> Markdown version of [/jobs/ext/2811373-application-cloud-security-consultant](https://www.wearedevelopers.com/jobs/ext/2811373-application-cloud-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application & Cloud Security Consultant - **Company:** Kyndryl (alcobendas, España) Seguir - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Continuous Integration, Systems Development Life Cycle, Cloud Services, Zero Trust Network Access, Secure Coding, Web Application Security, Software Engineering, Software Security, Software Troubleshooting, Information Technology, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 9, 2026 - **Apply:** https://www.recruit.net/job/application-cloud-security-consultant-jobs/1DE0C7809214D110 ## About the Role Who You Are MIN. REQUIRED EXPERIENCE * 5+ years of experience in Cybersecurity Services, with a focus on Application Security, Cloud Security, and Secure Software Development Lifecycle (Secure SDLC). * Proven experience working within enterprise-scale cloud and hybrid environments. LANGUAGES * Spanish and English (B2 level or higher). EDUCATION AND CERTIFICATION * Bachelor's or Master's degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, or equivalent experience. * Highly desired certifications: * CCSK (Certificate of Cloud Security Knowledge) * CCSP (Certified Cloud Security Professional) * AZ-500 Microsoft Azure Security Technologies * AWS Certified Security - Specialty * Kubernetes Security Specialist (CKS) * Relevant Secure SDLC, DevSecOps, or Cloud Security certifications CORE REQUIRED COMPETENCIES * Secure SDLC Governance: Definition and implementation of secure development frameworks and security gates. * DevSecOps Automation: Integration of security tools into CI/CD platforms and developer workflows. * Application Security Testing: Expertise in SAST, DAST, API Security Testing, SCA, and container security assessments. * Cloud Security Architecture: Deep understanding of Azure, AWS, and cloud-native security controls, including identity, networking, encryption, and workload protection. * Cloud Security Posture Management (CSPM): Experience assessing and improving cloud configurations, policies, and governance frameworks. * SASE & Zero Trust Architectures: Understanding of Secure Service Edge (SSE), Secure Web Gateway (SWG), CASB, ZTNA, and modern secure access architectures. * Threat Modeling & Risk Assessment: Ability to identify security risks in applications and cloud workloads and define pragmatic mitigation strategies. * Analytical Thinking: Strong troubleshooting and problem-solving skills in complex enterprise environments. * Documentation & Stakeholder Management: Ability to communicate security requirements and collaborate effectively with development, infrastructure, and security teams. ## Description The Application & Cloud Security Consultant will support the design, implementation, and continuous improvement of secure-by-design principles across application development, cloud environments, and modern access architectures. The role combines hands-on technical expertise and consulting capabilities to help organizations embed security throughout the software lifecycle while strengthening cloud security posture and Zero Trust access frameworks., * Drive Secure SDLC adoption across development programs. * Support implementation of DevSecOps tooling and automated security controls. * Perform application security assessments and architecture reviews. * Define secure coding standards and developer awareness initiatives. * Monitor application security posture and support remediation efforts. * Collaborate with cloud, infrastructure, and development teams to reduce application-related risks * Cloud Security Hardening: Assist in implementing cloud security controls, governance models, and remediation plans across Azure, CGP and AWS environments. * SASE/ZTNA Adoption: Support the deployment and optimization of modern secure access solutions aligned with Zero Trust principles (ZScaler, Netskope, etc) * Risk Mitigation & Governance: Identify security gaps, propose remediation roadmaps, and help ensure compliance with organizational security policies and industry standards. Being You The "Kyn" in Kyndryl means kinship, which represents the strong bonds we have with each other, our customers and our communities. We focus on ensuring all Kyndryls feel included and we welcome people of all cultures, backgrounds, and experiences. Even if you don't meet every requirement, we encourage you to apply. We believe in growth, and we're excited to see what you can bring. At Kyndryl, employee feedback has told us that our number one driver of employee engagement is belonging. That sense of belonging - being a valued, respected, trusted member of the team - is fundamental to our culture and fueling great experiences for our customers. This dedication to welcoming everyone into our company means that Kyndryl gives you the ability to thrive and contribute to our culture of empathy and shared success. That's The Kyndryl Way. What You Can Expect Your career with us isn't just a job-it's an adventure with purpose. We offer a dynamic, hybrid-friendly culture that supports your well-being and empowers you to grow. Our Be Well programs are thoughtfully designed to support your financial, mental, physical, and social health - because we know that when you feel your best, you do your best. From your very first day, you'll dive into impactful work that powers the systems our customers rely on every day. You won't just contribute - you'll make a difference, tackling meaningful projects that sharpen your skills and fuel your growth. We're here to champion your journey. With powerful tools to chart your career path, personalized development goals aligned with your ambitions, and continuous feedback to keep you inspired and on track, you'll have everything you need to thrive and evolve. You'll develop in-demand skills to grow your career and achieve your ambitions with access to cutting-edge learning opportunities - from certifications with Microsoft, Google, and Amazon to coaching and hands-on experiences. And through it all, you'll be part of a culture that values empathy, restless learning, and a devotion to shared success. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)