Cybersecurity Engineer

Gmv
Madrid, Spain
20 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Code Review Cyber Security Open Web Application Security Fortify (Software) Secure Coding Working Model 2D Software Repository Software Security Git Checkmarx Devsecops Static Application Security Testing

Job description

Experteer Overview In this role you will specialize in Application Security and SSDLC, collaborating with development teams to reduce security risks from early in the development lifecycle.You will conduct SAST and SCA reviews on large-scale services and help translate findings into actionable remediations.You will triage vulnerabilities, contextualize risk, and support developers with fixes.This position offers growth in a security-focused team that shapes secure development practices and continuous improvement.Compensaciones / Beneficios - Perform and analyze SAST and SCA reviews, including configuring projects and tools - Triage vulnerabilities, validate findings and false positives - Classify vulnerabilities and prepare technical reports with evidence and recommendations - Advise developers on remediation and verify fixes - Review vulnerabilities in libraries and dependencies - Apply secure development practices and collaborate with DevSecOps for service improvementResponsabilidades - Knowledge of OWASP Top 10, CWE, CVE and CVSS - Ability to analyze code and identify contextual vulnerabilities - Knowledge of secure development and secure coding best practices - Experience with Git and code repositories - Ability to prepare technical documentation and communicate remediation to developers - Experience with Fortify, Checkmarx or equivalent platforms is a plus - Knowledge of SCA, dependency analysis and manual code review is valuedRequisitos principales - Hybrid working model - teleworking up to 8 weeks/year - flexible start/finish times - career plan development and training - relocation package - competitive compensation and wellbeing program

Requirements

This position offers growth in a security-focused team that shapes secure development practices and continuous improvement.Compensaciones / Beneficios - Perform and analyze SAST and SCA reviews, including configuring projects and tools - Triage vulnerabilities, validate findings and false positives - Classify vulnerabilities and prepare technical reports with evidence and recommendations - Advise developers on remediation and verify fixes - Review vulnerabilities in libraries and dependencies - Apply secure development practices and collaborate with DevSecOps for service improvementResponsabilidades - Knowledge of OWASP Top 10, CWE, CVE and CVSS - Ability to analyze code and identify contextual vulnerabilities - Knowledge of secure development and secure coding best practices - Experience with Git and code repositories - Ability to prepare technical documentation and communicate remediation to developers - Experience with Fortify, Checkmarx or equivalent platforms is a plus

Benefits & conditions

Knowledge of SCA, dependency analysis and manual code review is valuedRequisitos principales - Hybrid working model - teleworking up to 8 weeks/year - flexible start/finish times - career plan development and training - relocation package - competitive compensation and wellbeing program

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

10:20 min

Building multidisciplinary teams and integrating secure code reviews

LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all