> Markdown version of [/jobs/ext/1477400-cyber-application-security-tester](https://www.wearedevelopers.com/jobs/ext/1477400-cyber-application-security-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber - Application Security Tester - **Company:** Deloitte - **Location:** Madrid, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Application Testing, Automation of Tests, Cloud Computing, Cyber Security, Continuous Integration, DevOps, Open Source Technology, Open Web Application Security, Fortify (Software), Secure Coding, Web Applications, Large Language Models, Software Security, Veracode, Information Technology, Tenable Nessus, Checkmarx, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 29, 2026 - **Apply:** https://www.buscojobs.com.es/cyber-application-security-tester-en-madrid-ID-365081920 ## About the Role Bachelor's degree in Computer Science, Cyber Security, International Cyber Security, or equivalent education experience. Experience in application testing. Experience with validation of scan results from the following testing tools would be of benefit: Snyk, Fortify,Contrast, Checkmarx, or Veracode. Strong knowledge of explaining to development teams of how to use secure coding techniques. Ability to convey technical risks to business managers and executives. Experience with managing and configuring scanning tools with DevOps and CI/CD systems hosted in a cloud environment. Experience working with variety of cultures across the globe and have the patience, understanding, and empathy to work collaboratively and effectively. Knowledge and ability to accurately describe the OWASP Top 10 most common web application, opensource, and LLM application security vulnerabilities found in most applications. ## Description Can you imagine taking part in the transformation of leading national and international organizations?At Deloitte, we are committed to making an impact on society, our clients, and our people.As an Application Security Tester on this team you'll help build and support deployed tooling that improves howour member firms find, understand and fix application vulnerabilities. You'll split your time between hands-on security testing, improving automation and tooling, and working with internal teams to turn technical findings into clear, actionable remediation guidance for our global network and teach development teams about secure coding and DevSecOps practices.Key Responsibilities:Support operational processes, rules of engagements and methodologies to deliver quality code analysis and DevSecOps automation services to Deloitte's global networkEnsure deliverables are of a quality nature and provide practical intelligence to help member firms remediate vulnerabilities identifiedExecute security testing or support of automated mechanismsCurate application security vulnerability data generated from application testing tools, provide concise and digestible remediation paths for member firmsEscalate key risks and issues to Automated Application Testing Delivery Manager that need special attention or hold urgencyAbility to both read and write in at least one development languageSignificant benefit of experience of DAST, SAST, SCA, container security, process automation, or robotics processingWork closely with the operations team to ensure appropriate customer facing documentation and communications are present to facilitate effective entry points and service offerings are presentSupport member firm liaisons with member firm and DTTL management and technical teams to ensure they are consuming all the offered Services within the Risk Management group across the globe and to ensure member firm expectations are being metCollaborate with the Global Cyber group to understand trends, issues and risks and to exchange expertiseThe teamDeloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.Required:Bachelor's degree in Computer Science, Cyber Security, International Cyber Security, or equivalent education experience.Experience in application testing.Experience with validation of scan results from the following testing tools would be of benefit: Snyk, Fortify,Contrast, Checkmarx, or Veracode.Strong knowledge of explaining to development teams of how to use secure coding techniques.Ability to convey technical risks to business managers and executives.Experience with managing and configuring scanning tools with DevOps and CI/CD systems hosted in a cloud environment.Experience working with variety of cultures across the globe and have the patience, understanding, and empathy to work collaboratively and effectively.Knowledge and ability to accurately describe the OWASP Top 10 most common web application, opensource, and LLM application security vulnerabilities found in most applications.What is it like to work at Deloitte??High-impact projectsoffering long-term growth and continuous learning opportunities.??Hybrid and flexible working model, with flexible hours and a healthy balance between remote work and collaboration in our offices or at client sites.?A positive and collaborative work environment, with team-building activities, cultural and sports events throughout the year.???Holistic wellbeing, supported by our physical, mental, and financial health programs, including on-site medical services.?Social impact, with access to a wide range of national and international volunteering initiatives and pro bono projects where you can contribute your time and talent.??A strong feedback culture and continuous learning, within an inclusive environment that promotes equal opportunities and personalized development plans. You may even see yourself atDeloitte University in Paris.?Exclusive benefits, including a comprehensive benefits portfolio and a flexible compensation plan.Next steps:If what you have read resonates with you, here is what comes next:Apply to the position by clicking"Apply now"and completing your profile.If your experience matches the role, our Talent team will contact you to get to know you better.Start your journey with Deloitte. We will guide you through each stage of the process until your onboarding. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)