> Markdown version of [/jobs/ext/1948325-cisoc-application-security-engineer-pharmaceutical-sector](https://www.wearedevelopers.com/jobs/ext/1948325-cisoc-application-security-engineer-pharmaceutical-sector). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cisoc Application Security Engineer (Pharmaceutical Sector) - **Company:** Omega CRM - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Bash Shell, Cyber Security, Python (Programming Language), OpenShift, Windows PowerShell, Secure Coding, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Scripting, Software Security, Kubernetes, Devsecops, Jenkins, Static Application Security Testing - **Published:** August 6, 2026 - **Apply:** https://www.buscojobs.com.es/cisoc-application-security-engineer-pharmaceutical-sector-en-barcelona-ID-365374533 ## About the Role teamsResponsabilidades xqbhyrx * Strong background in DevSecOps, application security, SAST tools, and secure coding practices* Experience with CI/CD pipelines (Jenkins) and container orchestration (Kubernetes/OpenShift)* Proficiency in scripting languages (Python, PowerShell, or Bash)Requisitos principales* Permanent contract* Flexible schedule* Trainings u**** Certifications* Home Office* Flexible retribution (public transport ticket, Ticket restaurant)* Health insurance ## Description Experteer Overview Se pueden requerir diversas habilidades interpersonales y experiencia para el siguiente puesto.Por favor, asegúrese de consultar la descripción a continuación con atención.In this role you will implement and manage SAST capabilities within a global pharma-supporting CISOC team.You will assess applications with SAST, guide developers on secure coding, and help shape vulnerability management processes.The position partners with IT and risk teams to deliver secure technology solutions aligned with business goals.You'll work in a cross-functional, security-focused environment where automation and policy enforcement matter.This is a hands-on, impact-driven role at the intersection of software development and security, with a mission to strengthen secure software delivery at scale.Compensaciones / Beneficios* Implement and manage SAST tools across the organization* Conduct security assessments of applications using SAST tools* Provide training and guidance to development teams on SAST tools and secure coding practices* Develop and enforce security policies and procedures* Help formulate vulnerability management frameworks and working structures* Perform research, classification and analysis of security events and vulnerabilities* Act as point of contact for managing and delivering vulnerability and remediation reports* Collaborate with IT and stakeholders to deliver technology solutions that improve security and productivity* Ensure BI framework processes and compliant documentation per SOPs and instructions* Coordinate vulnerability management status updates with risk and information security teamsResponsabilidades xqbhyrx * Strong background in DevSecOps, application security, SAST tools, and secure coding practices* Experience with CI/CD pipelines (Jenkins) and container orchestration (Kubernetes/OpenShift)* Proficiency in scripting languages (Python, PowerShell, or Bash)Requisitos principales* Permanent contract* Flexible schedule* Trainings u**** Certifications* Home Office* Flexible retribution (public transport ticket, Ticket restaurant)* Health insurance ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)