Middle · Гибрид · Лиссабон, Португалия · Английский B2
Навыки
Angular
API (интеграции)
ASP.NET
AWS
Bash / shell
CI/CD
C#
Ещё 17
DevSecOps
.NET
ISO 27001 / PCI DSS
Java
JavaScript
Linux
Maven
OWASP
Пентест
REST API
Управление рисками
SAST / DAST
Жизненный цикл разработки
SOLID и паттерны
Spring
TypeScript
Управление уязвимостями
О компании и продукте
Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located across EMEA, we aim to establish cybersecurity as an enabler of business success rather than a gatekeeper. We leverage an end-to-end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and medium-sized companies from all sectors and industries
Задачи
Application Security
Define and promote Secure SDLC practices
Integrate security requirements into the development lifecycle
Participate in architecture reviews and solution designs
Conduct threat modeling sessions
Support teams in implementing authentication, authorization, and data protection mechanisms
Vulnerability Management
Analyze results originating from
Penetration Tests
Vulnerability Assessments
SAST / DAST
Dependency Scanning
Container Scanning
Classify and prioritize vulnerabilities
Provide technical support during remediation
Track remediation plans and their respective SLAs
Penetration Testing Coordination
Define test scope
Coordinate with external vendors
Validate findings
Ensure tracking and closure of recommendations
Training & Enablement
Conduct Secure Coding workshops
Promote OWASP Top 10 and secure development best practices
Support the creation of Security Champions within teams
Требования
Cloud knowledge with hands-on experience in production application deployments
Since 2009, previously known as INTEGRITY, our team based in Portugal is specialised in providing cutting-edge Managed Security Services that combine its expertise and proprietary technology to consistently and effectively reduce the cyber risk of our clients
The comprehensive service range includes Persistent Intrusion Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management
ISO 27001 (Information Security) and ISO 9001 (Quality) certified, PCI-QSA, and member of CREST and CIS - Centre for Internet Security, we provide services to a considerable number of clients, operating in more than 20 countries
Будет плюсом
Knowledge of major cloud platforms (AWS and/or Azure preferred
Google Cloud or others are relevant and transferable)
Application Security Expertise
Practical knowledge of
OWASP Top 10, OWASP ASVS, and Secure Coding best practices
Threat Modeling
Authentication & Authorization (including OAuth2, OpenID Connect, and JWT)
Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайте — jobs.smartrecruiters.com.
Признаки мошенничества
Просят предоплату, «залог» или деньги за обучение и оборудование.
Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
Быстро уводят в мессенджер и торопят с решением.
Обещают большой доход без опыта и без деталей задач.
Настоящий работодатель не просит денег и платёжных данных до трудоустройства.
Продолжить поиск
Похожие вакансии
Причина сходства указана на каждой карточке
R
Почему похожа: похожая специализация · тот же грейд