> Markdown version of [/jobs/ext/2938416-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/2938416-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** Gmv - **Location:** Madrid, Spain (Remote available) - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Bash Shell, Cyber Security, Continuous Integration, Python (Programming Language), Open Web Application Security, Windows PowerShell, Systems Development Life Cycle, Secure Coding, Systems Integration, Software Vulnerability Management, Working Model 2D, Software Repository, Scripting, Software Security, Git, Enterprise Integration, Devsecops, Static Application Security Testing - **Published:** September 16, 2026 - **Apply:** https://www.buscojobs.com.es/cybersecurity-engineer-en-madrid-ID-372147790 ## About the Role Requisitos principalesPractical experience in Application Security and DevSecOps with SAST/SCA in CI/CD environments Knowledge of CI/CD, Git, and code repositories Understanding of OWASP Top 10, CWE, CVE, and CVSS; vulnerability and false-positive analysis Secure development and SSDLC with automated controls and Security Gates APIs and scripting experience (Python, PowerShell, or Bash) Tool and pipeline integration and troubleshooting Secure management of credentials, tokens, and secrets Ability to analyze code and collaborate with development teams cross-functional collaboration analytical thinking problem solving CI/CD experience Git and code repositories SAST/SCA integration ## Description OverviewIn this role you will advance automated, scalable DevSecOps within a large organization by embedding security into the SDLC.You'll work in an Application Security and SSDLC team to evolve security controls from early development stages.You'll automate SAST/SCA in CI/CD, tune rules, and support remediation with developers.The position offers a hands-on, collaborative environment focused on continuous improvement of security processes and credentials management, with a clear impact on product security.Compensaciones / Beneficioshybrid working modelteleworking 8 weeks/yearflexible start/finish timescareer plan development and trainingnational and international mobilityrelocation package availableResponsabilidadesAutomate and integrate SAST/SCA controls into CI/CD pipelinesConfigure, administer, and optimize security tools and onboard applications to DevSecOpsDefine and maintain Security Gates and scanning strategiesAnalyze vulnerabilities, manage false positives, and tune detection rulesDevelop automation and integrations using APIs and scriptingTroubleshoot issues across security tools, pipelines, and integrationsSupport developers with vulnerability remediation and revalidationContribute to ongoing improvement of SSDLC controls and secure credential managementRequisitos principalesPractical experience in Application Security and DevSecOps with SAST/SCA in CI/CD environmentsKnowledge of CI/CD, Git, and code repositoriesUnderstanding of OWASP Top 10, CWE, CVE, and CVSS; vulnerability and false-positive analysisSecure development and SSDLC with automated controls and Security GatesAPIs and scripting experience (Python, PowerShell, or Bash)Tool and pipeline integration and troubleshootingSecure management of credentials, tokens, and secretsAbility to analyze code and collaborate with development teamscross-functional collaborationanalytical thinkingproblem solvingCI/CD experienceGit and code repositoriesSAST/SCA integration ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)