Infrastructure Engineer

Lisbon, Czech Republic

Apply by 11 Nov 2026

£400/day

Job Ref.: 57939

Job Type: Contract

Job Description

  • Configure, run and tune Tenable WAS scans: templates, crawl scope, exclusions, throttling, scan windows including authenticated scans (recorded logins, SSO, token/header auth) and API scanning from OpenAPI/Swagger definitions.
  • Define and agree naming and tagging conventions up front – in the platform (scans, targets, tags, folders, user groups) and in documentation – so results stay consistently structured, filterable and reportable as the portfolio grows.
  • Analyse each application before scanning: architecture, auth flow, tech stack, SPA/JS behaviour, WAF and bot protection, prod vs. non-prod, blast radius.
  • Consult application responsible roles (application owners, product owners, dev leads, third-party suppliers) on scope, credentials, scan timing, and result validation. No scan goes live without agreed scope and an identified owner.
  • Provision and store all scan credentials in the corporate credential store, never in scan configurations, exports or local files, with defined rotation and least-privilege scoping.
  • Build and maintain the reporting layer: coverage, findings by severity/age, SLA compliance, remediation trend.
  • Maintain the documentation baseline: configurations and their rationale, per-application scope agreements and credentials handling, operating procedure – so the scanning setup is auditable and transferable, not held in one person's head.
Technical requirements
  • Hands-on experience with a DAST platform (Tenable WAS preferred; Invicti, Burp Suite Enterprise, Qualys WAS acceptable).
  • Development and architecture literacy: Practical understanding of how applications are built and deployed, sufficient to assess an application independently and determine what must be scanned and what falls in scope. Experience across the portfolio spectrum is expected: legacy monolithic and vendor-supplied applications, modern SPAs and API-first services, and microservice architectures with gateways and service-to-service authentication – running on cloud-native platforms as well as on-premise systems in local branch data rooms, where network reachability, scanner placement and available access differ substantially.
  • Authentication and application context: Demonstrable command of authentication mechanisms form-based login, SSO/SAML/OIDC, OAuth2 flows, MFA, API keys, bearer tokens, mTLS and the ability to establish and maintain a valid session for the full duration of a scan. Able to reason about application roles and privilege levels, recognising that anonymous, standard and privileged scans produce materially different results, and to account for exposure and context: internet-facing vs. internal, tenant boundaries, environment separation.
  • Application security fundamentals: OWASP Top 10 and API Security Top 10; common authentication, authorisation and session flaws.
  • Data engineering ability at analyst level: work with exports (CSV/JSON), pull data via REST APIs (Tenable API / pyTenable), correlate across sources, deduplicate, normalise, clean. Python and SQL expected; BI tooling (Power BI or equivalent) an advantage.
  • CMDB experience: application and business service records, resolving ownership gaps, and feeding data-quality corrections back to the CMDB.
  • ITSM experience: change management (RFCs and approvals for scanning activity), incident/request workflows, and escalation handling.
APPLY NOW

Similar Jobs.

AI Platform Engineer - Insurance
Greater London, South East, England

Location: London, United Kingdom Industry: Insurance Overview We are seeking an AI Platform Engineer to design, build and operate a secure, scalable AI/ML platform supporting insurance use cases inclu

Business Analyst -Data loss prevention - REMOTE
London, Greater London, South East, England

For our customer a Commodities Trader, we are seeking a Business Analyst with DLP (Purview) experience and NIS2 Compliance 6 month contract remote EU The Business Analyst is needed to support requirem

Azure Cloud Engineer
Zürich, Switzerland

For our customer, we are seeking an Azure Cloud Engineer for a project in Zurich. This is a 6 month project with a potential extension or permenant transfer Project Overview:  Location: Onsite, Zurich