Security Incident Lead

3 semanas atrás


Porto, Portugal Planet Tempo inteiro

by working for sectors where technology is theabler, everything is ground-breaking and there's a constant need to be innovative.

Be part of the team
that combines business knowledge, technological edge and a design experience. Our different backgrounds and know-how are key in developing solutions and experiences for digital clients.

Face challenges
and learn other ways of thinking and seeing the world - there's always room for your energy and creativity.

About The Role

Celfocus is looking to add an Application Security Analyst to join our team.

As part of your job, you will:

- Conducting analysis and threat modeling for new and existing Celfocus products/projects.

- Analyzing and discussing requirements; interacting with all participants in the software development process.

- Penetration testing web applications.

- Conducting both manual and automated testing.

- Participating in the creation and development of the company's products at all stages of their life cycle.

What are we looking for?

- Previous experience as a DevSecOps Security Analyst

- Profound security assurance tool knowledge

- Profound CI/CD knowledge

- Profound vulnerability knowledge

- Basic understanding of security compliance requirements

- Capability to align with teams from Analysts, Designers, Architects, Developers to DevOps.

- Knowledge of HTTP.

- Working knowledge of programming languages

- Knowledge of the Top 10 OWASP vulnerabilities: how to find, exploit and fix them.

- Knowledge of Burp Suite or other popular web scanners like ZAP, Acunetix, Netsparker, etc.

- The desire and ability to work in a team.

- The desire to develop yourself in the field of application security.

- A lively and flexible mind, clear logic, a detail-oriented approach

- Knowledge of English at least at the level of reading technical documentation.

Nice to have:

- Good knowledge of Linux or Windows operating systems.

- Skills in scripting and automating your work using Powershell, Python, Bash, etc.

- Knowledge of the OWASP Application Security Verification Standard (ASVS) , OWASP Testing Guide and experience in whole product or feature planning.

- An understanding of browser security mechanisms (SOP, cookies, CSP, HSTS, etc.)

- Familiarity with various protocols and attacks against them (OAuth, JWT, websockets, etc.)

- Experience with public clouds (Azure, AWS, GCP)

- Experience with pipeline Orchestrators (Jenkins, Azure DevOps, GitLab CI/CD)

- Penetration testing experience

Personal traits:

Ability to adapt to different contexts, teams and Clients

Teamwork skills but also sense of autonomy

Motivation for international projects and ok if travel is included

Willingness to collaborate with other players

Strong communication skills

Believe this is you? Come join the Team At Celfocus, we are committed to cultivate a diverse and inclusive workplace. As an equal-opportunity employer, we welcome applicants of all backgrounds, gender identities, and abilities. We are dedicated to providing reasonable accommodations for candidates with specific needs. If you require any adjustments during the selection process, please inform our Talent Acquisition Team.

Come join the Team
*Celfocus is a European high-tech system integrator, providing leading edge professional services focused on creating business value through Analytics and Cognitive solutions – addressing Telecommunications, Financial Services, Retail, Energy & Utilities, Pharmaceutical, and other markets' strategic opportunities.*
As a highly specialised engineering company, Celfocus helps clients undergo their innovation path, providing technological solutions to extract value from data and make it actionable.

Serving clients in +25 countries, Celfocus delivers solutions that boost customer experience and enhance operational efficiency, via our Cognitive Automation, Data & Analytics and Digital offers.

#J-18808-Ljbffr


  • Security Incident Lead

    1 semana atrás


    Porto, Portugal Planet Tempo inteiro

    remote type - Hybrid - locations - Porto - Portugal - Madrid Office - Spain - time type - Full time - posted on - Posted Today - time left to apply - End Date: December 31, 2025 (30+ days left to apply) - job requisition id - JR10472 Role Overview As the Security Incident Lead, you will collaborate with the Head of Security Operations, Security Operations...

  • Cyber Security Lead

    Há 3 dias


    Porto, Portugal Anova Tempo inteiro

    **Cyber Security Lead** **Location**: Remote in Portugal or Hybrid in Porto or Coimbra office **Key Responsibilities** - Lead and drive IT & Cybersecurity engineering projects end‑to‑end (scoping, design, implementation, validation and operational hand‑over). - Create and own the corporate cybersecurity strategy, including the compliance,...

  • It Security Architect

    2 semanas atrás


    Porto, Portugal PrimeIT Tempo inteiro

    We are looking for an IT Security Architect to be responsible for implementing the Group and Regional IT security policies within a geographical scope and on functional scopes. The role will include the management of incident response, in coordination with the Regional stakeholders and the Group security team. The perfect fit should assure the security,...

  • IT Security Architect

    2 semanas atrás


    Porto, Portugal PrimeIT Tempo inteiro

    We are looking for an IT Security Architect to be responsible for implementing the Group and Regional IT security policies within a geographical scope and on functional scopes. The role will include the management of incident response, in coordination with the Regional stakeholders and the Group security team. The perfect fit should assure the security,...

  • It Security Architect

    2 semanas atrás


    Porto, Portugal PrimeIT Tempo inteiro

    We are looking for an IT Security Architect to be responsible for implementing the Group and Regional IT security policies within a geographical scope and on functional scopes. The role will include the management of incident response, in coordination with the Regional stakeholders and the Group security team. The perfect fit should assure the security,...

  • IT Security Architect

    2 semanas atrás


    Porto, Portugal PrimeIT Tempo inteiro

    We are looking for an IT Security Architect to be responsible for implementing the Group and Regional IT security policies within a geographical scope and on functional scopes. The role will include the management of incident response, in coordination with the Regional stakeholders and the Group security team. The perfect fit should assure the security,...

  • Regional Secops Engineer

    2 semanas atrás


    Porto, Portugal PrimeIT Tempo inteiro

    We are looking for a Security Operations (SecOps) Engineer to be in charge for securing Regional IT environment within a geographical scope. About the Role The goal is to assist and lead in the remediation of cybersecurity incidents, navigates through IT security controls implementation, works with the GRC (Governance, Risk and Compliance) team during...

  • IT Security Architect

    4 semanas atrás


    Porto, Portugal PrimeIT Tempo inteiro

    IT Security Architect We are looking for an IT Security Architect to be responsible for implementing the Group and Regional IT security policies within a geographical scope and on functional scopes. The role will include the management of incident response, in coordination with the Regional stakeholders and the Group security team. The perfect fit should...

  • IT Security Architect

    1 semana atrás


    Porto, Portugal PrimeIT Tempo inteiro

    IT Security Architect We are looking for an IT Security Architect to be responsible for implementing the Group and Regional IT security policies within a geographical scope and on functional scopes. The role will include the management of incident response, in coordination with the Regional stakeholders and the Group security team. The perfect fit should...

  • IT Security Architect

    1 semana atrás


    Porto, Portugal PrimeIT Tempo inteiro

    IT Security Architect We are looking for an IT Security Architect to be responsible for implementing the Group and Regional IT security policies within a geographical scope and on functional scopes. The role will include the management of incident response, in coordination with the Regional stakeholders and the Group security team. The perfect fit should...