Application Security And Secure Development

GMV Spain
Madrid, Spain
8 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Shift work
Languages
English

Tech stack

Artificial Intelligence Software System Penetration Testing Burp Suite Cloud Computing Linux Secure Coding Software Vulnerability Management Scripting Software Security Cyber Threat Analysis Restful APIs Qualys

Job description

Application Security and Secure DevelopmentIf you want to takethe next step in your cybersecurity career,becoming a technical reference inVulnerabilityManagementwithin a large-scale service for a financial sectororganization, your place is with usWe ?ll get to the point; we’ll tell you what’s not on the web.If you want to know more about deGMVWHAT CHALLENGE WILL YOU BE TAKING ON?You will act as the technical reference for aVulnerability Managementservice, leading advanced analysis, risk-based prioritization andvulnerability treatment across infrastructure,applications, Cloud and container environments.Your mainresponsibilities will include:Acting as the technicalreference for Vulnerability Management operations and resolving technical escalations.Performing advanced analysisand risk-based prioritization, considering factors such asCVSS, EPSS,CISA KEV, exposure, criticality andThreat Intelligence.Defining and monitoring remediationactivities, mitigations and compensating controls.Coordinating with specializedHacking,Cloud, Hardening/Compliance, Threat Intelligence and Automationteams.Supervising critical oractively exploited vulnerabilities, including technicalverification and closure.MonitoringSLAs, KPIsand reporting,identifying opportunities for automation and service improvement.Contributing to the evolutionof the service and the safe and supervised use of AI inVulnerability Management.WHAT DO WE NEED IN OUR TEAM?We are looking for aprofessional with at least 5 years of experiencein cybersecurity, with significant experience in Vulnerability Management, and a technicaluniversity degree or equivalent qualification.You should have:Strong knowledge of the vulnerabilitylifecycle and risk-based prioritization, includingCVSS, EPSS, CISA KEVandThreatIntelligence.Experience with vulnerabilityscanning and management tools, preferablyQualys.Solid knowledge ofWindows,Linux, networking, applications, Cloudand container environments.Experience in exploitationanalysis, defining mitigations and compensating controls, as well asSLA, KPIandreporting management.Knowledge of scripting,REST APIs, JSONand automation.Strong technicalleadership, autonomy and multidisciplinary coordination skills.Security, Hardening/Compliance, Pentesting and tools such asPrisma Cloud, Qualys WAAS or Burp Suite, willbe valued.Knowledge of cybersecurity governance and risk.Technical English is required, with a B2 level being recommended.WHAT DO WE OFFER?Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area.Flexible start and finish times, and intensive working hours Fridays and in summer.Personalizedcareerplan development, training and language learning support.National and international mobility.Do you come from another country?We can offer you a relocation package.Competitivecompensation with ongoing reviews, flexible compensation anddiscount on brands.Wellbeingprogram: Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more!In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team.In addition, bank transfers and bank cards will neverbe requested.If you are contacted through another process, please get in touch with the person responsible for the selection process.We promote equal opportunities inrecruitment, and we are committed to inclusion and diversity.#J-*****-Ljbffr

Requirements

We are looking for aprofessional with at least 5 years of experiencein cybersecurity, with significant experience in Vulnerability Management, and a technicaluniversity degree or equivalent qualification. You should have: Strong knowledge of the vulnerabilitylifecycle and risk-based prioritization, includingCVSS, EPSS, CISA KEVandThreatIntelligence. Experience with vulnerabilityscanning and management tools, preferablyQualys. Solid knowledge ofWindows,Linux, networking, applications, Cloudand container environments. Experience in exploitationanalysis, defining mitigations and compensating controls, as well asSLA, KPIandreporting management. Knowledge of scripting,REST APIs, JSONand automation. Strong technicalleadership, autonomy and multidisciplinary coordination skills. Security, Hardening/Compliance, Pentesting and tools such asPrisma Cloud, Qualys WAAS or Burp Suite, willbe valued. Knowledge of cybersecurity governance and risk. Technical English is required, with a B2 level being recommended.

Benefits & conditions

Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area. Flexible start and finish times, and intensive working hours Fridays and in summer. Personalizedcareerplan development, training and language learning support. National and international mobility. Do you come from another country? We can offer you a relocation package. Competitivecompensation with ongoing reviews, flexible compensation anddiscount on brands. Wellbeingprogram: Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more! In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team. In addition, bank transfers and bank cards will neverbe requested. If you are contacted through another process, please get in touch with the person responsible for the selection process. We promote equal opportunities inrecruitment, and we are committed to inclusion and diversity. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:30 min

Integrating automated security and vulnerability scanning

Alexandra Petri · World Congress 2023

Videos

See all

Related articles

See all