Application Security And Devsecops

Gmv
Madrid, Spain
5 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Microsoft Azure Cloud Computing System Configuration Continuous Integration Github Open Web Application Security Fortify (Software) Secure Coding SonarQube Systems Integration
+10 more
Software Vulnerability Management Working Model 2D Software Security Git Gitlab-ci Checkmarx Devsecops Security Orchestration, Automation & Response Jenkins Static Application Security Testing

Job description

If you want to take the next step in your cybersecurity career, combiningtechnical service managementwith a hands?on role inApplication Security and DevSecOps, this opportunity will allow you to contribute to the evolution of a corporate security service within a large organization.We ?ll get to the point; we’ll tell you what’s not on the web.If you want to know more about de GMVWHAT CHALLENGE WILL YOU BE TAKING ON?You will combine two key responsibilities:acting as the technical referenceand customer point of contact, while also contributing hands?on to the implementation and evolution ofApplication Security, SSDLC and DevSecOpscapabilities.Your main responsibilities will include:Technically coordinating the service, managing demand, planning, priorities, capacity, SLAs and KPIs.Integrating, configuring and optimizing SAST/SCA controls in CI/CD pipelines.Coordinating application onboarding and defining Security Gates.Contributing to vulnerability triage, prioritization, remediation and revalidation.Acting as the technical point of contact for the customer, providing reporting and service follow?up.Driving automation and industrialization through APIs and scripting.Managing risks, incidents, deviations and escalations.Advising development teams and coordinating with different technical areas.Driving the evolution of the SSDLC/DevSecOps model, including the safe and supervised adoption of AI.WHAT DO WE NEED IN OUR TEAM?We are looking for a professional with solid experience inApplication Security, SSDLC and DevSecOps, combining technical expertise with experience in service or team coordination.You should have knowledge of:SAST/SCA, vulnerability management and CI/CD security.OWASP, CWE, CVE, CVSS and Secure Coding.Git, pipelines and Security Gates.SLA, KPI, demand, capacity and risk management.APIs, scripting and automation.Customer interaction and technical/executive reporting.AI governance and risk management, including traceability and human oversight.We will also value previous experience with Checkmarx, Fortify, SonarQube and CI/CD platforms such as Azure DevOps, Jenkins, GitHub Actions or GitLab CI/CD will be valued, as well as knowledge of Cloud, containers, IaC and software supply chain security.Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF and security automation will also be valued, as well as experience applying AI to AppSec/DevSecOps and relevant training or certifications.WHAT DO WE OFFER?Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.Flexible start and finish times, and intensive working hours Fridays and in summer.Personalized career plan development, training and language learning support.National and international mobility.Do you come from another country?We can offer you a relocation package.Competitive compensation with ongoing reviews, flexible compensation and discount on brands.Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!In our recruitment processes you will always have telephone and personal contact, face?to?face or online, with our talent acquisition team.In addition, bank transfers and bank cards will never be requested.If you are contacted through another process, please get in touch with the person responsible for the selection process.We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.WHAT ARE YOU WAITING FOR?JOIN US#J-*****-Ljbffr

Requirements

We are looking for a professional with solid experience inApplication Security, SSDLC and DevSecOps, combining technical expertise with experience in service or team coordination. You should have knowledge of: SAST/SCA, vulnerability management and CI/CD security. OWASP, CWE, CVE, CVSS and Secure Coding. Git, pipelines and Security Gates. SLA, KPI, demand, capacity and risk management. APIs, scripting and automation. Customer interaction and technical/executive reporting. AI governance and risk management, including traceability and human oversight. We will also value previous experience with Checkmarx, Fortify, SonarQube and CI/CD platforms such as Azure DevOps, Jenkins, GitHub Actions or GitLab CI/CD will be valued, as well as knowledge of Cloud, containers, IaC and software supply chain security. Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF and security automation will also be valued, as well as experience applying AI to AppSec/DevSecOps and relevant training or certifications.

Benefits & conditions

Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area. Flexible start and finish times, and intensive working hours Fridays and in summer. Personalized career plan development, training and language learning support. National and international mobility. Do you come from another country? We can offer you a relocation package. Competitive compensation with ongoing reviews, flexible compensation and discount on brands. Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more! In our recruitment processes you will always have telephone and personal contact, face?to?face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through another process, please get in touch with the person responsible for the selection process. We promote equal opportunities in recruitment, and we are committed to inclusion and diversity. WHAT ARE YOU WAITING FOR? JOIN US #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · World Congress 2023

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all