> Markdown version of [/jobs/ext/2084148-security-application-analyst](https://www.wearedevelopers.com/jobs/ext/2084148-security-application-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Application Analyst - **Company:** ISG Personalmanagement - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** ASP.NET, Java (Programming Language), .NET Framework, PHP (Programming Language), Agile Methodology, Software System Penetration Testing, Microsoft Azure, Burp Suite, Unix, Code Review, Github, Python (Programming Language), Open Web Application Security, PCI Data Security Standards, Secure Coding, Software Engineering, SonarQube, Software Vulnerability Management, Software Security, Veracode, Checkmarx, Jenkins, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 16, 2026 - **Apply:** https://www.buscojobs.com.es/security-application-analyst-en-madrid-ID-367530462 ## About the Role Focus on vulnerability management, code reviews, and compliance in a regulated betting environment.Collaborate with developers to embed security in Agile workflows, minimizing risks across Java, . NET, Python, and PHP stacks.Key ResponsibilitiesConduct SAST, DAST, and penetration testing using tools like Checkmarx, Burp Suite, OWASP ZAP, and Snyk.Review code, manage SCA for third-party libraries, and integrate security into CI/CD pipelines with Jenkins or Azure DevOps.Investigate incidents, support SOC operations, and ensure PCI DSS/ISO compliance while educating developers on OWASP Top 10 risks.Required Qualifications3+ years in software development (Java, .NET, Python, PHP) with transition to application security.Proficiency in SAST/DAST tools (SonarQube, Veracode, Semgrep), WAF configuration, and runtime monitoring (Contrast Security). Knowledge of secure frameworks (Spring, ASP.NET), Unix systems, and regulated industry standards.Preferred SkillsExperience with secrets detection, IaC security, and container scanning in gaming/betting sectors.Certifications like CSSLP, OSCP, or Security+; strong problem-solving and team collaboration.Familiarity with GitHub Actions and threat modeling.What We OfferCompetitive salary, hybrid work in Sofia's tech hub, and growth in global cybersecurity operations. Apply if you thrive at the dev-sec intersection. ## Description A leading global sports betting and gaming company, significant operations in Sofia's tech hub, and a focus on innovative customer-facing platforms seeks a Security Application Analyst.Es esencial asegurarse de que cumple con los requisitos como solicitante para este puesto; por favor, lea atentamente la información a continuación.This role bridges software development and cybersecurity, ideal for developers transitioning to secure coding practices.Role OverviewJoin the Sofia cybersecurity team to perform security assessments on customer-facing applications.Focus on vulnerability management, code reviews, and compliance in a regulated betting environment.Collaborate with developers to embed security in Agile workflows, minimizing risks across Java, .NET, Python, and PHP stacks.Key ResponsibilitiesConduct SAST, DAST, and penetration testing using tools like Checkmarx, Burp Suite, OWASP ZAP, and Snyk.Review code, manage SCA for third-party libraries, and integrate security into CI/CD pipelines with Jenkins or Azure DevOps.Investigate incidents, support SOC operations, and ensure PCI DSS/ISO compliance while educating developers on OWASP Top 10 risks.Required Qualifications3+ years in software development (Java, .NET, Python, PHP) with transition to application security.Proficiency in SAST/DAST tools (SonarQube, Veracode, Semgrep), WAF configuration, and runtime monitoring (Contrast Security).Knowledge of secure frameworks (Spring, ASP.NET), Unix systems, and regulated industry standards.Preferred SkillsExperience with secrets detection, IaC security, and container scanning in gaming/betting sectors.Certifications like CSSLP, OSCP, or Security+; strong problem-solving and team collaboration.Familiarity with GitHub Actions and threat modeling.What We OfferCompetitive salary, hybrid work in Sofia's tech hub, and growth in global cybersecurity operations.Apply if you thrive at the dev-sec intersection.xqysrnh If you are interested in this challenging position we are looking forward to receiving your comprehensive application for.******* preferably through our ISG career portal or via email.Visit /jobs/search - here you can find new job offers every day. ## Related Videos - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Building Multi-Tenant ASP.NET Core Applications: Best Practices and Real-World Solutions](https://www.wearedevelopers.com/videos/1552-building-multi-tenant-asp-net-core-applications-best-practices-and-real-world-solutions) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)