This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Checkmarx Security Research group seeks an experienced, curious, detail-oriented Application Security Analyst to join our team in Braga. Your role will include an in-depth understanding of vulnerabilities and how they occur in the code, from open-source libraries to proprietary code, and involvement with the entire security research group. On one hand, you will get familiar with our family of security products, such as SAST, DAST, SCA, SCS, and others. On the other hand, your work can include scripting and leveraging AI to automate and improve processes, researching and supporting the development of new product features, identifying 0-day vulnerabilities, and staying up to date with the latest Application Security trends. Apart from the Security Research group, you will collaborate with multiple Teams, including Product Management, R&D, and others.
Job Responsibility:
Analyze source code containing various security risks & vulnerabilities written in multiple languages/frameworks
Analyze results produced by Checkmark’s AST solutions that can include SAST, DAST, IaC, and other engines
Collaborate with other areas in the group, such as SCA and SCS
Supervise required technical components and collaborate with the required teams
Engage in proactive interactions with Product and R&D teams to align the security aspect of new features and product enhancements
Research ways to improve internal processes and promote relevant product features
Be at the forefront of the Application Security world: Discover and report Application Security trends. Suggest new ideas and write publications on new vulnerabilities and relevant topics
Develop Python scripts and tools for research purposes and automation
Leverage the latest technological trends for optimizing processes, including AI
Requirements:
Passionate about security and keen on growing in the security field
1-2 years of experience as an analyst or researcher
1-2 years of experience in a similar role in the security field
Familiar with key AppSec concepts, such as understanding security concepts, vulnerabilities, and secure coding practices
Have a deep understanding of the OWASP Top 10
Experience with Python scripting/programming
Familiarity with both interpreted and compiled languages, and the ability to learn new programming languages and technologies independently
Basic experience in conducting security research, bug bounties, and Pentesting
Excellent writing and oral presentation skills in English
Customer-oriented mindset and driven by innovation