JUMP TO CONTENT

Security Engineer

__jobinformationwidget.freetext.LocationText__

Porto, Portugal

  1. Full-time
  2. Technical and Functional Expertise
  3. Hybrid
  4. Tieto Group
Job Description

We are looking for a DevSecOps / Application Security Engineer to join a forward-thinking technology team supporting large-scale digital transformation and cloud modernization initiatives.

If you are passionate about secure software development, cloud-native security, and embedding security into every stage of the development lifecycle, this role offers an exciting opportunity to work in a collaborative and innovation-driven environment.

Main Responsibilities

  • Define, standardize, and evolve Secure Software Development Life Cycle (S-SDLC) practices across multiple engineering teams
  • Integrate and manage application security testing tools (SAST, DAST, SCA) within CI/CD pipelines
  • Lead vulnerability management initiatives across cloud environments and Kubernetes clusters
  • Maintain, automate, and improve infrastructure security controls, including WAF configurations and network security policies
  • Guide development and DevOps teams on secure coding practices and DevSecOps principles
  • Ensure alignment with industry standards and frameworks such as OWASP, CIS Benchmarks, and DORA
  • Support continuous improvement of security posture across applications and infrastructure

Required Skills

  • Bachelor’s degree in Computer Science, Cybersecurity, or equivalent practical experience
  • Solid professional experience as a Security Engineer with strong focus on Application Security and DevSecOps practices
  • Hands-on experience with containerization technologies and orchestration platforms (e.g., Docker, Kubernetes)
  • Strong programming and scripting skills (Python, Bash, Java, Go, or similar)
  • Good understanding of security standards and frameworks, including OWASP Top 10 and ISO 27001
  • Strong communication skills and ability to work effectively with both technical and non-technical stakeholders
  • Proactive, responsible, and collaborative mindset

Nice to Have

  • Certifications such as CKA (Certified Kubernetes Administrator) or CKS (Certified Kubernetes Security Specialist)
  • Strong analytical skills for threat detection and security risk assessment
  • Excellent communication abilities to translate technical security concepts into business impact
  • Experience aligning security requirements with cloud modernization and business objectives

Additional Information

At Tieto, we believe in the power of diversity, equity, and inclusion. We encourage applicants of all backgrounds, genders (m/f/d), and walks of life to join our team, as we believe that this fosters an inspiring workplace and fuels innovation. Our commitment to openness, trust, and diversity is at the heart of our mission to create digital futures that benefit businesses, societies, and humanity.

Diversity, equity and inclusion (tietoevry.com)

Company description

We are Tieto - A leading software and technology consulting company

We provide customers across different industries with mission-critical solutions through our specialized software businesses Tieto Caretech, Tieto Banktech and Tieto Indtech as well as Tieto Tech Consulting business.

Our around 14 000 talented vertical software, design, cloud and AI experts are dedicated to empowering our customers to succeed and innovate with latest technology.

Tieto’s annual revenue is approximately EUR 2 billion. The company’s shares are listed on the NASDAQ exchange in Helsinki and Stockholm, as well as on Oslo Børs.

Our hiring process

Discover and apply

Found the job you came for? Great! Apply now and we’ll get in touch soon! Didn’t find what you were looking for? Keep yourself updated by signing up to our talent community or reach out to us!

Please note: To ensure a smooth and efficient hiring experience for all, we do not accept CVs via email or "contact us" form. All applications must be submitted through our recruitment portal, where they are securely stored and professionally processed