Application Security And Devsecops
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+10 more
Job description
If you want to take the next step in your cybersecurity career, combiningtechnical service managementwith a hands?on role inApplication Security and DevSecOps, this opportunity will allow you to contribute to the evolution of a corporate security service within a large organization.We ?ll get to the point; we’ll tell you what’s not on the web.If you want to know more about de GMVWHAT CHALLENGE WILL YOU BE TAKING ON?You will combine two key responsibilities:acting as the technical referenceand customer point of contact, while also contributing hands?on to the implementation and evolution ofApplication Security, SSDLC and DevSecOpscapabilities.Your main responsibilities will include:Technically coordinating the service, managing demand, planning, priorities, capacity, SLAs and KPIs.Integrating, configuring and optimizing SAST/SCA controls in CI/CD pipelines.Coordinating application onboarding and defining Security Gates.Contributing to vulnerability triage, prioritization, remediation and revalidation.Acting as the technical point of contact for the customer, providing reporting and service follow?up.Driving automation and industrialization through APIs and scripting.Managing risks, incidents, deviations and escalations.Advising development teams and coordinating with different technical areas.Driving the evolution of the SSDLC/DevSecOps model, including the safe and supervised adoption of AI.WHAT DO WE NEED IN OUR TEAM?We are looking for a professional with solid experience inApplication Security, SSDLC and DevSecOps, combining technical expertise with experience in service or team coordination.You should have knowledge of:SAST/SCA, vulnerability management and CI/CD security.OWASP, CWE, CVE, CVSS and Secure Coding.Git, pipelines and Security Gates.SLA, KPI, demand, capacity and risk management.APIs, scripting and automation.Customer interaction and technical/executive reporting.AI governance and risk management, including traceability and human oversight.We will also value previous experience with Checkmarx, Fortify, SonarQube and CI/CD platforms such as Azure DevOps, Jenkins, GitHub Actions or GitLab CI/CD will be valued, as well as knowledge of Cloud, containers, IaC and software supply chain security.Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF and security automation will also be valued, as well as experience applying AI to AppSec/DevSecOps and relevant training or certifications.WHAT DO WE OFFER?Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.Flexible start and finish times, and intensive working hours Fridays and in summer.Personalized career plan development, training and language learning support.National and international mobility.Do you come from another country?We can offer you a relocation package.Competitive compensation with ongoing reviews, flexible compensation and discount on brands.Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!In our recruitment processes you will always have telephone and personal contact, face?to?face or online, with our talent acquisition team.In addition, bank transfers and bank cards will never be requested.If you are contacted through another process, please get in touch with the person responsible for the selection process.We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.WHAT ARE YOU WAITING FOR?JOIN US#J-*****-Ljbffr
Requirements
We are looking for a professional with solid experience inApplication Security, SSDLC and DevSecOps, combining technical expertise with experience in service or team coordination. You should have knowledge of: SAST/SCA, vulnerability management and CI/CD security. OWASP, CWE, CVE, CVSS and Secure Coding. Git, pipelines and Security Gates. SLA, KPI, demand, capacity and risk management. APIs, scripting and automation. Customer interaction and technical/executive reporting. AI governance and risk management, including traceability and human oversight. We will also value previous experience with Checkmarx, Fortify, SonarQube and CI/CD platforms such as Azure DevOps, Jenkins, GitHub Actions or GitLab CI/CD will be valued, as well as knowledge of Cloud, containers, IaC and software supply chain security. Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF and security automation will also be valued, as well as experience applying AI to AppSec/DevSecOps and relevant training or certifications.
Benefits & conditions
Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area. Flexible start and finish times, and intensive working hours Fridays and in summer. Personalized career plan development, training and language learning support. National and international mobility. Do you come from another country? We can offer you a relocation package. Competitive compensation with ongoing reviews, flexible compensation and discount on brands. Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more! In our recruitment processes you will always have telephone and personal contact, face?to?face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through another process, please get in touch with the person responsible for the selection process. We promote equal opportunities in recruitment, and we are committed to inclusion and diversity. WHAT ARE YOU WAITING FOR? JOIN US #J-*****-Ljbffr
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 121 - AI goes offline
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Where To Find Software Engineering Jobs
Is Software Engineering Over-Saturated?