# Application Security (AppSec) Engineer

[Joom Group](https://gurify.com/jobs?q=Joom%20Group) · Lisbon, Portugal · Posted 2 weeks ago

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://joom-group.breezy.hr/p/3b2baa070de8)

## Job description

Application Security (AppSec) Engineer
Company: Joom
Location: Lisbon, PT
Type: FULL_TIME

Joom Group is an international tech-centric group of e-commerce companies founded in 2016 in Latvia. We are here to transform the largest industry in the world, global trade, making it more transparent, efficient, and technology-driven.

Today, Joom Group brings together the following businesses: Joom, a platform for shopping from all over the world; JoomPro, the first end-to-end cross-border B2B marketplace, with successful operations in Brazil and plans to expand to other markets; JoomPulse, data platform that provides analytics and recommendations for marketplace sellers; and Onfy, a pharmaceutical marketplace in Germany. Joom Group’s offices are located in China, Brazil, Portugal, Latvia, and Germany, with headquarters in Lisbon, Portugal. We work as one international team, sharing knowledge and collaborating across countries, businesses, and products.

As we continue to grow and introduce new products and services, we become increasingly susceptible to security threats. We are currently seeking an Application Security Engineer for our infrastructure team to stay informed about current threats and ensure the security of our development and applications.

This role offers the opportunity to develop the application security direction from the ground up and achieve international certification.

We prioritize innovation over bureaucracy and legacy code and are always open to fresh ideas.

### Responsibilities

- Implement SSDLC with the development team
- Analyze the security of the company's products
- Assist teams in addressing vulnerabilities
- Stay informed about current threats and develop code protections

### Requirements

- 3+ years of experience in web/mobile application security
- Experience in securing mobile and web applications
- Experience in building secure development processes (SSDLC)
- Experience with white box testing
- Knowledge of *NIX systems and basic network protocols

### Preferred

- Experience in bug bounty programs
- Relevant information security certifications (e.g., OSCP, CompTIA Security+)
- CVE authorship
- Proficiency in Go, Python, or Java

### We offer

- Compensation package: base salary and performance-based bonuses
- Office-first: flexible hours with a possibility to work remotely 52 days per year, and 22 days of paid annual leave
- Care & Wellbeing: health insurance (including dental care) for employees and their children, daily meal allowance, and 100% paid sick leave
- AI-first approach: licenses and access to a wide range of AI tools
- Team & Growth: collaboration with colleagues across Portugal, Brazil, Latvia and China, with opportunities for promotions, professional trainings, and English courses
- Community & Engagement: annual team building activities, knowledge-sharing workshops, and a strong sense of team work

Before applying for the above position please review our Candidate Privacy Notice here. By responding to the vacancy, you acknowledge that you have read our Privacy notice.

**Live in Joom Group’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- AW [Application Security Engineer (f/m/d)](https://gurify.com/job/application-security-engineer-f-m-d-at-awin-fb24719a88c0) Awin · Berlin, Poland · 4 days ago
- SO [Application Security Engineer - Sonar](https://gurify.com/job/application-security-engineer-sonar-at-sonarsource-7bfd29fc9b53) Sonarsource · Austin, Texas · last week
- ON [Application Security Engineer - ONE ZERO](https://gurify.com/job/application-security-engineer-one-zero-at-onezerobank-2e8386af9bda) Onezerobank · Tel Aviv-Yafo, Israel · 5 days ago
- TR [Senior Application Security Engineer](https://gurify.com/job/senior-application-security-engineer-at-tripadvisor-e6adf974d3c7) Tripadvisor · Oxford, London · 3 days ago
- EN [Senior Security Engineer (AI/Cloud)](https://gurify.com/job/senior-security-engineer-ai-cloud-at-enhesa-460616ef8acb) Enhesa · Lisbon, Portugal · 2 months ago
- SO [Application Security Engineer](https://gurify.com/job/application-security-engineer-at-sonarsource-a1847194c1cb) Sonarsource · Geneva · last week

