{"id":7848,"date":"2026-07-31T15:54:12","date_gmt":"2026-07-31T15:54:12","guid":{"rendered":"https:\/\/www.hexa-group.pt\/jobs\/application-security-engineer-senior\/"},"modified":"2026-08-12T14:54:04","modified_gmt":"2026-08-12T14:54:04","slug":"application-security-engineer-senior","status":"publish","type":"company_job","link":"https:\/\/www.hexa-group.pt\/pt\/jobs\/application-security-engineer-senior\/","title":{"rendered":"Application Security Engineer | Senior"},"content":{"rendered":"<p>Linguas: Portugu\u00eas C2 Ingl\u00eas C1 | Franc\u00eas Valorizado<br \/>\nModelo Hibrido<br \/>\nRate: 345\u20ac<\/p>","protected":false},"excerpt":{"rendered":"<p>DH037317 \u00b7 Portugal \u00b7 banque \u00b7 Open<\/p>","protected":false},"featured_media":0,"template":"","meta":{"_acf_changed":false,"boond_id":"6904","boond_reference":"DH037317","boond_place":"mondeeuropeportugal","boond_place_label":"Portugal","boond_state":12,"boond_state_label":"Open","boond_start_date":"immediate","boond_closing_date":"2026-08-19","boond_answer_date":"2026-07-30","boond_duration":255,"boond_raw_description":"Linguas: Portugu\u00eas C2 Ingl\u00eas C1 | Franc\u00eas Valorizado \nModelo Hibrido \nRate: 345\u20ac","boond_criteria":"ABOUT THE OPPORTUNITY\n\nWe are looking for a Senior Application Security Engineer to support application security initiatives within a regulated banking environment. Based in Lisbon or Porto with a hybrid working model, this role combines technical depth, advisory capability and leadership responsibilities to strengthen secure development practices across international software delivery teams.\n\nWHAT YOU WILL DO\n\n- Contribute to the application security strategy, roadmap and continuous improvement of secure software development practices.\n- Provide expert advisory support to development squads on application security, vulnerability remediation and secure implementation.\n- Lead complex vulnerability analysis activities, including prioritization, remediation guidance and false positive optimization.\n- Mentor junior application security engineers and support knowledge sharing across technical teams.\n- Drive the continuous improvement and adoption of the Secure Software Development Lifecycle framework.\n- Facilitate workshops, training sessions and open guidance sessions for developers and technical leads.\n- Create and maintain technical documentation, best practices and practical guidance for secure development.\n- Monitor and optimize security metrics, including KPIs, KRIs and OKRs.\n- Analyze emerging threats, follow technology trends and propose proof of concepts for security improvements.\n\nWHAT WE ARE LOOKING FOR\n\n- More than 9 years of professional experience in cybersecurity, application security or DevSecOps.\n- Higher education in engineering, computer science, cybersecurity or a related technical field.\n- Proven experience leading application security initiatives or security improvement projects.\n- Strong autonomy in project delivery, stakeholder guidance and technical decision support.\n- Ability to influence development teams and promote secure engineering practices across different environments.\n- Professional working proficiency in English for an international context.\n- Clear communication skills, with the ability to explain technical risks and remediation actions to different audiences.\n\nTECHNICAL SKILLS\n\n- SAST, SCA, Container Image Scanning and DAST.\n- Infrastructure as Code scanning and secrets detection.\n- Security integration in CI\/CD pipelines.\n- OWASP Top 10 vulnerabilities and secure coding practices.\n- Vulnerability analysis, remediation prioritization and false positive optimization.\n- End-of-support lifecycle management.\n- Cloud security across private, public, regulated and hybrid environments.\n- Python, C++, C# or comparable programming languages.\n- Hadoop, Angular or comparable development frameworks.\n- Secure Software Development Lifecycle practices.\n- Security metrics, including KPIs, KRIs and OKRs.\n\nNICE TO HAVE\n\n- Professional working proficiency in French.\n- Previous experience in an international banking environment.\n- Experience with developer enablement, technical training or security community initiatives.\n- Familiarity with awareness platforms or secure coding learning tools.\n\nCOMPENSATION TRANSPARENCY\n\nBase salary range: EUR 28,000 - EUR 40,000 gross\/year\nTotal compensation: up to EUR 50,000\/year\nThe salary range is based on objective and gender-neutral criteria, including required competencies, professional experience, level of responsibility and role requirements. Final compensation will be determined according to the candidate's profile and position requirements.\n\nWHAT WE OFFER\n\n- Private health insurance from the first day, with no waiting period and the possibility of family extension.\n- Confidential mental health support through dedicated psychological support, content and live sessions.\n- Continuous learning and certification support to strengthen long-term professional capability.\n- Flexibility whenever the role and delivery context allow it, supporting sustainable performance and daily balance.\n- Childcare vouchers and practical family support measures.\n- Team moments, shared milestones and a close leadership presence when it matters most.\n- Upskilling opportunities in information security, cybersecurity best practices, quality management and AI governance where relevant to the role.\n\nEQUAL OPPORTUNITY\n\nHexa is committed to equal opportunity, inclusive recruitment and fair assessment practices. In alignment with the principles of the Portuguese Diversity Charter, we value different backgrounds, perspectives and experiences, and we make employment decisions based on competencies, responsibility level, experience and role requirements.\n\nHEXA LIFE\n\nAt Hexa, every professional is a Builder. We work with honesty, mutual support and agility, combining individual expertise with shared responsibility. Joining Hexa means contributing to solutions, relationships and delivery practices that are built together with quality, transparency and long-term impact.","boond_expertise_area":"banque","boond_is_visible":true,"boond_created_at":"2026-07-30T12:38:16+0200","boond_created_ts":1785407896,"boond_updated_at":"2026-07-31T17:43:31+0200","boond_type_of":1,"boond_mode":1,"boond_active_positionings":0,"boond_manager_id":"17497","boond_agency_id":"1","boond_agency_label":"Hexa Consulting","boond_pole_id":"1","job_location":"Portugal","job_contract":"banque","job_business_unit":"Hexa Consulting","job_seniority":"Senior","job_title_without_seniority":"Application Security Engineer","job_remote_url":"","job_source":"boond","manatal_hash":"","manatal_status":"","job_last_synced_at":"2026-08-12 14:54:04"},"class_list":["post-7848","company_job","type-company_job","status-publish","hentry"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/company_job\/7848","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/company_job"}],"about":[{"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/types\/company_job"}],"version-history":[{"count":1,"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/company_job\/7848\/revisions"}],"predecessor-version":[{"id":7859,"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/company_job\/7848\/revisions\/7859"}],"wp:attachment":[{"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/media?parent=7848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}