Application Security And Devsecops Technical Leader - Gmv

Gmv
Madrid, Spain
18 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Microsoft Azure Cloud Computing Continuous Integration Github Open Web Application Security Fortify (Software) Secure Coding SonarQube Software Vulnerability Management Working Model 2D
+8 more
Software Security Git Gitlab-ci Checkmarx Devsecops Security Orchestration, Automation & Response Jenkins Static Application Security Testing

Job description

OverviewIn this role you help evolve a corporate security service by combining technical leadership with hands-on AppSec work.You will coordinate the security service while implementing and advancing SSDLC and DevSecOps capabilities within a large organization.Expect to drive security gates, automate controls in CI/CD, and guide risk management and reporting.This is a hands-on, cross-functional role with a strong focus on impact, automation, and AI-enabled security.You will collaborate with development teams to shape secure software delivery.Compensaciones / BeneficiosHybrid working model8 weeks teleworking per yearFlexible start/end times; intensive Fridays and summerPersonalized career plan development; training and language learning supportNational and international mobility; relocation packageCompetitive compensation with ongoing reviews; flexible compensation; brand discountsResponsabilidadesTechnically coordinate the security service, manage demand, plan priorities, capacity, SLAs and KPIsIntegrate, configure and optimize SAST/SCA controls in CI/CD pipelinesCoordinate application onboarding and define Security GatesContribute to vulnerability triage, remediation and revalidationAct as technical point of contact for customers, providing reporting and follow-upDrive automation and industrialization through APIs and scriptingManage risks, incidents, deviations and escalationsAdvise development teams and coordinate with different technical areasDrive evolution of the SSDLC/DevSecOps model, including AI governance and supervised adoptionRequisitos principalesSolid experience in Application Security, SSDLC and DevSecOps with service or team coordinationKnowledge of SAST/SCA, vulnerability management, and CI/CD securityFamiliarity with OWASP, CWE, CVE, CVSS and Secure CodingExperience with Git, pipelines and Security GatesUnderstanding of SLA, KPI, demand, capacity and risk managementExperience with APIs, scripting and automationCustomer interaction and technical/executive reportingAI governance and risk management, including traceability and human oversightExperience with Checkmarx, Fortify, SonarQube and CI/CD platforms (Azure DevOps, Jenkins, GitHub Actions, GitLab CI/CD) is valuedKnowledge of Cloud, containers, IaC and software supply chain securityKnowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF; security automation; and applying AI to AppSec/DevSecOpsRelevant training or certifications are valuedStrong communication and stakeholder managementCollaborative team player with cross-functional coordinationProblem-solving and analytical mindsetSAST/SCA and vulnerability managementCI/CD security and pipelinesSecurity Gates and gate-based on-boarding

Requirements

Requisitos principalesSolid experience in Application Security, SSDLC and DevSecOps with service or team coordination Knowledge of SAST/SCA, vulnerability management, and CI/CD security Familiarity with OWASP, CWE, CVE, CVSS and Secure Coding Experience with Git, pipelines and Security Gates Understanding of SLA, KPI, demand, capacity and risk management Experience with APIs, scripting and automation Customer interaction and technical/executive reporting AI governance and risk management, including traceability and human oversight Experience with Checkmarx, Fortify, SonarQube and CI/CD platforms (Azure DevOps, Jenkins, GitHub Actions, GitLab CI/CD) is valued Knowledge of Cloud, containers, IaC and software supply chain security Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF; security automation; and applying AI to AppSec/DevSecOps Relevant training or certifications are valued Strong communication and stakeholder management Collaborative team player with cross-functional coordination Problem-solving and analytical mindset SAST/SCA and vulnerability management CI/CD security and pipelines Security Gates and gate-based on-boarding

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:31 min

Implementing initial GitOps architecture with Jenkins and Argo CD

Lian Li · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all