Cybersecurity engineer

Gmv Tres Cantos
Tres Cantos, Spain
8 days ago
Apply on www.recruit.net
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Microsoft Azure Cloud Computing Cyber Security Continuous Integration Open Web Application Security Fortify (Software) Secure Coding SonarQube Systems Integration Software Vulnerability Management
+7 more
Software Security Git Gitlab-ci Checkmarx Devsecops Jenkins Static Application Security Testing

Job description

Gain full access to exclusive job listings from leading companies worldwide.

  • Verified, High-Quality Jobs Only No ads, scams, or junk-just genuine opportunities.

  • Focus on Real Opportunities Explore thousands of open positions tailored to your lifestyle, including flexible remote jobs.

  • Exclusive Resume Review Receive expert feedback with personalized suggestions to enhance your resume.

Cybersecurity engineer

If you want to takethe next step in your cybersecurity career,combining technical service management with a hands-on role in Application Security andDevSecOps, this opportunity will allow you to contribute to theevolution of a corporate security service within a large organization.

We´ll get to the point; we’ll tell you what’s not on the web.If you want to know more about de GMV

WHAT CHALLENGE WILL YOU BE TAKING ON?

You will combine twokey responsibilities: acting as the technicalreference and customer point of contact, while also contributinghands-on to the implementation and evolution of ApplicationSecurity, SSDLC and DevSecOps capabilities. Your mainresponsibilities will include:

  • Technically coordinating the service, managing demand, planning, priorities, capacity, SLAs and KPIs.
  • Integrating, configuring and optimizing SAST/SCA controls in CI/CD pipelines.
  • Coordinating application onboarding and defining Security Gates.
  • Contributing to vulnerability triage, prioritization, remediation and revalidation.
  • Acting as the technical point of contact for the customer, providing reporting and service follow-up.
  • Driving automation and industrialization through APIs and scripting.
  • Managing risks, incidents, deviations and escalations.
  • Advising development teams and coordinating with different technical areas.
  • Driving the evolution of the SSDLC/DevSecOps model, including the safe and supervised adoption of AI.

Requirements

We are looking for aprofessional with solid experience in ApplicationSecurity, SSDLC and DevSecOps, combining technical expertise withexperience in service or team coordination. You should haveknowledge of:

  • SAST/SCA, vulnerability management and CI/CD security.
  • OWASP, CWE, CVE, CVSS and Secure Coding.
  • Git, pipelines and Security Gates.
  • SLA, KPI, demand, capacity and risk management.
  • APIs, scripting and automation.
  • Customer interaction and technical/executive reporting.
  • AI governance and risk management, including traceability and human oversight.

We will also value previous experience with Checkmarx, Fortify, SonarQube and CI/CDplatforms such as Azure DevOps, Jenkins, GitHubActions or GitLab CI/CD will be valued, as well as knowledge of Cloud, containers, IaC and software supply chainsecurity. Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF and securityautomation will also be valued, as well as experience applying AI to AppSec/DevSecOps and relevant training orcertifications.

Benefits & conditions

Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area.

Flexible start and finish times, and intensive working hours Fridays and insummer.

Personalizedcareer plan development, training and language learning support.

National and international mobility. Do you come from another country?We can offer you a relocation package.

Competitivecompensation with ongoing reviews, flexible compensation anddiscount on brands.

Wellbeingprogram: Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more!

In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team. In addition, bank transfers and bank cards will neverbe requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.

We promote equal opportunities inrecruitment, and we are committed to inclusion and diversity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.recruit.net
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · World Congress 2023

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

Videos

See all

Related articles

See all