Remuneration
Not specified
Location
Tres Cantos, MD, Spain
Visa sponsorship
Not specified
Job summary
The DevSecOps / AppSec Engineer role focuses on integrating security into the software development lifecycle by implementing and evolving a DevSecOps model. Key responsibilities include automating SAST/SCA controls in CI/CD pipelines, configuring security tools, analyzing vulnerabilities, and supporting developers with remediation efforts. The position requires knowledge of CI/CD, OWASP Top 10, and scripting languages such as Python, PowerShell, or Bash.
Qualifications
- practical experience in Application Security and DevSecOps
- knowledge of CI/CD, Git and code repositories
- knowledge of OWASP Top 10, CWE, CVE and CVSS
- knowledge of secure development and SSDLC
- knowledge of APIs and scripting, particularly Python, PowerShell or Bash
- knowledge of tool and pipeline integration and troubleshooting
- knowledge of secure management of credentials and secrets
Responsibilities
- Integrating and automating SAST/SCA controls into CI/CD pipelines
- Configuring, administering and optimizing security tools
- Defining and maintaining Security Gates and scanning strategies
- Analyzing vulnerabilities and managing false positives
- Developing automation and integrations using APIs and scripting
- Troubleshooting issues across security tools and pipelines
- Supporting developers with vulnerability remediation
- Contributing to the improvement of SSDLC controls
Skills
AzureAzure DevOpsBashDockerGitGitHubGitHub ActionsGitLabGitLab CIJenkinsKubernetesPowerShellPythonSonarQubeCheckov
Certifications
DevSecOpsApplication SecuritySecure Coding
Relocation
No