Talk to us

Hexa Consulting

Application Security Engineer

Senior

Business unitHexa Consulting LocationPortugal SenioritySenior

Job criteria

ABOUT THE OPPORTUNITY

We are looking for a Senior Application Security Engineer to support application security initiatives within a regulated banking environment. Based in Lisbon or Porto with a hybrid working model, this role combines technical depth, advisory capability and leadership responsibilities to strengthen secure development practices across international software delivery teams.

WHAT YOU WILL DO

- Contribute to the application security strategy, roadmap and continuous improvement of secure software development practices.
- Provide expert advisory support to development squads on application security, vulnerability remediation and secure implementation.
- Lead complex vulnerability analysis activities, including prioritization, remediation guidance and false positive optimization.
- Mentor junior application security engineers and support knowledge sharing across technical teams.
- Drive the continuous improvement and adoption of the Secure Software Development Lifecycle framework.
- Facilitate workshops, training sessions and open guidance sessions for developers and technical leads.
- Create and maintain technical documentation, best practices and practical guidance for secure development.
- Monitor and optimize security metrics, including KPIs, KRIs and OKRs.
- Analyze emerging threats, follow technology trends and propose proof of concepts for security improvements.

WHAT WE ARE LOOKING FOR

- More than 9 years of professional experience in cybersecurity, application security or DevSecOps.
- Higher education in engineering, computer science, cybersecurity or a related technical field.
- Proven experience leading application security initiatives or security improvement projects.
- Strong autonomy in project delivery, stakeholder guidance and technical decision support.
- Ability to influence development teams and promote secure engineering practices across different environments.
- Professional working proficiency in English for an international context.
- Clear communication skills, with the ability to explain technical risks and remediation actions to different audiences.

TECHNICAL SKILLS

- SAST, SCA, Container Image Scanning and DAST.
- Infrastructure as Code scanning and secrets detection.
- Security integration in CI/CD pipelines.
- OWASP Top 10 vulnerabilities and secure coding practices.
- Vulnerability analysis, remediation prioritization and false positive optimization.
- End-of-support lifecycle management.
- Cloud security across private, public, regulated and hybrid environments.
- Python, C++, C# or comparable programming languages.
- Hadoop, Angular or comparable development frameworks.
- Secure Software Development Lifecycle practices.
- Security metrics, including KPIs, KRIs and OKRs.

NICE TO HAVE

- Professional working proficiency in French.
- Previous experience in an international banking environment.
- Experience with developer enablement, technical training or security community initiatives.
- Familiarity with awareness platforms or secure coding learning tools.

COMPENSATION TRANSPARENCY

Base salary range: EUR 28,000 - EUR 40,000 gross/year
Total compensation: up to EUR 50,000/year
The salary range is based on objective and gender-neutral criteria, including required competencies, professional experience, level of responsibility and role requirements. Final compensation will be determined according to the candidate's profile and position requirements.

WHAT WE OFFER

- Private health insurance from the first day, with no waiting period and the possibility of family extension.
- Confidential mental health support through dedicated psychological support, content and live sessions.
- Continuous learning and certification support to strengthen long-term professional capability.
- Flexibility whenever the role and delivery context allow it, supporting sustainable performance and daily balance.
- Childcare vouchers and practical family support measures.
- Team moments, shared milestones and a close leadership presence when it matters most.
- Upskilling opportunities in information security, cybersecurity best practices, quality management and AI governance where relevant to the role.

EQUAL OPPORTUNITY

Hexa is committed to equal opportunity, inclusive recruitment and fair assessment practices. In alignment with the principles of the Portuguese Diversity Charter, we value different backgrounds, perspectives and experiences, and we make employment decisions based on competencies, responsibility level, experience and role requirements.

HEXA LIFE

At Hexa, every professional is a Builder. We work with honesty, mutual support and agility, combining individual expertise with shared responsibility. Joining Hexa means contributing to solutions, relationships and delivery practices that are built together with quality, transparency and long-term impact.