Intermedia
Posted 1mo ago

Application Security Engineer

Intermedia
Portugal
OnsiteFull Time
Responsibilities
  • reviewing design
  • performing assessments
  • advising teams
Requirements
  • 3–5 years application security experience
  • Bachelor's or Master's in a related field
  • Knowledge of OWASP and secure coding
  • DevSecOps/SDLC experience
  • Static/dynamic scanning (BurpSuite, ZAP, Snyk)
  • Python preferred
  • Cloud and container security (AWS, Azure
  • Docker
  • Kubernetes)
Technical tools mentioned
OWASPSDLCBurpSuiteZAPSnykPythonAWSAzureDockerKubernetesCTF

Job description

*ALL CANDIDATES MUST BE LOCATED IN PORTUGAL*

About Intermedia  

Are you looking for a company where YOUR VOICE is heard? Where you can MAKE A DIFFERENCE? Do you THRIVE in a FAST-PACED work environment? Do you wake every morning EXCITED to work with GREAT PEOPLE and create SUCCESS TOGETHER? Then Intermedia is the place for you. 

Intermedia has established itself as a leading provider of cloud communications and collaboration tech that allows companies to connect better. We have a strong track record of growth, profitability, and creating an environment where everyone matters. Everyone. While we are fast-paced and admittedly a bit intense, we promise that you won’t be bored. You will find Intermedia is a place where you can indulge your passion for creating and supporting great cloud technology. What’s more, we always look to promote from within and have many employees who have been with us 10, 15, and 20+ years! 

Culture at Intermedia is built on teamwork and transparency.  We hold each other accountable and always have each other’s back! 

Are you ready to make your mark? 

About the Role
 

Intermedia has a wide portfolio of internally developed application software, ranging from web and desktop apps to lower level PBX solutions. Due to the growing demand for integrating security activities into diverse development processes, Intermedia is looking for an experienced and self-motivated Application Security Engineer to help us deliver built-in security to our products.

As part of the Global Security team, you will support our company wide application security program, helping the company build secure products. You will be the voice of security for all things related to application security to our spectrum of engineering teams, guiding the architecture and execution of our SDLC throughout the enterprise. This position is an individual contributor role, reporting directly to the Manager, Application Security.

What you will be doing:

  • Perform design and architecture review of new features, suggest security requirements
  • Collaborate with DevOps and engineering teams, advising on security features and best practices in SDLC
  • Utilize static security scanning tools, review findings and coordinate remediation actions
  • Perform ongoing manual security assessments
  • Review the results of external penetration tests and communicate suggested fixes to development teams
  • Provide on-demand support on application security topics
  • Drive process improvement ideas
  • Assist with vetting and intake of defects from 3rd party security researchers via our Bug Bounty program

What you will bring to the role:

  • 3 - 5 years of experience in the application security field
  • Bachelors or Master Degree in related field of expertise
  • Knowledge of secure coding best practices and industry standards (such as OWASP) and the ability to apply them to different programming languages
  • Familiarity with SDLC and DevSecOps concepts and hands-on experience in implementing them
  • Knowledge and/or hands on experience with identifying A.I. threats in a security landscape
  • Experience in using static and dynamic security scanning tools (such as BurpSuite, ZAP, and Snyk, or other related technologies)
  • Experience with programming languages such as Python is preferred
  • Ability to explain application security threats and mitigation options to both developers and project managers
  • Good communication skills in written and verbal English
  • Experience and/or knowledge in securing applications within cloud platforms (AWS, Azure) and containerized environments (Docker, Kubernetes)
  • Participation in CTF challenges and bug-bounty programs

Diversity, Inclusion, and Equal Opportunity

We hire, promote, and compensate employees based on their ability to perform their job responsibilities, without regard to race, color, creed, religion, sex, gender, marital status, national origin, ancestry, age, citizenship, physical or mental disability, sexual orientation, or any other basis protected by applicable law (collectively referred to in our Code of Conduct as “Protected Classes”). We do not tolerate employment discrimination in the workplace, and we are committed to making reasonable accommodations for identified disabilities or other limitations as required by all applicable laws. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. 

About Intermedia

Provides cloud-based business communication and collaboration software.

