Jobs / GMV
Application Security and DevSecOps
GMV · Tres Cantos, MD, Spain
Tres Cantos, MD, SpainHybrid
Remuneration
Not specified
Location
Tres Cantos, MD, Spain
Visa sponsorship
Not specified
Job summary
This role enhances corporate security services by integrating Application Security and DevSecOps practices. Key responsibilities include managing service coordination, optimizing SAST/SCA controls in CI/CD pipelines, and driving automation through APIs and scripting, while advising development teams and managing risks and incidents effectively.
Benefits
Hybrid working model8 weeks teleworking outside usual geographical areaFlexible start and finish timesIntensive working hours Fridays and in summerPersonalized career plan developmentTraining and language learning supportNational and international mobilityRelocation packageCompetitive compensationWellbeing program
Qualifications
- solid experience in Application Security, SSDLC and DevSecOps
- knowledge of SAST/SCA, vulnerability management and CI/CD security
- knowledge of OWASP, CWE, CVE, CVSS and Secure Coding
- knowledge of Git, pipelines and Security Gates
- knowledge of SLA, KPI, demand, capacity and risk management
- knowledge of APIs, scripting and automation
- knowledge of customer interaction and technical/executive reporting
- knowledge of AI governance and risk management, including traceability and human oversight
Responsibilities
- Technically coordinating the service, managing demand, planning, priorities, capacity, SLAs and KPIs
- Integrating, configuring and optimizing SAST/SCA controls in CI/CD pipelines
- Coordinating application onboarding and defining Security Gates
- Contributing to vulnerability triage, prioritization, remediation and revalidation
- Acting as the technical point of contact for the customer, providing reporting and service follow-up
- Driving automation and industrialization through APIs and scripting
- Managing risks, incidents, deviations and escalations
- Advising development teams and coordinating with different technical areas
- Driving the evolution of the SSDLC/DevSecOps model, including the safe and supervised adoption of AI
Skills
AzureAzure DevOpsGitGitHubGitHub ActionsGitLabGitLab CIJenkinsSonarQube
Relocation
No