Application Security and DevSecOps

GMV

Tres Cantos

Híbrido

EUR 55.000 - 90.000

Jornada completa

hace 14 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Transforma esta oferta en una entrevista: un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Hybrid working model
Relocation package
Career development & training
Wellbeing program

Descripción de la vacante

GMV is seeking a cybersecurity professional to join our team and bridge technical service management with hands-on Application Security and DevSecOps work. You will act as the technical reference and customer point of contact while enhancing SSDLC capabilities, SAST/SCA integration, and secure CI/CD practices.

You will coordinate security gates, drive automation via APIs, and support vulnerability triage and remediation for complex software projects, including AI governance aspects.

Formación

  • Solid experience in Application Security, SSDLC and DevSecOps.
  • Experience in service or team coordination.
  • Familiarity with security controls in CI/CD pipelines.

Responsabilidades

  • Technically coordinating the service, managing demand, planning, priorities, capacity, SLAs and KPIs.
  • Integrating, configuring and optimizing SAST/SCA controls in CI/CD pipelines.
  • Coordinating application onboarding and defining Security Gates.
  • Contributing to vulnerability triage, prioritization, remediation and revalidation.
  • Acting as the technical point of contact for the customer, providing reporting and service follow‑up.
  • Driving automation and industrialization through APIs and scripting.
  • Managing risks, incidents, deviations and escalations.
  • Advising development teams and coordinating with different technical areas.
  • Driving the evolution of the SSDLC/DevSecOps model, including AI adoption.

Conocimientos

Application Security
SSDLC
DevSecOps
SAST/SCA
CI/CD security
OWASP/CWE/CVE
Git/Pipelines/Security Gates
APIs & scripting
Automation
AI governance

Herramientas

Checkmarx
Fortify
SonarQube
Azure DevOps
Jenkins
GitHub Actions
GitLab CI/CD
Cloud
Containers
IaC

Descripción del empleo

If you want to take the next step in your cybersecurity career, combining technical service management with a hands‑on role in Application Security and DevSecOps, this opportunity will allow you to contribute to the evolution of a corporate security service within a large organization.

We´ll get to the point; we'll tell you what's not on the web. If you want to know more about de GMV

WHAT CHALLENGE WILL YOU BE TAKING ON?

You will combine two key responsibilities: acting as the technical reference and customer point of contact, while also contributing hands‑on to the implementation and evolution of Application Security, SSDLC and DevSecOps capabilities.

Your main responsibilities will include:

  • Technically coordinating the service, managing demand, planning, priorities, capacity, SLAs and KPIs.
  • Integrating, configuring and optimizing SAST/SCA controls in CI/CD pipelines.
  • Coordinating application onboarding and defining Security Gates.
  • Contributing to vulnerability triage, prioritization, remediation and revalidation.
  • Acting as the technical point of contact for the customer, providing reporting and service follow‑up.
  • Driving automation and industrialization through APIs and scripting.
  • Managing risks, incidents, deviations and escalations.
  • Advising development teams and coordinating with different technical areas.
  • Driving the evolution of the SSDLC/DevSecOps model, including the safe and supervised adoption of AI.
WHAT DO WE NEED IN OUR TEAM?

We are looking for a professional with solid experience in Application Security, SSDLC and DevSecOps, combining technical expertise with experience in service or team coordination.

You should have knowledge of:

  • SAST/SCA, vulnerability management and CI/CD security.
  • OWASP, CWE, CVE, CVSS and Secure Coding.
  • Git, pipelines and Security Gates.
  • SLA, KPI, demand, capacity and risk management.
  • APIs, scripting and automation.
  • Customer interaction and technical/executive reporting.
  • AI governance and risk management, including traceability and human oversight.

We will also value previous experience with Checkmarx, Fortify, SonarQube and CI/CD platforms such as Azure DevOps, Jenkins, GitHub Actions or GitLab CI/CD will be valued, as well as knowledge of Cloud, containers, IaC and software supply chain security.

Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF and security automation will also be valued, as well as experience applying AI to AppSec/DevSecOps and relevant training or certifications.

WHAT DO WE OFFER?

Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.

Flexible start and finish times, and intensive working hours Fridays and in summer.

Personalized career plan development, training and language learning support.

National and international mobility. Do you come from another country? We can offer you a relocation package.

Competitive compensation with ongoing reviews, flexible compensation and discount on brands.

Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!

In our recruitment processes you will always have telephone and personal contact, face‑to‑face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.

We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.

WHAT ARE YOU WAITING FOR? JOIN US
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Application Security and DevSecOps Technical Leader
Application Security and DevSecOps Technical Leader

GMV Spain • Tres Cantos

Híbrido
EUR 75.000 - 110.000
Hybrid working
Relocation package
Flexible hours
+2
DevSecOps / AppSec Engineer
DevSecOps / AppSec Engineer

GMV Spain • Tres Cantos

Híbrido
EUR 50.000 - 80.000
Hybrid working model
Teleworking up to 8 weeks per year
Flexible start and finish times
+1
DevSecOps / AppSec Engineer
DevSecOps / AppSec Engineer

GMV • Tres Cantos

Híbrido
EUR 45.000 - 65.000
Hybrid working model
Relocation package
Flexible hours
+2
Application Security and Secure Development
Application Security and Secure Development

GMV • Tres Cantos

Híbrido
EUR 60.000 - 90.000
Hybrid work model
Relocation package
Career development
+2
Application Security and Secure Development
Application Security and Secure Development

GMV Spain • Tres Cantos

Híbrido
EUR 65.000 - 90.000
Hybrid working model
Relocation package
Training and language support
Vulnerability Management Team Lead
Vulnerability Management Team Lead

GMV Spain • Tres Cantos

Híbrido
EUR 70.000 - 95.000
Vulnerability Management Team Lead
Vulnerability Management Team Lead

GMV • Tres Cantos

Híbrido
EUR 70.000 - 110.000
Hybrid work model
Relocation package
Wellbeing program
Vulnerability Management Analyst
Vulnerability Management Analyst

GMV • Tres Cantos

Híbrido
EUR 40.000 - 56.000
Hybrid work model
Relocation package
Language learning support
+2
Vulnerability Management Analyst
Vulnerability Management Analyst

GMV Spain • Tres Cantos

Híbrido
EUR 42.000 - 56.000
Relocation package
Flexible compensation
Health insurance
+2
Ingeniero/A Devsecops / Appsec, Hibrido
Ingeniero/A Devsecops / Appsec, Hibrido

Gmv • Madrid

Híbrido
EUR 50.000 - 70.000