Year founded
1993
Employees
1350
Organization type
Private
Latest investment
Raised $345.00M Debt Financing (2024) — led by Existing Lenders
Headquarters
US

Similar jobs

Application Security Engineer roles
1w
Save
Mark Applied
Hide
Senior Application Security Engineer
Portugal
RemoteFull Time
Intapp
IntappNASDAQ: INTA: Cloud business management software for professional and financial services.
3+ YOERequires 3+ years in application security or 5+ years across development and security, Python and TypeScript backend experience, SCA/SAST/DAST analysis, testing, code review, and strong communication skills.
Python, TypeScript, SCA, SAST, DAST
1w
Save
Mark Applied
Hide
Lead Application Security Engineer
Portugal
RemoteFull Time
Remofirst
Remofirst: Global employer of record and payroll platform for remote teams
Hands-on application security experience with code review, threat modeling, offensive testing, AWS security, customer-facing identity, API security, and risk-based communication.
Python, Java, Django, FastAPI, Spring Boot, Kafka, RabbitMQ, PostgreSQL, MongoDB, AWS, IAM, Service Control Policies (SCPs), EKS, RDS, S3, Auth0, SAML, OIDC, REST APIs, Terraform, SAST, DAST, Kubernetes, SCIM
2w
Save
Mark Applied
Hide
Devoteam Cyber Trust | Application Security Engineer | Mobility Sector
Lisboa, Lisbon, Portugal
HybridFull Time
Devoteam
Devoteam: Global IT consulting firm providing digital transformation and cloud services.
Experience in software development and application architecture with hands-on cloud and application security skills; able to perform threat modeling, vulnerability analysis, and secure SDLC enablement.
Java, Spring Boot, Maven, C#, .NET Framework, .NET Core, ASP.NET, Angular, Linux, Shell Scripting, AWS, Azure, Google Cloud, SonarQube, Checkmarx, Fortify, Veracode, Snyk, Dependabot, OWASP ZAP, Burp Suite, Trivy
1mo
Save
Mark Applied
Hide
Graduate Programme 2027: Information Security Engineer (Appsec)
Barcelona or Dubai or Krakow or Lisbon or London or Madrid or Porto or Poland or Portugal or Spain or United Arab Emirates or United Kingdom
zł16k/mo HybridFull Time
Revolut
Revolut: Global financial super app for spending, saving, and investing.
Predicted/achieved 2:1 degree in a STEM subject (2025–2027 grads), coding portfolio, strong problem-solving, English fluency, full-time availability from 2027, willingness to work hybrid (≈3 days/week) and travel to a local Revolut office.
SAST, DAST, OWASP
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Lisbon, /, Portugal
€80k-€105k/yr HybridFull Time
Thought Machine
Thought Machine: Provides cloud-native core banking and payments software for banks.
Expertise in application security including web app pentesting, threat modelling, security tooling, cloud/container security (AWS/GCP/Kubernetes/Docker), and programming in Python, Go or Java; experience in DevOps security and mentoring developers.
Python, Go, Java, Burp Suite, OWASP Top 10, AWS, GCP, Kubernetes, Docker
2mo
Save
Mark Applied
Hide
Mid-level Application Security Engineer (Hybrid - Lisbon)
Lisbon, Lisbon, Portugal
HybridFull Time
Cognizant
CognizantNasdaq: CTSH: Provides global information technology and business process outsourcing services.
Proven experience reverse engineering Android apps or offensive security; strong Android security knowledge; static and dynamic analysis expertise; familiarity with JNI, Android SDK, Java/Kotlin; proficiency with Ghidra/IDA Pro, Frida, Burp Suite; strong communication.
Ghidra, IDA Pro, Frida, Burp Suite, apktool, hexdump, Android SDK, Java, Kotlin, JNI, ARM
2mo
Save
Mark Applied
Hide
Mid-level Application Security Engineer (Hybrid - Lisbon)
Lisbon, Lisbon, Portugal
HybridFull Time
Cognizant
CognizantNASDAQ: CTSH: Provides IT consulting and technology services to global enterprises.
3+ YOEExperience reverse engineering Android apps, strong Android security knowledge, proficiency with static/dynamic analysis, Java/Kotlin familiarity, excellent communication and independent problem-solving skills.
Ghidra, IDA Pro, Frida, Burp Suite, apktool, hexdump, Android SDK, Java, Kotlin, ARM
2mo
Save
Mark Applied
Hide
Mid-level Application Security Engineer (Hybrid - Lisbon)
Lisbon, Lisboa, Portugal
HybridFull Time
Cognizant
CognizantNasdaq: CTSH: Provides IT consulting and digital business process services.
Experience reversing or assessing Android applications, understanding of Android internals/JNI, static and dynamic analysis, proficiency with analysis tools, strong problem-solving and communication, ability to work independently.
Ghidra, IDA Pro, Frida, Burp Suite, apktool, hexdump, Android SDK, Java, Kotlin, ARM