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Application Security (AppSec) Engineer","description":"\u003Cp\u003EApplication Security (AppSec) Engineer\u003Cbr /\u003ECompany: Joom\u003Cbr /\u003ELocation: Lisbon, PT\u003Cbr /\u003EType: FULL_TIME\u003C/p\u003E\u003Cp\u003EJoom Group is an international tech-centric group of e-commerce companies founded in 2016 in Latvia. We are here to transform the largest industry in the world, global trade, making it more transparent, efficient, and technology-driven.\u003C/p\u003E\u003Cp\u003EToday, Joom Group brings together the following businesses: Joom, a platform for shopping from all over the world; JoomPro, the first end-to-end cross-border B2B marketplace, with successful operations in Brazil and plans to expand to other markets; JoomPulse, data platform that provides analytics and recommendations for marketplace sellers; and Onfy, a pharmaceutical marketplace in Germany. Joom Group\u2019s offices are located in China, Brazil, Portugal, Latvia, and Germany, with headquarters in Lisbon, Portugal. We work as one international team, sharing knowledge and collaborating across countries, businesses, and products.\u003C/p\u003E\u003Cp\u003EAs we continue to grow and introduce new products and services, we become increasingly susceptible to security threats. We are currently seeking an Application Security Engineer for our infrastructure team to stay informed about current threats and ensure the security of our development and applications.\u003C/p\u003E\u003Cp\u003EThis role offers the opportunity to develop the application security direction from the ground up and achieve international certification.\u003C/p\u003E\u003Cp\u003EWe prioritize innovation over bureaucracy and legacy code and are always open to fresh ideas.\u003C/p\u003E\u003Ch3\u003EResponsibilities\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EImplement SSDLC with the development team\u003C/li\u003E\u003Cli\u003EAnalyze the security of the company\u0026#39;s products\u003C/li\u003E\u003Cli\u003EAssist teams in addressing vulnerabilities\u003C/li\u003E\u003Cli\u003EStay informed about current threats and develop code protections\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ERequirements\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E3\u002B years of experience in web/mobile application security\u003C/li\u003E\u003Cli\u003EExperience in securing mobile and web applications\u003C/li\u003E\u003Cli\u003EExperience in building secure development processes (SSDLC)\u003C/li\u003E\u003Cli\u003EExperience with white box testing\u003C/li\u003E\u003Cli\u003EKnowledge of *NIX systems and basic network protocols\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EPreferred\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience in bug bounty programs\u003C/li\u003E\u003Cli\u003ERelevant information security certifications (e.g., OSCP, CompTIA Security\u002B)\u003C/li\u003E\u003Cli\u003ECVE authorship\u003C/li\u003E\u003Cli\u003EProficiency in Go, Python, or Java\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWe offer\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ECompensation package: base salary and performance-based bonuses\u003C/li\u003E\u003Cli\u003EOffice-first: flexible hours with a possibility to work remotely 52 days per year, and 22 days of paid annual leave\u003C/li\u003E\u003Cli\u003ECare \u0026amp; Wellbeing: health insurance (including dental care) for employees and their children, daily meal allowance, and 100% paid sick leave\u003C/li\u003E\u003Cli\u003EAI-first approach: licenses and access to a wide range of AI tools\u003C/li\u003E\u003Cli\u003ETeam \u0026amp; Growth: collaboration with colleagues across Portugal, Brazil, Latvia and China, with opportunities for promotions, professional trainings, and English courses\u003C/li\u003E\u003Cli\u003ECommunity \u0026amp; Engagement: annual team building activities, knowledge-sharing workshops, and a strong sense of team work\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EBefore applying for the above position please review our Candidate Privacy Notice here. By responding to the vacancy, you acknowledge that you have read our Privacy notice.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"application-security-appsec-engineer-at-joom-group-8fc35aa2afbe"},"url":"https://gurify.com/job/application-security-appsec-engineer-at-joom-group-8fc35aa2afbe","datePosted":"2026-08-26","validThrough":"2026-10-27T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Joom Group","sameAs":"https://joom-group.breezy.hr"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"PT","addressLocality":"Lisbon"}},"employmentType":"CONTRACTOR"}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Portugal","item":"https://gurify.com/jobs/portugal"},{"@type":"ListItem","position":3,"name":"Application Security (AppSec) Engineer","item":"https://gurify.com/job/application-security-appsec-engineer-at-joom-group-8fc35aa2afbe"}]}
```
