Application Security Analyst
Make an impact by working for sectors where technology is the enabler, where everything is ground-breaking and there’s a constant need to be innovative. Be part of the team that combines business knowledge, technological edge and a design experience - who complement and help each other in developing solutions and experiences for digital clients. Face challenges and learn other ways of thinking and seeing the world. There’s always room for your energy and creativity.
About the role
- Conducting analysis and threat modeling for new and existing Celfocus products/projects.
- Analyzing and discussing requirements; interacting with all participants in the software development process.
- Penetration testing web applications.
- Conducting both manual and automated testing.
- Participating in the creation and development of the company's products at all stages of their life cycle.
What are we looking for?
- A lively and flexible mind, clear logic, a detail-oriented approach.
- Capability to align with teams from Analysts, Designers, Architects, Developers to DevOps.
- Knowledge of HTTP.
- Working knowledge of programming languages
- Knowledge of the Top 10 OWASP vulnerabilities: how to find, exploit and fix them.
- Knowledge of Burp Suite or other popular web scanners like ZAP, Acunetix, Netsparker, etc.
- The desire and ability to work in a team.
- The desire to develop yourself in the field of application security.
- Knowledge of English at least at the level of reading technical documentation.
Nice to have:
- Good knowledge of Linux or Windows operating systems.
- Skills in scripting and automating your work using Powershell, Python, Bash, etc.
- Knowledge of the OWASP Application Security Verification Standard (ASVS) , OWASP Testing Guide and experience in whole product or feature planning.
- An understanding of browser security mechanisms (SOP, cookies, CSP, HSTS, etc.)
- Familiarity with various protocols and attacks against them (OAuth, JWT, websockets, etc.)
- Experience with public clouds (Azure, AWS, GCP)
- Experience with pipeline Orchestrators (Jenkins, Azure DevOps, GitLab CI/CD)
- Penetration testing experience
Personal traits:
- Ability to adapt to different contexts, teams and Clients
- Teamwork skills but also sense of autonomy
- Motivation for international projects and ok if travel is included
- Willingness to collaborate with other players
- Strong communication skills
We want people who like to roll up their sleeves and open their minds. Believe this is you? Come join the Team!
- Department
- Digital

Lisbon
About Celfocus
Celfocus delivers high-tech system integration services in the digital and cognitive space
As a Technology company, Celfocus accelerates Product & Service innovation, by promoting innovative digital capabilities and delivering business value in the most complex, mission-critical challenges.
From Strategy through Operations, collaborating in areas such as Actionable AI, Cognitive Automation and Digital – to produce the maximum benefits across Business & Technology.
Application Security Analyst
Loading application form
Already working at Celfocus?
Let’s recruit together and find your next colleague.