Senior Application Security Engineer
Salary:
€60000-80000 - Per Annum
Locations:
Lisbon, Portugal
Type:
Permanent
Published:
September 1, 2026
Contact:
Ike Feehi
Ref:
21503
Required Skills:
Share this job
Apply

Senior Application Security Engineer

We are looking for a technically strong Senior Application Security practitioner ready to take on real ownership. You will work directly with the Head of Application Security, contributing to the Secure Design practice and helping embed security earlier across the development lifecycle.

What You'll Do

  • Help build and mature the Secure Design and Threat Modeling program, defining methodology, review standards, and sign off criteria across the organization
  • Drive early stage security initiatives, embedding security earlier in the development lifecycle through design reviews, developer enablement, and security gating within CI/CD
  • Own API security as a core discipline
  • Support offensive security initiatives across the organization
  • Build and maintain security automation using Python, creating tooling that scales the Application Security team's capacity
  • Partner directly with developers on SAST and SCA remediation, scan optimization, and reducing friction in the security feedback loop
  • Contribute to AI assisted security pipelines, defining escalation paths, SLAs, and accountability structures for vulnerability management

What We're Looking For

  • Hands on experience across secure design, threat modeling, API security, and offensive security
  • Offensive security capability including penetration testing experience and a solid understanding of real world attack and API exploitation patterns
  • Deep familiarity with the OWASP Top 10 in practice
  • API security depth, with experience assessing REST and GraphQL APIs
  • Strong Python proficiency, comfortable building automation tools that others will depend on
  • Experience running programs that embed security earlier in delivery, including CI/CD security, developer enablement, and design review processes
  • Solid understanding of web application and API security
  • Comfortable reading code across multiple languages and engaging with engineering teams at a technical depth
  • Familiarity with cloud native environments and attack surface management
  • Demonstrated ability to influence across engineering and product, operating at an architecture level
  • Relevant certifications are a plus, including OSCP, OSWE, GWEB, CSSLP, CISSP, or CEH
  • Exposure to AI assisted security tooling or LLM security is a strong differentiator

Apply

We use cookies to provide the best possible experience for our users. They help us provide essential functionality and improve site performance, and allow us to offer a more personalised experience when using the site.