> Markdown version of [/jobs/ext/2939043-application-security-and-devsecops](https://www.wearedevelopers.com/jobs/ext/2939043-application-security-and-devsecops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security And Devsecops - **Company:** Gmv - **Location:** Madrid, Spain (Remote available) - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Microsoft Azure, Cloud Computing, System Configuration, Continuous Integration, Github, Open Web Application Security, Fortify (Software), Secure Coding, SonarQube, Systems Integration, Software Vulnerability Management, Working Model 2D, Software Security, Git, Gitlab-ci, Checkmarx, Devsecops, Security Orchestration, Automation & Response, Jenkins, Static Application Security Testing - **Published:** September 16, 2026 - **Apply:** https://www.buscojobs.com.es/application-security-and-devsecops-en-madrid-ID-372120105 ## About the Role We are looking for a professional with solid experience inApplication Security, SSDLC and DevSecOps, combining technical expertise with experience in service or team coordination. You should have knowledge of: SAST/SCA, vulnerability management and CI/CD security. OWASP, CWE, CVE, CVSS and Secure Coding. Git, pipelines and Security Gates. SLA, KPI, demand, capacity and risk management. APIs, scripting and automation. Customer interaction and technical/executive reporting. AI governance and risk management, including traceability and human oversight. We will also value previous experience with Checkmarx, Fortify, SonarQube and CI/CD platforms such as Azure DevOps, Jenkins, GitHub Actions or GitLab CI/CD will be valued, as well as knowledge of Cloud, containers, IaC and software supply chain security. Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF and security automation will also be valued, as well as experience applying AI to AppSec/DevSecOps and relevant training or certifications. ## Description If you want to take the next step in your cybersecurity career, combiningtechnical service managementwith a hands?on role inApplication Security and DevSecOps, this opportunity will allow you to contribute to the evolution of a corporate security service within a large organization.We ?ll get to the point; we'll tell you what's not on the web.If you want to know more about de GMVWHAT CHALLENGE WILL YOU BE TAKING ON?You will combine two key responsibilities:acting as the technical referenceand customer point of contact, while also contributing hands?on to the implementation and evolution ofApplication Security, SSDLC and DevSecOpscapabilities.Your main responsibilities will include:Technically coordinating the service, managing demand, planning, priorities, capacity, SLAs and KPIs.Integrating, configuring and optimizing SAST/SCA controls in CI/CD pipelines.Coordinating application onboarding and defining Security Gates.Contributing to vulnerability triage, prioritization, remediation and revalidation.Acting as the technical point of contact for the customer, providing reporting and service follow?up.Driving automation and industrialization through APIs and scripting.Managing risks, incidents, deviations and escalations.Advising development teams and coordinating with different technical areas.Driving the evolution of the SSDLC/DevSecOps model, including the safe and supervised adoption of AI.WHAT DO WE NEED IN OUR TEAM?We are looking for a professional with solid experience inApplication Security, SSDLC and DevSecOps, combining technical expertise with experience in service or team coordination.You should have knowledge of:SAST/SCA, vulnerability management and CI/CD security.OWASP, CWE, CVE, CVSS and Secure Coding.Git, pipelines and Security Gates.SLA, KPI, demand, capacity and risk management.APIs, scripting and automation.Customer interaction and technical/executive reporting.AI governance and risk management, including traceability and human oversight.We will also value previous experience with Checkmarx, Fortify, SonarQube and CI/CD platforms such as Azure DevOps, Jenkins, GitHub Actions or GitLab CI/CD will be valued, as well as knowledge of Cloud, containers, IaC and software supply chain security.Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF and security automation will also be valued, as well as experience applying AI to AppSec/DevSecOps and relevant training or certifications.WHAT DO WE OFFER?Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.Flexible start and finish times, and intensive working hours Fridays and in summer.Personalized career plan development, training and language learning support.National and international mobility.Do you come from another country?We can offer you a relocation package.Competitive compensation with ongoing reviews, flexible compensation and discount on brands.Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!In our recruitment processes you will always have telephone and personal contact, face?to?face or online, with our talent acquisition team.In addition, bank transfers and bank cards will never be requested.If you are contacted through another process, please get in touch with the person responsible for the selection process.We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.WHAT ARE YOU WAITING FOR?JOIN US#J-*****-Ljbffr ## Related Videos - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)