Specialist II, Application Security (TCF)

Convergys

Bogotá ciudad

Híbrido

COP 78.120.000 - 122.760.000

Jornada completa

Hace 5 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Descripción de la vacante

Concentrix in Bogotá seeks a Specialist II, Application Security to strengthen security across the software development lifecycle. You will collaborate with Security, DevOps, and Development teams to embed secure coding practices and automate security testing across pipelines.

The role focuses on DevSecOps maturity, integrating security tools (SAST, DAST, SCA), API security, and vulnerability remediation, while aligning with OWASP and NIST standards. Strong cross-functional teamwork is essential.

Formación

  • Experience or working knowledge in application security, DevSecOps, secure SDLC practices, or related security functions.
  • Understanding of secure coding practices and common application security risks.
  • Familiarity with security testing tools and approaches, including SAST, DAST, and SCA.
  • Knowledge of API security concepts, including authentication, authorization, rate limiting, access control, and sensitive data exposure.
  • Experience supporting vulnerability management activities, including tracking, prioritization, remediation coordination, and reporting.
  • Ability to collaborate with Development, DevOps, and Security teams in a cross-functional environment.
  • Familiarity with CI/CD pipelines and the integration of automated security testing into development workflows.
  • Understanding of external exposure management, internet-facing application risks, and attack surface monitoring.
  • Knowledge of OWASP and NIST standards.

Responsabilidades

  • Serve as a key bridge between Security, DevOps, and Development teams to embed security throughout the SDLC.
  • Partner with application developers to promote secure coding practices, identify security gaps, and recommend effective remediation.
  • Provide training and guidance to developers on secure coding standards, application security risks, and security tools within CI/CD pipelines.
  • Support and enhance DevSecOps practices with a focus on automated security testing across development workflows.
  • Integrate and maintain security tools, including SAST, DAST, and SCA, within CI/CD pipelines.
  • Drive automation initiatives for application security assessments, including API security testing for authentication, authorization, rate limiting, sensitive data exposure, and access control.
  • Support external exposure management, including internet-facing asset discovery, attack surface monitoring, and vulnerability identification.
  • Monitor and manage risks related to internet-facing applications, including MFA, SSO, and exposure risks.
  • Track, prioritize, and support remediation of vulnerabilities identified through SAST, DAST, SCA, API testing, and external scanning.
  • Report on vulnerability remediation progress and help ensure findings are closed within defined timelines.
  • Collaborate with cross-functional teams on root cause analysis, security control improvements, and continuous application security enhancements.
  • Maintain documentation related to security findings, remediation actions, automation improvements, and DevSecOps pipeline updates.
  • Ensure application security practices align with organizational policies and industry standards, including OWASP and NIST.
  • Complete all assigned, mandatory training within the timeframe provided.
  • Conduct and/or participate in regularly scheduled 1:1 meetings with your direct manager and/or direct reports.

Conocimientos

Application security
DevSecOps
Secure SDLC
SAST
DAST
SCA
CI/CD
APIs security
Vulnerability management
OWASP
NIST
Documentation

