Skip to content
Home
Experience

Checkmarx

Application Security Engineer

2024 — 2026· Braga, Portugal
  • Application Security
  • Security
  • Pentesting
  • Research
  • Static Analysis
  • Data Science
  • Reporting
  • Software Engineering
  • Automation

As an Application Security Engineer at Checkmarx, I focused on improving our engines through static analysis and vulnerability research. I perform deep static analysis on large-scale systems and open source projects to detect security flaws and match them to our engines’ results.

Building on my software engineering background, I am also responsible for the design and development of internal tools and automation platforms that support the Application Security team. My work bridges security analysis with software engineering, enabling more efficient, data-driven decision-making.

My main project in this role, besides security related activities, was the CLab Platform, a comprehensive system that parses and visualizes results from multiple SAST, DAST, and IaC engines such as Checkmarx, Snyk, Veracode, GitHub Advanced Security, and Semgrep but also serves as a hub for all internal development for the whole department. The platform highlights results in their respective source files, allowing analysts to classify findings as True Positive (TP), False Positive (FP), or Not Exploitable (NE). This unified analysis environment provides an unbiased view of various security engines, enabling fair comparisons and deeper understanding of strengths and weaknesses across the market.

Beyond tool development, I actively engage in vulnerability research, discovering, reproducing, and studying new security flaws. These findings are later translated into detection queries or research reports that enhance our products’ capabilities and threat coverage.

I also participate in CVE Hunt initiatives, where our team targets specific technologies or products to uncover new vulnerabilities over dedicated research sprints. These exercises often lead to valuable CVE discoveries and strengthen our offensive security expertise.

Through my technical analysis and collaboration with product teams, I have directly contributed to the successful retention of key clients who were considering alternative SAST/DAST/IaC solutions reinforcing the value and competitiveness of our security products.

Overall, my role combines hands-on security research, software engineering, and analytical thinking to build tools, identify vulnerabilities, and empower the organization to deliver stronger and more reliable security solutions.

Highlights

  • Performed a lot of security analysis work on static code and engine results
  • Research on new vulnerabilities for new queries and detection methods
  • Started development on intneral tools and software for the AppSec department
  • Designed, developed and delivered result comparison project C-LAB

From this role

Related projects

1
C-LAB — cover

Professional·Checkmarx

2025

C-LAB

Internal tool for comparison and management of different engines' results across multiple companies

Backend & Systems ArchitectureNode.jsExpress.jsJavascriptMongoDBMySQLgRPC+15 more