> Markdown version of [/jobs/ext/3008524-cisoc-application-security-engineer-pharmaceutical-sector-at-omega-crm](https://www.wearedevelopers.com/jobs/ext/3008524-cisoc-application-security-engineer-pharmaceutical-sector-at-omega-crm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cisoc Application Security Engineer (Pharmaceutical Sector) At Omega Crm - **Company:** Omega CRM - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Bash Shell, Cyber Security, DevOps, Python (Programming Language), OpenShift, Windows PowerShell, Salesforce.Com, Secure Coding, Software Engineering, Software Vulnerability Management, Scripting, Large Language Models, Software Security, Cyber Threat Analysis, Kubernetes, Devsecops, Jenkins, Static Application Security Testing - **Published:** September 20, 2026 - **Apply:** https://www.buscojobs.com.es/cisoc-application-security-engineer-pharmaceutical-sector-at-omega-crm-en-barcelona-ID-372011470 ## About the Role follow defined processes.Ensure compliant documentation requirements and guarantee its production as required according to the SOPs and working instructions.Work with various risk & information security teams in presenting vulnerability management status & updates to technology subject matter experts & management.RequirementsStrong background in DevSecOps, application security, SAST tools, and secure coding practicesExperience with CI/CD pipelines (Jenkins) and container orchestration (Kubernetes/OpenShift)Proficiency in scripting languages (Python, PowerShell, or Bash)Nice to have RequirementsKnowledge of security vulnerabilities, threat mitigation, and remediation processes (triage, prioritization, change management)Ability to work in international, multicultural environments with strong English communication skillsSolid analytical, problem-solving, teamwork, and results-driven mindsetFamiliarity with automation, APIs, and AI in DevOps, including LLMs, agent-based systems, and workflow ## Description Omega CRM Consulting is looking for a CISOC Application Security Engineer that would like to collaborate with one of the top global pharmaceutical companies.As member of Cyber Intelligence & Security Operations Center (CISOC) team, he/she will be responsible for implementing and managing Static Application Security Testing (SAST) within our organization.The ideal candidate will have a strong background in software development and security, with a particular focus on the implementation and use of SAST tools.ResponsibilitiesImplement and manage SAST tools across the organization.Conduct security assessments of applications using SAST tools.Provide training and guidance to development teams on the use of SAST tools and secure coding practices.Participate in the development and enforcement of security policies and procedures.Help to formulate vulnerability management frameworks & working structures.Perform tasks including research, classification and analysis of security events and vulnerabilities detected.Act as point of contact for managing & delivering various vulnerability & remediation reports.Working in close collaboration with the IT Team members and stakeholders to deliver and implement technology solutions in support of the business objectives to improve productivity and enhance processes and security.Understand BI framework and follow defined processes.Ensure compliant documentation requirements and guarantee its production as required according to the SOPs and working instructions.Work with various risk & information security teams in presenting vulnerability management status & updates to technology subject matter experts & management.RequirementsStrong background in DevSecOps, application security, SAST tools, and secure coding practicesExperience with CI/CD pipelines (Jenkins) and container orchestration (Kubernetes/OpenShift)Proficiency in scripting languages (Python, PowerShell, or Bash)Nice to have RequirementsKnowledge of security vulnerabilities, threat mitigation, and remediation processes (triage, prioritization, change management)Ability to work in international, multicultural environments with strong English communication skillsSolid analytical, problem-solving, teamwork, and results-driven mindsetFamiliarity with automation, APIs, and AI in DevOps, including LLMs, agent-based systems, and workflow orchestrationRelevant security certifications are a plus but not mandatoryWhat do We offerPermanent contractFlexible ScheduleWork-Life balanceTrainings & CertificationsImprove your skills and get the official certificate from our main partnersHome OfficeFlexible retribution (public transport ticket, Ticket restaurant, ...)Health insuranceOMEGA in actionAbout usOmega CRM, a Merkle Company, is a global digital company specialising in accelerating the Business Experience (BX) of our clients through customer-centric solutions, technology, and data - all enhanced by AI.Together with Merkle, we form the largest Customer Experience Management (CXM) agency in Spain, and as part of the dentsu group, we offer end-to-end solutions that integrate media, creativity, content, technology, and strategy to deliver real business impact.With over 23 years of experience, a team of 580+ professionals from 24 nationalities, and 2,500+ certifications, Omega CRM is a recognised leader in the Salesforce ecosystem in Spain.We operate across key industries including Retail, Healthcare, Pharma, Real Estate, Education, and Non?Profit, delivering omnichannel experiences in Customer Service, eCommerce, Marketing, and Analytics.Client satisfaction is at our core (rating: 4.9/5), and we've been recognised with awards such as Salesforce Partner of the Year FY23 and Most Innovative Project (Iberia).At Omega CRM, we believe in growth through people - guided by our values: #Talent, #Flexibility, #Commitment, and #Innovation.We grow #Together.#J-*****-Ljbffr ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)