🎁 Antes de se candidatar, treine esta entrevista. Crie sua conta grátis no WorkMundi e ganhe um Treinamento de Entrevista no HelpsYouSpeak — sem custo, sem cartão. Quero meu treinamento →
We are looking for a Senior Application Security Engineer to join the security team and play a key role in protecting a growing portfolio of cloud-based applications and services. Key Responsibilities Drive and oversee the implementation of Secure Software Development best practices across development and QA teams. Advise developers and technical teams on application security, secure coding, and the OWASP Top 10 . Integrate and manage SAST, DAST, and vulnerability analysis tools throughout the SDLC and CI/CD pipelines. Analyse security tool findings and help developers understand and effectively remediate vulnerabilities. Conduct security-focused code reviews , identifying vulnerabilities, root causes, and potential attack vectors. Participate in threat modelling and security risk assessments from the early stages of application design. Manage the penetration testing programme , coordinating external providers, reviewing reports, and following up on remediation activities. Manage and assess vulnerabilities identified through the bug bounty programme , prioritising findings according to risk and ensuring timely remediation. Work closely with the external SOC to investigate and resolve security incidents, particularly application-level vulnerabilities tracked through Microsoft Sentinel . Contribute to maintaining the ISO 27001 ISMS and SOC 2 Type II compliance. Contribute to security risk management and maintain the security risk register. Act as a trusted point of contact for clients and stakeholders regarding Application Security matters. Keep IT and senior management informed about security risks, vulnerabilities, progress, and key initiatives. Requirements 5+ years of experience in Application Security, Cybersecurity, DevSecOps, or a similar role. CISSP certification . Practical experience with at least one programming language, preferably PHP or Java . Bachelor's degree in Computer Science, Engineering, IT, or a related field. Professional experience will be considered highly valuable. Strong knowledge of OWASP Top 10, Web Application Security, API Security, and Threat Modelling . Experience with Cloud Native environments , particularly Kubernetes and Docker . Knowledge of AWS Security . Experience with DevSecOps and CI/CD methodologies and practices. Ability to interpret penetration testing reports and manage vulnerability remediation. Knowledge of SAST/DAST and application security tools. Understanding of vulnerability management, threat detection, incident response, and general cybersecurity principles. Knowledge of ISO 27001 and/or SOC 2 . Strong analytical and problem-solving skills with excellent attention to detail. Excellent communication skills and the ability to work effectively with both technical and non-technical stakeholders. Nice to Have Hands-on experience conducting penetration testing . Certifications such as CEH, OSCP, or CREST . Experience with Bug Bounty programmes . Experience working with development teams in Agile/DevOps environments. Experience working in regulated environments or with ISO 27001 / SOC 2 requirements. Ready for your next challenge? Join a project where you will have the opportunity to strengthen application security, work with advanced cloud and security technologies, and make a real impact across the software development lifecycle. Apply now and take the next step in your cybersecurity career!
Here's how to pick the right one and stand out in your application.
144.883Jobs
31.687IN
81%EN
That number is real. WorkMundi's database shows 144,883 open engineer roles across the world. India has the most with 31,687 jobs, followed by the United States with 30,084. If you just finished reading one job ad and felt paralyzed by choice, you're not alone—but this scale is actually an advantage. It means you can afford to be selective.
Start by geography and language. The majority of engineer ads—117,837 of them—have the job posting text written in English. Use that as one filter, but remember: the ad text language tells you nothing about whether the role actually requires you to speak English day-to-day. Read the job description carefully. Then check which countries have the volume you're targeting. Singapore, Poland, and Australia round out the top five after India and the US.
Next, learn who's hiring. Accenture has posted 2,801 engineer roles. andurilindustries, speechify, and jobgether are also actively recruiting. If you're applying to one of these names, research their hiring patterns and interview style before you apply. That homework pays off.
When you interview, expect the question every engineer hears: 'Tell me about a time you had to debug a problem that wasn't in your job description.' Have a specific story ready—not a general one. Name the tools, the deadline pressure, and what you learned. Hiring managers listen for whether you see problem-solving as part of the role itself, not a favour.