DevSecOps / AppSec Engineer

GMV Spain

Tres Cantos

Híbrido

EUR 50.000 - 80.000

Jornada completa

Hace 10 días
Generador de candidaturas

Una candidatura completa en un minuto: currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Hybrid working model
Teleworking up to 8 weeks per year
Flexible start and finish times
Relocation package

Descripción de la vacante

GMV Spain is seeking a cybersecurity professional to join its Application Security and SSDLC service. The role focuses on deploying an automated DevSecOps model across development teams, integrating security controls early in the lifecycle and driving scalable security practices.

You will help automate tooling, configure security gates, and support developers in remediation, with a strong emphasis on collaboration in a technical environment.

Formación

  • Experience implementing SAST/SCA in CI/CD environments and securing SDLC.
  • Knowledge of vulnerability analysis (OWASP Top10, CWE, CVE/CVSS).
  • Experience with APIs, scripting languages, and tool integrations.

Responsabilidades

  • Integrate SAST/SCA controls into CI/CD pipelines.
  • Configure and optimize security tools and onboarding of applications into DevSecOps.
  • Define Security Gates and scanning strategies; monitor vulnerabilities.

Conocimientos

CI/CD
Git
OWASP Top10
SSDLC
APIs
Scripting
Credentials security
Code analysis

Herramientas

Checkmarx
Checkmarx One
Fortify
SonarQube
Azure DevOps
Jenkins
GitHub Actions
GitLab CI/CD

Descripción del empleo

If you want todevelop your career in cybersecurity andwork on integrating security into the software development lifecycle, thisopportunity will allow you to drive an automated,scalable and continuous DevSecOps model within a large organization.

We´ll get to the point; we'll tell you what's not on the web.If you want to know more about deGMV

WHAT CHALLENGE WILL YOU BE TAKING ON?

You will join an Application Security and SSDLC service, helpingimplement and evolve the DevSecOps modeland integrate security controls from the early stages of development. Your mainresponsibilities will include:

  • Integrating and automating SAST/SCA controls into CI/CD pipelines.
  • Configuring, administeringand optimizing security tools and onboarding applications into the DevSecOps model.
  • Defining and maintaining SecurityGates andscanning strategies.
  • Analyzing vulnerabilities,managing false positives and performing rule tuning.
  • Developing automation andintegrations using APIs and scripting.
  • Troubleshooting issues acrosssecurity tools, pipelines and integrations.
  • Supporting developers with vulnerabilityremediation and revalidation.
  • Contributing to thecontinuous improvement of SSDLC controls and the secure management of credentials andsecrets.
  • You will work in atechnical and collaborative environment, helping integrate security intodevelopment processes in an automated andcontinuous way.
WHAT DO WE NEED IN OUR TEAM?

We are looking for aprofessional with practical experience in ApplicationSecurity and DevSecOps, particularly integrating SAST/SCA into CI/CD environments. You should haveknowledge of:

  • CI/CD, Gitand code repositories.
  • OWASP Top10, CWE, CVE and CVSS, as well as vulnerability and false-positive analysis.
  • Securedevelopment and SSDLC, including automated controls and Security Gates.
  • APIs andscripting,particularly Python, PowerShell or Bash.
  • Tool and pipeline integrationand troubleshooting.
  • Secure management of credentials,tokens and secrets.
  • The ability to analyze codeand collaborate effectively with development teams.

We will also value previous experience, and knowledge inCheckmarx/Checkmarx One, Fortify, SonarQube andCI/CD platforms such as Azure DevOps, Jenkins,GitHub Actions or GitLab CI/CD will be valued. Knowledge of SBOM, software supply chain security, Docker,Kubernetes, IaC and container security, as well as SARIF, APIs and automation, will also bevalued. Training or certifications in DevSecOps,Application Security or Secure Coding will be a plus.

WHAT DO WE OFFER?

Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area.

Flexible start and finish times, and intensive working hours Fridays and insummer.

Personalizedcareer plan development, training and language learning support.

National and international mobility. Do you come from another country?We can offer you a relocation package.

Competitivecompensation with ongoing reviews, flexible compensation anddiscount on brands.

Wellbeingprogram: Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more!

In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team. In addition, bank transfers and bank cards will neverbe requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.

We promote equal opportunities inrecruitment, and we are committed to inclusion and diversity.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Application Security and Secure Development
Application Security and Secure Development

GMV Spain • Tres Cantos

Híbrido
EUR 55.000 - 75.000
Hybrid working model
Teleworking opportunities
Relocation package
+1
Ingeniero/A Devsecops / Appsec, Hibrido
Ingeniero/A Devsecops / Appsec, Hibrido

Gmv • Madrid

Híbrido
EUR 50.000 - 70.000
Vulnerability Management Analyst
Vulnerability Management Analyst

GMV Spain • Tres Cantos

Híbrido
EUR 42.000 - 56.000
Relocation package
Flexible compensation
Health insurance
+2
Vulnerability Management Team Lead
Vulnerability Management Team Lead

GMV Spain • Tres Cantos

Híbrido
EUR 70.000 - 95.000
Senior pentester
Senior pentester

GMV Spain • Madrid

Híbrido
EUR 70.000 - 100.000
Hybrid work model
Relocation package
Wellbeing program
+1
Cybersecurity Architect
Cybersecurity Architect

GMV Spain • Tres Cantos

Híbrido
EUR 60.000 - 90.000
Relocation package
Hybrid work model
Career development plan
+1
Cybersecurity Engineer for vulnerability management projects
Cybersecurity Engineer for vulnerability management projects

GMV Spain • Tres Cantos

Híbrido
EUR 45.000 - 65.000
Hybrid work model
Relocation package
Language learning support
+1
Architect Cybersecurity Junior
Architect Cybersecurity Junior

GMV • Tres Cantos

Híbrido
EUR 55.000 - 75.000
Hybrid working model
Relocation package
Career development plan
+3
Secure Infrastructure Systems Engineer
Secure Infrastructure Systems Engineer

GMV • Tres Cantos

Híbrido
EUR 52.000 - 68.000
Hybrid working
Relocation package
Health/dental insurance
DevOps and Backend Developer
DevOps and Backend Developer

GMV • Tres Cantos

Híbrido
EUR 45.000 - 65.000
Hybrid work
Teleworking option
Flexible hours
+3