Cybersecurity Engineer

Gmv
Madrid, Spain
1 day ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Microsoft Azure Cyber Security Continuous Integration Github Python (Programming Language) Windows PowerShell Fortify (Software) Secure Coding Software Engineering SonarQube
+9 more
Systems Integration Software Security Gitlab-ci Kubernetes Checkmarx Devsecops Docker Jenkins Static Application Security Testing

Job description

Cybersecurity engineer Job DetailsIf you want todevelop your career in cybersecurity andwork on integrating security into the software development lifecycle, thisopportunity will allow you to drive an automated,scalable and continuous DevSecOps model within a large organization.Well get to the point; we’ll tell you what’s not on the web.If you want to know more about de GMVWHAT CHALLENGE WILL YOU BE TAKING ON?You will join an Application Security and SSDLC service, helpingimplement and evolve the DevSecOps modeland integrate security controls from the early stages of development.Your mainresponsibilities will include:Integrating and automating SAST/SCAcontrols into CI/CD pipelines.Configuring, administeringand optimizing security tools and onboarding applications into the DevSecOps model.Defining and maintaining SecurityGates andscanning strategies.Analyzing vulnerabilities,managing false positives and performing rule tuning.Developing automation andintegrations using APIs and scripting.Troubleshooting issues acrosssecurity tools, pipelines and integrations.Supporting developers with vulnerabilityremediation and revalidation.Contributing to thecontinuous improvement of SSDLC controls and the secure management of credentials andsecrets.You will work in atechnical and collaborative environment, helping integrate security intodevelopment processes in an automated andcontinuous way.WHAT DO WE NEED IN OUR TEAM?We are looking for aprofessional with practical experience in ApplicationSecurity and DevSecOps, particularly integrating SAST/SCA into CI/CD environments.You should haveknowledge of:CI/CD, Gitand code repositories.OWASP Top10, CWE, CVE and CVSS, as well as vulnerability and false-positive analysis.Securedevelopment and SSDLC, including automated controls and Security Gates.APIs andscripting,particularly Python, PowerShell or Bash.Tool and pipeline integrationand troubleshooting.Secure management of credentials,tokens and secrets.The ability to analyze codeand collaborate effectively with development teams.We will also value previous experience, and knowledge in Checkmarx/Checkmarx One, Fortify, SonarQube andCI/CD platforms such as Azure DevOps, Jenkins,GitHub Actions or GitLab CI/CD will be valued.Knowledge of SBOM, software supply chain security, Docker,Kubernetes, IaC and container security, as well as SARIF, APIs and automation, will also bevalued.Training or certifications in DevSecOps,Application Security or Secure Coding will be a plus.WHAT DO WE OFFER?Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area.Flexible start and finish times, and intensive working hours Fridays and insummer.Personalizedcareer plan development, training and language learning support.National and international mobility.Do you come from another country?We can offer you a relocation package.Competitivecompensation with ongoing reviews, flexible compensation anddiscount on brands.Wellbeingprogram: Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more!? In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team.In addition

Requirements

We are looking for aprofessional with practical experience in ApplicationSecurity and DevSecOps, particularly integrating SAST/SCA into CI/CD environments.You should haveknowledge of:CI/CD, Gitand code repositories.OWASP Top10, CWE, CVE and CVSS, as well as vulnerability and false-positive analysis.Securedevelopment and SSDLC, including automated controls and Security Gates.APIs andscripting,particularly Python, PowerShell or Bash.Tool and pipeline integrationand troubleshooting.Secure management of credentials,tokens and secrets.The ability to analyze codeand collaborate effectively with development teams.We will also value previous experience, and knowledge in Checkmarx/Checkmarx One, Fortify, SonarQube andCI/CD platforms such as Azure DevOps, Jenkins,GitHub Actions or GitLab CI/CD will be valued.Knowledge of SBOM, software supply chain security, Docker,Kubernetes, IaC and container security, as well as SARIF, APIs and automation, will also bevalued. Training or certifications in DevSecOps,Application Security or Secure Coding will be a plus.WHAT DO WE OFFER?

Benefits & conditions

Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area. Flexible start and finish times, and intensive working hours Fridays and insummer. Personalizedcareer plan development, training and language learning support. National and international mobility. Do you come from another country? We can offer you a relocation package. Competitivecompensation with ongoing reviews, flexible compensation anddiscount on brands.Wellbeingprogram: Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more! ? In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team. In addition

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · World Congress 2023

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

Videos

See all

Related articles

See all