Application Security Specialist II — DevSecOps & Automation

Convergys

Bogotá ciudad

Híbrido

COP 78.120.000 - 122.760.000

Jornada completa

Hace 5 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura completa en un minuto: currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Descripción de la vacante

Concentrix in Bogotá seeks a Specialist II, Application Security to strengthen security across the software development lifecycle. You will collaborate with Security, DevOps, and Development teams to embed secure coding practices and automate security testing across pipelines.

The role focuses on DevSecOps maturity, integrating security tools (SAST, DAST, SCA), API security, and vulnerability remediation, while aligning with OWASP and NIST standards. Strong cross-functional teamwork is essential.

Formación

  • Experience or working knowledge in application security, DevSecOps, secure SDLC practices, or related security functions.
  • Understanding of secure coding practices and common application security risks.
  • Familiarity with security testing tools and approaches, including SAST, DAST, and SCA.
  • Knowledge of API security concepts, including authentication, authorization, rate limiting, access control, and sensitive data exposure.
  • Experience supporting vulnerability management activities, including tracking, prioritization, remediation coordination, and reporting.
  • Ability to collaborate with Development, DevOps, and Security teams in a cross-functional environment.
  • Familiarity with CI/CD pipelines and the integration of automated security testing into development workflows.
  • Understanding of external exposure management, internet-facing application risks, and attack surface monitoring.
  • Knowledge of OWASP and NIST standards.

Responsabilidades

  • Serve as a key bridge between Security, DevOps, and Development teams to embed security throughout the SDLC.
  • Partner with application developers to promote secure coding practices, identify security gaps, and recommend effective remediation.
  • Provide training and guidance to developers on secure coding standards, application security risks, and security tools within CI/CD pipelines.
  • Support and enhance DevSecOps practices with a focus on automated security testing across development workflows.
  • Integrate and maintain security tools, including SAST, DAST, and SCA, within CI/CD pipelines.
  • Drive automation initiatives for application security assessments, including API security testing for authentication, authorization, rate limiting, sensitive data exposure, and access control.
  • Support external exposure management, including internet-facing asset discovery, attack surface monitoring, and vulnerability identification.
  • Monitor and manage risks related to internet-facing applications, including MFA, SSO, and exposure risks.
  • Track, prioritize, and support remediation of vulnerabilities identified through SAST, DAST, SCA, API testing, and external scanning.
  • Report on vulnerability remediation progress and help ensure findings are closed within defined timelines.
  • Collaborate with cross-functional teams on root cause analysis, security control improvements, and continuous application security enhancements.
  • Maintain documentation related to security findings, remediation actions, automation improvements, and DevSecOps pipeline updates.
  • Ensure application security practices align with organizational policies and industry standards, including OWASP and NIST.
  • Complete all assigned, mandatory training within the timeframe provided.
  • Conduct and/or participate in regularly scheduled 1:1 meetings with your direct manager and/or direct reports.

Conocimientos

Application security
DevSecOps
Secure SDLC
SAST
DAST
SCA
CI/CD
APIs security
Vulnerability management
OWASP
NIST
Documentation

Herramientas

SAST tools
DAST tools
SCA tools
CI/CD tooling

Descripción del empleo

Concentrix in Bogotá seeks a Specialist II, Application Security to strengthen security across the software development lifecycle. You will collaborate with Security, DevOps, and Development teams to embed secure coding practices and automate security testing across pipelines.

The role focuses on DevSecOps maturity, integrating security tools (SAST, DAST, SCA), API security, and vulnerability remediation, while aligning with OWASP and NIST standards. Strong cross-functional teamwork is essential.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Specialist II, Application Security (TCF)
Specialist II, Application Security (TCF)

Convergys • Bogotá ciudad

Híbrido
COP 78.120.000 - 122.760.000
Senior Application & AI Security Lead
Senior Application & AI Security Lead

Auxis • Bogotá ciudad

Presencial
COP 180.000.000 - 240.000.000
Threat Detection & SOAR Automation Engineer
Threat Detection & SOAR Automation Engineer

IBM • Bogotá

Híbrido
COP 60.000.000 - 90.000.000
Senior Security Engineer - Enterprise Platforms & AI Security
Senior Security Engineer - Enterprise Platforms & AI Security

StoneX Group Inc. • Bogotá

Híbrido
COP 150.000.000 - 250.000.000
Hybrid work
Office Bogotá
SecOps Engineer - Scale Security & Impact (Equity)
SecOps Engineer - Scale Security & Impact (Equity)

Addi • Bogotá ciudad

Presencial
COP 9.000.000 - 15.000.000
Equity
Senior AI-Driven App Sec Engineer: Secure SDLC & Remediation
Senior AI-Driven App Sec Engineer: Secure SDLC & Remediation

AgileEngine • Colombia

Presencial
COP 248.667.000 - 319.716.000
Professional growth
Competitive compensation
Exciting projects
+1
Senior AppSec & SAST Engineer — Remote, Flexible Hours
Senior AppSec & SAST Engineer — Remote, Flexible Hours

BairesDev • Bogotá

Presencial
COP 314.410.000 - 419.214.000
100% remote work
Excellent compensation
Hardware and software setup
+3
Security Operations Jr. Manager — Risk, Audits & Compliance
Security Operations Jr. Manager — Risk, Audits & Compliance

IntouchCX • Bogotá

Presencial
COP 7.000.000 - 11.000.000
Hybrid InfoSec Analyst — Drive Enterprise Security
Hybrid InfoSec Analyst — Drive Enterprise Security

Rockwell Automation • Medellín

Híbrido
COP 60.000.000 - 100.000.000
Comprehensive mindfulness programs
Volunteer Paid Time off
Volunteer and donation matching
+3
Senior DevSecOps Engineer – Secure CI/CD & Cloud
Senior DevSecOps Engineer – Secure CI/CD & Cloud

Illumia • Bogotá

Híbrido
COP 110.000.000 - 170.000.000