Cybersecurity engineer
GMV · Tres Cantos, Spain
You apply off-site, with the employer or the job board. I never handle applications.
Cybersecurity engineer | Job Details
If you want to take the next step in your cybersecurity career, combining technical service management with a hands-on role in Application Security and DevSecOps, this opportunity will allow you to contribute to the evolution of a corporate security service within a large organization.
We´ll get to the point; we'll tell you what's not on the web. If you want to know more about de GMV
WHAT CHALLENGE WILL YOU BE TAKING ON?
You will combine two key responsibilities: acting as the technical reference and customer point of contact, while also contributing hands-on to the implementation and evolution of Application Security, SSDLC and DevSecOps capabilities.
Your main responsibilities will include:
- Technically coordinating the service, managing demand, planning, priorities, capacity, SLAs and KPIs.
- Integrating, configuring and optimizing SAST/SCA controls in CI/CD pipelines.
- Coordinating application onboarding and defining Security Gates.
- Contributing to vulnerability triage, prioritization, remediation and revalidation.
- Acting as the technical point of contact for the customer, providing reporting and service follow-up.
- Driving automation and industrialization through APIs and scripting.
- Managing risks, incidents, deviations and escalations.
- Advising development teams and coordinating with different technical areas.
- Driving the evolution of the SSDLC/DevSecOps model, including the safe and supervised adoption of AI.
WHAT DO WE NEED IN OUR TEAM?
We are looking for a professional with solid experience in Application Security, SSDLC and DevSecOps, combining technical expertise with experience in service or team coordination.
You should have knowledge of:
- SAST/SCA, vulnerability management and CI/CD security.
- OWASP, CWE, CVE, CVSS and Secure Coding.
- Git, pipelines and Security Gates.
- SLA, KPI, demand, capacity and risk management.
- APIs, scripting and automation.
- Customer interaction and technical/executive reporting.
- AI governance and risk management, including traceability and human oversight.
We will also value previous experience with Checkmarx, Fortify, SonarQube and CI/CD platforms such as Azure DevOps, Jenkins, GitHub Actions or GitLab CI/CD will be valued, as well as knowledge of Cloud, containers, IaC and software supply chain security.
Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF and security automation will also be valued, as well as experience applying AI to AppSec/DevSecOps and relevant training or certifications.
WHAT DO WE OFFER?
Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.
Flexible start and finish times, and intensive working hours Fridays and in summer.
Personalized career plan development, training and language learning support.
National and international mobility. Do you come from another country? We can offer you a relocation package.
Competitive compensation with ongoing reviews, flexible compensation and discount on brands.
Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!
- ️ In our recruitment processes you will always have telephone and personal contact, face-to-face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.
❤️ We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.
WHAT ARE YOU WAITING FOR? JOIN US
#LI-Hybrid