Herramientas

SAST tools
DAST tools
SCA tools
CI/CD tooling

Descripción del empleo

## Specialist II, Application Security (TCF)Apply: COL Bogota - Oficinas y terrazas de: Full time: Posted Today: End Date: October 30, 2026 (30+ days left to apply): R1760819Job Title:Specialist II, Application Security (TCF)Job DescriptionWe're Concentrix. The intelligent transformation partner. Solution-focused. Tech-powered. Intelligence-fueled. The global technology and services leader that powers the world’s best brands, today and into the future. We’re solution-focused, tech-powered, intelligence-fueled. With unique data and insights, deep industry expertise, and advanced technology solutions, we’re the intelligent transformation partner that powers a world that works, helping companies become refreshingly simple to work, interact, and transact with. We shape new game-changing careers in over 70 countries, attracting the best talent. In our Information Technology and Global Security team, you will deliver the latest technology infrastructure, transformative software solutions and industry-leading global security for our staff and clients. You will work with the best in the world to design, implement and strategize IT, security, application development, innovation, and solutions in today’s hyperconnected world. You will be part of the technology team that is core to our vision of develop, build and run the future of Integrated Services. Our game-changers around the world have devoted their careers to ensuring every relationship is exceptional. And we’re proud to be recognized with awards such as \"World's Best Workplaces,\" “Best Companies for Career Growth,” and “Best Company Culture,” year after year. We embrace our game-changers with open arms, people from diverse backgrounds, who are curious and willing to learn. Your natural talent to help others and go beyond WOW for our customers will fit right in with what we do and who we are. Join us and be part of this journey towards greater opportunities and brighter futures.The Specialist II, Application Security plays a key role in strengthening application security across the software development lifecycle. This role partners closely with Security, DevOps, and Development teams to embed secure coding practices, automate security testing, and support timely vulnerability remediation. The ideal candidate will help advance DevSecOps maturity by integrating security tools, improving CI/CD pipeline controls, and reducing risks across applications, APIs, and internet-facing assets.**Responsibilities*** Serve as a key bridge between Security, DevOps, and Development teams to embed security throughout the SDLC.* Partner with application developers to promote secure coding practices, identify security gaps, and recommend effective remediation.* Provide training and guidance to developers on secure coding standards, application security risks, and security tools within CI/CD pipelines.* Support and enhance DevSecOps practices with a focus on automated security testing across development workflows.* Integrate and maintain security tools, including SAST, DAST, and SCA, within CI/CD pipelines.* Drive automation initiatives for application security assessments, including API security testing for authentication, authorization, rate limiting, sensitive data exposure, and access control.* Support external exposure management, including internet-facing asset discovery, attack surface monitoring, and vulnerability identification.* Monitor and manage risks related to internet-facing applications, including MFA, SSO, and exposure risks.* Track, prioritize, and support remediation of vulnerabilities identified through SAST, DAST, SCA, API testing, and external scanning.* Report on vulnerability remediation progress and help ensure findings are closed within defined timelines.* Collaborate with cross-functional teams on root cause analysis, security control improvements, and continuous application security enhancements.* Maintain documentation related to security findings, remediation actions, automation improvements, and DevSecOps pipeline updates.* Ensure application security practices align with organizational policies and industry standards, including OWASP and NIST.* Complete all assigned, mandatory training within the timeframe provided.* Conduct and/or participate in regularly scheduled 1:1 meetings with your direct manager and/or direct reports.**Qualifications*** Experience or working knowledge in application security, DevSecOps, secure SDLC practices, or related security functions.* Understanding of secure coding practices and common application security risks.* Familiarity with security testing tools and approaches, including SAST, DAST, and SCA.* Knowledge of API security concepts, including authentication, authorization, rate limiting, access control, and sensitive data exposure.* Experience supporting vulnerability management activities, including tracking, prioritization, remediation coordination, and reporting.* Ability to collaborate effectively with Development, DevOps, and Security teams in a cross-functional environment.* Familiarity with CI/CD pipelines and the integration of automated security testing into development workflows.* Understanding of external exposure management, internet-facing application risks, and attack surface monitoring.* Knowledge of industry security standards and frameworks, including OWASP and NIST.* Strong documentation, communication, analytical, and problem-solving skills.* Ability to support root cause analysis and recommend continuous improvements to strengthen application security posture.* Comfortable providing guidance and training to technical teams on security practices and tooling.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Application Security Specialist II — DevSecOps & Automation
Application Security Specialist II — DevSecOps & Automation

Convergys • Bogotá ciudad

Híbrido
COP 78.120.000 - 122.760.000
Junior Cybersecurity engineer
Junior Cybersecurity engineer

Unisys • Bogotá ciudad

Híbrido
COP 40.000.000 - 70.000.000
Application Engineer
Application Engineer

Salvatech • Bogotá ciudad

Presencial
COP 185.117.000 - 277.675.000
CyberSecurity Manager
CyberSecurity Manager

Lean Solutions Group • Colombia

Presencial
COP 120.000.000 - 200.000.000
Senior Full Stack Engineer
Senior Full Stack Engineer

Movate, Inc. • Colombia

Híbrido
COP 140.000.000 - 240.000.000
SOC Detection & response - Senior Cybersecurity Engineer - English Bilingual engineer
SOC Detection & response - Senior Cybersecurity Engineer - English Bilingual engineer

Unisys • Bogotá

Híbrido
COP 194.439.000 - 356.472.000
Application Security Manager Product & AI Security
Application Security Manager Product & AI Security

Auxis • Bogotá ciudad

Presencial
COP 180.000.000 - 240.000.000
Network Security Engineer- (English Required)
Network Security Engineer- (English Required)

DaCodes. • Colombia

A distancia
COP 122.010.736 - 284.691.719
Flexible work hours
Day off on your birthday
Private health insurance
+7
Security Engineer (Ingeniero/a de Seguridad)
Security Engineer (Ingeniero/a de Seguridad)

clara • Bogotá ciudad

Presencial
COP 248.316.000 - 372.474.000
Security Engineer - SR
Security Engineer - SR

Arionkoder • Bogotá, Distrito Capital

Presencial
COP 218.762.000 - 328.144.000
20 business days of vacation
Family Leave
Dynamic remote work culture