Cisoc Application Security Engineer

Ambit Iberia
Madrid, Spain
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Bash Shell Cyber Security DevOps Python (Programming Language) OpenShift Windows PowerShell Secure Coding Software Engineering Software Vulnerability Management Scripting
+6 more
Large Language Models Software Security Kubernetes Devsecops Jenkins Static Application Security Testing

Job description

We are looking for an Application Security Engineer to join our CISOC team, responsible for implementing and managing SAST tools and supporting secure software development across the organization.TasksImplement and manage SAST tools across the organization.Conduct security assessments of applications using SAST tools.Provide training and guidance to development teams on the use of SAST tools and secure coding practices.Participate in the development and enforcement of security policies and procedures.Help to formulate vulnerability management frameworks & working structures.Perform tasks including research, classification and analysis of security events and vulnerabilities detected.Act as point of contact for managing & delivering various vulnerability & remediation reports.Working in close collaboration with the IT Team members and stakeholders to deliver and implement technology solutions in support of the business objectives to improve productivity and enhance processes and security.Understand BI framework and follow defined processes.Ensure compliant documentation requirements and guarantee its production as required according to the SOPs and working instructions.Work with various risk & information security teams in presenting vulnerability management status & updates to technology subject matter experts & management.Must HaveStrong background in DevSecOps, application security, SAST tools, and secure coding practicesExperience with CI/CD pipelines (Jenkins) and container orchestration (Kubernetes/OpenShift)Proficiency in scripting languages (Python, PowerShell, or Bash)Nice To HaveKnowledge of security vulnerabilities, threat mitigation, and remediation processes (triage, prioritization, change management)Ability to work in international, multicultural environments with strong English communication skillsSolid analytical, problem-solving, teamwork, and results-driven mindsetFamiliarity with automation, APIs, and AI in DevOps, including LLMs, agent-based systems, and workflow orchestrationRelevant security certifications are a plus but not mandatorySchedule08h-17h from Monday to Friday (flexible)4 days remote, on-site every Thursday.ConditionsSalary package based on your profile.Ticket restaurant included in-office hours.Flexible compensation plan (free of income tax) where we provide you with medical insurance, public transport ticket and childcare check.Discounts in gym network.Training catalogue.Our goal is that you are well in every way!#J-*****-Ljbffr

Requirements

Must Have Strong background in DevSecOps, application security, SAST tools, and secure coding practices Experience with CI/CD pipelines (Jenkins) and container orchestration (Kubernetes/OpenShift) Proficiency in scripting languages (Python, PowerShell, or Bash) Nice To Have Knowledge of security vulnerabilities, threat mitigation, and remediation processes (triage, prioritization, change management) Ability to work in international, multicultural environments with strong English communication skills Solid analytical, problem-solving, teamwork, and results-driven mindset Familiarity with automation, APIs, and AI in DevOps, including LLMs, agent-based systems, and workflow orchestration Relevant security certifications are a plus but not mandatory

Benefits & conditions

08h-17h from Monday to Friday (flexible) 4 days remote, on-site every Thursday. Conditions Salary package based on your profile. Ticket restaurant included in-office hours. Flexible compensation plan (free of income tax) where we provide you with medical insurance, public transport ticket and childcare check. Discounts in gym network. Training catalogue. Our goal is that you are well in every way! #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · WWC 2023

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all