD platforms, ideally Jenkins, including troubleshooting pipeline and scanner integration issues.
Experience with threat modeling and secure design reviews.
Strong understanding of common vulnerability classes (e.g., OWASP Top 10) and remediation techniques.
Excellent written communication, with the ability to produce clear, structured security reports for both technical and non-technical audiences.
Ability to train and collaborate with developers, and to explain security issues in a practical, constructive way.
Security certifications (e.g., OSCP, GWAPT, CEH, CSSLP).
Experience defining or improving security processes and governance.
Scripting or programming skills (e.g., Python, Bash) for automation.
Familiarity with cloud and containerized environments.
Short availability to start the project
This is a remote position with flexible working hours. Candidates are expected to have the ability to work independently and demonstrate initiative in identifying and addressing security challenges.
spgi · Virtual, Gurugram, Haryana