Security Application Analyst

ISG Personalmanagement
Madrid, Spain
12 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

ASP.NET Java (Programming Language) .NET Framework PHP (Programming Language) Agile Methodology Software System Penetration Testing Microsoft Azure Burp Suite Unix Code Review Github Python (Programming Language)
+12 more
Open Web Application Security PCI Data Security Standards Secure Coding Software Engineering SonarQube Software Vulnerability Management Software Security Veracode Checkmarx Jenkins Static Application Security Testing Dynamic Application Security Testing

Job description

A leading global sports betting and gaming company, significant operations in Sofia’s tech hub, and a focus on innovative customer-facing platforms seeks a Security Application Analyst.This role bridges software development and cybersecurity, ideal for developers transitioning to secure coding practices.Role OverviewJoin the Sofia cybersecurity team to perform security assessments on customer-facing applications.Focus on vulnerability management, code reviews, and compliance in a regulated betting environment.Collaborate with developers to embed security in Agile workflows, minimizing risks across Java, .NET, Python, and PHP stacks.Key ResponsibilitiesConduct SAST, DAST, and penetration testing using tools like Checkmarx, Burp Suite, OWASP ZAP, and Snyk.Review code, manage SCA for third-party libraries, and integrate security into CI/CD pipelines with Jenkins or Azure DevOps.Investigate incidents, support SOC operations, and ensure PCI DSS/ISO compliance while educating developers on OWASP Top 10 risks.RequiredQualifications3+ years in software development (Java, .NET, Python, PHP) with transition to application security.Proficiency in SAST/DAST tools (SonarQube, Veracode, Semgrep), WAF configuration, and runtime monitoring (Contrast Security).Knowledge of secure frameworks (Spring, ASP.NET), Unix systems, and regulated industry standards.PreferredSkillsExperience with secrets detection, IaC security, and container scanning in gaming/betting sectors.Certifications like CSSLP, OSCP, or Security+; strong problem-solving and team collaboration.Familiarity with GitHub Actions and threat modeling.What We OfferCompetitive salary, hybrid work in Sofia’s tech hub, and growth in global cybersecurity operations.Apply if you thrive at the dev-sec intersection.If you are interested in this challenging position we are looking forward to receiving your comprehensive application for ref.no.*** preferably through our ISG career portal or via email.Visit isg.com/jobs/search - here you can find new job offers every day.

Requirements

Qualifications3+ years in software development (Java, .NET, Python, PHP) with transition to application security. Proficiency in SAST/DAST tools (SonarQube, Veracode, Semgrep), WAF configuration, and runtime monitoring (Contrast Security). Knowledge of secure frameworks (Spring, ASP.NET), Unix systems, and regulated industry standards. Preferred SkillsExperience with secrets detection, IaC security, and container scanning in gaming/betting sectors. Certifications like CSSLP, OSCP, or Security+; strong problem-solving and team collaboration. Familiarity with GitHub Actions and threat modeling. What We OfferCompetitive salary, hybrid work in Sofia’s tech hub, and growth in global cybersecurity operations. Apply if you thrive at the dev-sec intersection.

About the company

A leading global sports betting and gaming company, significant operations in Sofia’s tech hub, and a focus on innovative customer-facing platforms seeks a Security Application Analyst. This role bridges software development and cybersecurity, ideal for developers transitioning to secure coding practices. Role OverviewJoin the Sofia cybersecurity team to perform security assessments on customer-facing applications. Focus on vulnerability management, code reviews, and compliance in a regulated betting environment. Collaborate with developers to embed security in Agile workflows, minimizing risks across Java, . NET, Python, and PHP stacks. Key ResponsibilitiesConduct SAST, DAST, and penetration testing using tools like Checkmarx, Burp Suite, OWASP ZAP, and Snyk. Review code, manage SCA for third-party libraries, and integrate security into CI/CD pipelines with Jenkins or Azure DevOps. Investigate incidents, support SOC operations, and ensure PCI DSS/ISO compliance while educating developers on OWASP Top 10 risks.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Loading talks and stories from around this role…