Cybersecurity engineer
GMV · Tres Cantos, Spain
You apply off-site, with the employer or the job board. I never handle applications.
Cybersecurity engineer | Job Details
If you want to develop your career in cybersecurity and work on integrating security into the software development lifecycle, this opportunity will allow you to drive an automated, scalable and continuous DevSecOps model within a large organization.
We´ll get to the point; we'll tell you what's not on the web. If you want to know more about de GMV
WHAT CHALLENGE WILL YOU BE TAKING ON?
You will join an Application Security and SSDLC service, helping implement and evolve the DevSecOps model and integrate security controls from the early stages of development.
Your main responsibilities will include:
- Integrating and automating SAST/SCA controls into CI/CD pipelines.
- Configuring, administering and optimizing security tools and onboarding applications into the DevSecOps model.
- Defining and maintaining Security Gates and scanning strategies.
- Analyzing vulnerabilities, managing false positives and performing rule tuning.
- Developing automation and integrations using APIs and scripting.
- Troubleshooting issues across security tools, pipelines and integrations.
- Supporting developers with vulnerability remediation and revalidation.
- Contributing to the continuous improvement of SSDLC controls and the secure management of credentials and secrets.
- You will work in a technical and collaborative environment, helping integrate security into development processes in an automated and continuous way.
WHAT DO WE NEED IN OUR TEAM?
We are looking for a professional with practical experience in Application Security and DevSecOps, particularly integrating SAST/SCA into CI/CD environments.
You should have knowledge of:
- CI/CD, Git and code repositories.
- OWASP Top 10, CWE, CVE and CVSS, as well as vulnerability and false-positive analysis.
- Secure development and SSDLC, including automated controls and Security Gates.
- APIs and scripting, particularly Python, PowerShell or Bash.
- Tool and pipeline integration and troubleshooting.
- Secure management of credentials, tokens and secrets.
- The ability to analyze code and collaborate effectively with development teams.
We will also value previous experience, and knowledge in Checkmarx/Checkmarx One, Fortify, SonarQube and CI/CD platforms such as Azure DevOps, Jenkins, GitHub Actions or GitLab CI/CD will be valued.
Knowledge of SBOM, software supply chain security, Docker, Kubernetes, IaC and container security, as well as SARIF, APIs and automation, will also be valued. Training or certifications in DevSecOps, Application Security or Secure Coding will be a plus.
WHAT DO WE OFFER?
Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.
Flexible start and finish times, and intensive working hours Fridays and in summer.
Personalized career plan development, training and language learning support.
National and international mobility. Do you come from another country? We can offer you a relocation package.
Competitive compensation with ongoing reviews, flexible compensation and discount on brands.
Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!
- ️ In our recruitment processes you will always have telephone and personal contact, face-to-face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.
❤️ We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.
WHAT ARE YOU WAITING FOR? JOIN US
#LI-Hybrid