Cybersecurity engineer

Gmv Tres Cantos
Tres Cantos, Spain
8 days ago
Apply on www.recruit.net
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Microsoft Azure Bash Shell Cyber Security System Configuration Continuous Integration Github Python (Programming Language) Open Web Application Security Windows PowerShell Fortify (Software)
+17 more
Secure Coding Software Engineering SonarQube Systems Integration Software Vulnerability Management Software Repository Scripting Software Security Git Gitlab-ci Kubernetes Enterprise Integration Checkmarx Devsecops Docker Jenkins Static Application Security Testing

Job description

Gain full access to exclusive job listings from leading companies worldwide.

  • Verified, High-Quality Jobs Only No ads, scams, or junk-just genuine opportunities.

  • Focus on Real Opportunities Explore thousands of open positions tailored to your lifestyle, including flexible remote jobs.

  • Exclusive Resume Review Receive expert feedback with personalized suggestions to enhance your resume.

Cybersecurity engineer

If you want todevelop your career in cybersecurity andwork on integrating security into the software development lifecycle, thisopportunity will allow you to drive an automated,scalable and continuous DevSecOps model within a large organization.

We´ll get to the point; we’ll tell you what’s not on the web.If you want to know more about de GMV

WHAT CHALLENGE WILL YOU BE TAKING ON?

You will join an Application Security and SSDLC service, helpingimplement and evolve the DevSecOps modeland integrate security controls from the early stages of development. Your mainresponsibilities will include:

  • Integrating and automating SAST/SCA controls into CI/CD pipelines.
  • Configuring, administering and optimizing security tools and onboarding applications into the DevSecOps model.
  • Defining and maintaining Security Gates and scanning strategies.
  • Analyzing vulnerabilities, managing false positives and performing rule tuning.
  • Developing automation and integrations using APIs and scripting.
  • Troubleshooting issues across security tools, pipelines and integrations.
  • Supporting developers with vulnerability remediation and revalidation.
  • Contributing to the continuous improvement of SSDLC controls and the secure management of credentials and secrets.
  • You will work in atechnical and collaborative environment, helping integrate security intodevelopment processes in an automated andcontinuous way.

Requirements

We are looking for aprofessional with practical experience in ApplicationSecurity and DevSecOps, particularly integrating SAST/SCA into CI/CD environments. You should haveknowledge of:

  • CI/CD, Git and code repositories.
  • OWASP Top 10, CWE, CVE and CVSS, as well as vulnerability and false-positive analysis.
  • Secure development and SSDLC, including automated controls and Security Gates.
  • APIs and scripting, particularly Python, PowerShell or Bash.
  • Tool and pipeline integration and troubleshooting.
  • Secure management of credentials, tokens and secrets.
  • The ability to analyze code and collaborate effectively with development teams.

We will also value previous experience, and knowledge in Checkmarx/Checkmarx One, Fortify, SonarQube andCI/CD platforms such as Azure DevOps, Jenkins,GitHub Actions or GitLab CI/CD will be valued. Knowledge of SBOM, software supply chain security, Docker,Kubernetes, IaC and container security, as well as SARIF, APIs and automation, will also bevalued. Training or certifications in DevSecOps,Application Security or Secure Coding will be a plus.

Benefits & conditions

Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area.

Flexible start and finish times, and intensive working hours Fridays and insummer.

Personalizedcareer plan development, training and language learning support.

National and international mobility. Do you come from another country?We can offer you a relocation package.

Competitivecompensation with ongoing reviews, flexible compensation anddiscount on brands.

Wellbeingprogram: Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more!

In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team. In addition, bank transfers and bank cards will neverbe requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.

We promote equal opportunities inrecruitment, and we are committed to inclusion and diversity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.recruit.net
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all