ABOUT THE OPPORTUNITY
We are looking for a Mid Application Security Engineer to support secure software delivery in the fintech sector. This role focuses on application security practices, vulnerability analysis, automation of security controls and close collaboration with engineering teams in a remote work model.
WHAT YOU WILL DO
- Analyze application and API security risks across modern software environments.
- Triage, classify and prioritize security vulnerabilities, providing clear remediation guidance to engineering teams.
- Support the integration of automated security checks and approval gates into CI/CD pipelines.
- Contribute to secure design reviews and help improve application security practices across development workflows.
- Review source code to identify security issues and support effective remediation.
- Collaborate with technical teams to strengthen cloud application security and reduce common configuration risks.
WHAT WE ARE LOOKING FOR
- Mid-level experience in application security, secure software development or security engineering.
- Ability to work autonomously with engineering teams and translate security findings into practical technical actions.
- Solid understanding of secure design principles, web and API security risks and vulnerability remediation.
- Professional working proficiency in English and a collaborative, responsible and solution-oriented mindset.
- Interest in continuous improvement, security standardization and the optimization of secure delivery practices.
TECHNICAL SKILLS
- OWASP Top 10, CWE, secure design principles and common web and API vulnerability remediation.
- SAST, DAST or SCA tools such as Snyk, Semgrep, Checkmarx, SonarQube, dependency-check, OWASP ZAP or Trivy.
- CI/CD security integration using tools such as Jenkins, GitHub Actions or GitLab CI.
- Vulnerability triage, risk classification and remediation guidance.
- Source code analysis and hands-on proficiency in at least one programming language such as Java, Python or Go.
- Public cloud security fundamentals across AWS, Azure or GCP, including IAM, network security controls and common configuration risks.
NICE TO HAVE
- Experience in financial software, fintech or enterprise SaaS environments.
- Familiarity with SOC 2, ISO/IEC 27001 or PCI DSS.
- Experience using GenAI or LLMs to improve application security productivity.
- Practical threat modeling experience, including methodologies such as STRIDE.
- Familiarity with Docker or Kubernetes-based application environments.
- Offensive security experience, bug bounty or CTF participation, or certifications such as OSCP or eJPT.
COMPENSATION TRANSPARENCY
Base salary range: EUR 19,000 - EUR 24,000 gross/year
Total compensation: up to EUR 32,000/year
The salary range is based on objective and gender-neutral criteria, including required competencies, professional experience, level of responsibility and role requirements. Final compensation will be determined according to the candidate's profile and position requirements.
WHAT WE OFFER
- Private health insurance from the first day, with no waiting periods and optional family extension.
- Confidential mental health support through TEAM 24, including psychological support, content and live sessions.
- Continuous training and certification support to strengthen long-term professional growth.
- Flexibility whenever the role and context allow it, supporting sustainable delivery and daily balance.
- Childcare vouchers and practical family support measures.
- Team moments, shared milestones and leadership presence when it matters most.
- Upskilling opportunities in information security, AI governance, cybersecurity best practices and quality management.
EQUAL OPPORTUNITY
Hexa is committed to equal opportunity and inclusive recruitment. We promote fair, objective and respectful selection processes aligned with the principles of the Portuguese Diversity Charter.
HEXA LIFE
At Hexa, we are all Builders. You will join a collaborative environment built on honesty, mutual support and agility, where people are encouraged to contribute, learn and improve the solutions, projects and professional relationships they help build.
Application Security Engineer
Planck Technologies
Senior Application Security Engineer
Intapp
Application Security Engineer
Igaminghunt
Backup Security Monitoring Engineer
Olisipo
AI Security Engineer
Expleo Jobs Pt En
Devoteam Cyber Trust | Application Security Engineer | FinTech Sector
Devoteam