Cybersecurity Engineer

Gmv
Madrid, Spain
12 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Bash Shell Cyber Security Continuous Integration Python (Programming Language) Open Web Application Security Windows PowerShell Systems Development Life Cycle Secure Coding Systems Integration Software Vulnerability Management Working Model 2D
+7 more
Software Repository Scripting Software Security Git Enterprise Integration Devsecops Static Application Security Testing

Job description

OverviewIn this role you will advance automated, scalable DevSecOps within a large organization by embedding security into the SDLC.You’ll work in an Application Security and SSDLC team to evolve security controls from early development stages.You’ll automate SAST/SCA in CI/CD, tune rules, and support remediation with developers.The position offers a hands-on, collaborative environment focused on continuous improvement of security processes and credentials management, with a clear impact on product security.Compensaciones / Beneficioshybrid working modelteleworking 8 weeks/yearflexible start/finish timescareer plan development and trainingnational and international mobilityrelocation package availableResponsabilidadesAutomate and integrate SAST/SCA controls into CI/CD pipelinesConfigure, administer, and optimize security tools and onboard applications to DevSecOpsDefine and maintain Security Gates and scanning strategiesAnalyze vulnerabilities, manage false positives, and tune detection rulesDevelop automation and integrations using APIs and scriptingTroubleshoot issues across security tools, pipelines, and integrationsSupport developers with vulnerability remediation and revalidationContribute to ongoing improvement of SSDLC controls and secure credential managementRequisitos principalesPractical experience in Application Security and DevSecOps with SAST/SCA in CI/CD environmentsKnowledge of CI/CD, Git, and code repositoriesUnderstanding of OWASP Top 10, CWE, CVE, and CVSS; vulnerability and false-positive analysisSecure development and SSDLC with automated controls and Security GatesAPIs and scripting experience (Python, PowerShell, or Bash)Tool and pipeline integration and troubleshootingSecure management of credentials, tokens, and secretsAbility to analyze code and collaborate with development teamscross-functional collaborationanalytical thinkingproblem solvingCI/CD experienceGit and code repositoriesSAST/SCA integration

Requirements

Requisitos principalesPractical experience in Application Security and DevSecOps with SAST/SCA in CI/CD environments Knowledge of CI/CD, Git, and code repositories Understanding of OWASP Top 10, CWE, CVE, and CVSS; vulnerability and false-positive analysis Secure development and SSDLC with automated controls and Security Gates APIs and scripting experience (Python, PowerShell, or Bash) Tool and pipeline integration and troubleshooting Secure management of credentials, tokens, and secrets Ability to analyze code and collaborate with development teams cross-functional collaboration analytical thinking problem solving CI/CD experience Git and code repositories SAST/SCA integration

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all