Overview Expleo is a trusted partner for your innovation journey. As a global engineering, technology and consulting service provider, we are ideally positioned to help you achieve your ambitions and future-proof your business. With a smart blend of bold thinking and reliable execution, we’re able to fast-track innovation through each step of your value chain.We are strategically positioned to build value, with a global footprint across 30 countries.We are as global and local as you need us to be, with strong best-in-class pan-European technological centres and unique best-shoring capabilities.We leverage a network of high value-adding affiliates in consulting and industrial excellence, and leading partners across multiple sectors to provide you with the most comprehensive services and solutions in an ever-changing environment. Responsibilities - 5+ years of professional experience in software development and/or application architecture, with proven experience in Application Security. - Define and promote Secure SDLC and Security-by-Design practices. - Integrate security requirements into application architecture, design and development. - Lead or facilitate Threat Modeling and application security reviews. - Analyze and prioritize vulnerabilities identified through SAST, DAST, SCA, container scanning, vulnerability assessments and penetration tests. - Coordinate penetration testing activities, including scope definition, external providers, findings validation and remediation follow-up. - Provide hands-on support to development teams in vulnerability remediation and secure coding. - Promote best practices around authentication, authorization, API security, data protection, cryptography and secrets management. - Integrate security controls and automated security testing into CI/CD pipelines, supporting DevSecOps adoption. - Develop security guidelines, standards and metrics, and promote security awareness through Secure Coding workshops and Security Champions. Essential skills - Strong understanding of OWASP Top 10, OWASP ASVS, Secure Coding and Threat Modeling. - Practical knowledge of OAuth2, OpenID Connect, JWT, API Security, TLS, cryptography and secrets management. - Strong development experience in Java/Spring Boot or C#/.NET, including REST APIs. - Solid understanding of cloud environments, with real-world application deployment experience, preferably AWS and/or Azure. - Good knowledge of Linux and shell scripting. - Experience with application security tools such as SonarQube, Checkmarx, Fortify, Veracode, Snyk, Dependabot, OWASP ZAP, Burp Suite or Trivy. - Ability to read and understand source code and application architecture and translate security findings into practical remediation. - Strong communication and collaboration skills, with the ability to act as a technical advisor and security advocate for development teams.
Senior Security Engineer - Application Security
Outsystems
Senior Application Security Engineer
Intapp
Application Security Engineer
Igaminghunt
Devoteam Cyber Trust | Application Security Engineer | FinTech Sector
Devoteam
Devoteam Cyber Trust | Application Security Engineer | Mobility Sector
Devoteam
Cyber Security Engineer – Penetration Tester (f/m/d)
EnBW IT-Solutions