DevSecOps / AppSec Engineer

GMV

Tres Cantos

Híbrido

EUR 45.000 - 65.000

Jornada completa

hace 15 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura completa en un minuto: currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Hybrid working model
Relocation package
Flexible hours
Language learning support
Wellbeing program

Descripción de la vacante

GMV invites you to join an Application Security and SSDLC service, helping implement and evolve a DevSecOps model by automating security controls from the earliest development stages. You will integrate SAST/SCA into CI/CD pipelines, configure and optimize security tools, define Security Gates, analyze vulnerabilities, and automate with APIs using Python, PowerShell, or Bash.

This role offers a hybrid work arrangement, ongoing training, and opportunities to collaborate with development teams

Formación

  • Experience in Application Security and DevSecOps, integrating SAST/SCA into CI/CD environments.
  • Knowledge of secure SDLC and automated controls.
  • Familiarity with vulnerability analysis and remediation best practices.

Responsabilidades

  • Integrate and automate SAST/SCA controls into CI/CD pipelines.
  • Configure, administer and optimize security tools and onboarding applications into the DevSecOps model.
  • Define and maintain Security Gates and scanning strategies.
  • Analyze vulnerabilities, manage false positives and tune rules.
  • Develop automation and integrations using APIs and scripting (Python/PowerShell/Bash).
  • Troubleshoot issues across security tools, pipelines and integrations.
  • Support developers with vulnerability remediation and revalidation.
  • Contribute to SSDLC controls and secure credential management.

Conocimientos

CI/CD
SAST/SCA
Git
OWASP Top 10
Vulnerability analysis
Security Gates
APIs & scripting
Docker/Kubernetes
Checkmarx/Checkmarx One
Fortify
SonarQube
Azure DevOps
Jenkins
GitHub Actions
GitLab CI/CD

Herramientas

Checkmarx
Checkmarx One
Fortify
SonarQube
Azure DevOps
Jenkins
GitHub Actions
GitLab CI/CD

Descripción del empleo

If you want to develop your career in cybersecurity and work on integrating security into the software development lifecycle, this opportunity will allow you to drive an automated, scalable and continuous DevSecOps model within a large organization.

We'll get to the point; we'll tell you what's not on the web. If you want to know more about de GMV

WHAT CHALLENGE WILL YOU BE TAKING ON?

You will join an Application Security and SSDLC service, helping implement and evolve the DevSecOps model and integrate security controls from the early stages of development.

Your main responsibilities will include:

  • Integrating and automating SAST/SCA controls into CI/CD pipelines.
  • Configuring, administering and optimizing security tools and onboarding applications into the DevSecOps model.
  • Defining and maintaining Security Gates and scanning strategies.
  • Analyzing vulnerabilities, managing false positives and performing rule tuning.
  • Developing automation and integrations using APIs and scripting.
  • Troubleshooting issues across security tools, pipelines and integrations.
  • Supporting developers with vulnerability remediation and revalidation.
  • Contributing to the continuous improvement of SSDLC controls and the secure management of credentials and secrets.
  • You will work in a technical and collaborative environment, helping integrate security into development processes in an automated and continuous way.
WHAT DO WE NEED IN OUR TEAM?

We are looking for a professional with practical experience in Application Security and DevSecOps, particularly integrating SAST/SCA into CI/CD environments.

You should have knowledge of:

  • CI/CD, Git and code repositories.
  • OWASP Top 10, CWE, CVE and CVSS, as well as vulnerability and false-positive analysis.
  • Secure development and SSDLC, including automated controls and Security Gates.
  • APIs and scripting, particularly Python, PowerShell or Bash.
  • Tool and pipeline integration and troubleshooting.
  • Secure management of credentials, tokens and secrets.
  • The ability to analyze code and collaborate effectively with development teams.

We will also value previous experience, and knowledge in Checkmarx/Checkmarx One, Fortify, SonarQube and CI/CD platforms such as Azure DevOps, Jenkins, GitHub Actions or GitLab CI/CD will be valued.

Knowledge of SBOM, software supply chain security, Docker, Kubernetes, IaC and container security, as well as SARIF, APIs and automation, will also be valued. Training or certifications in DevSecOps, Application Security or Secure Coding will be a plus.

WHAT DO WE OFFER?

Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.

Flexible start and finish times, and intensive working hours Fridays and in summer.

Personalized career plan development, training and language learning support.

National and international mobility. Do you come from another country? We can offer you a relocation package.

Competitive compensation with ongoing reviews, flexible compensation and discount on brands.

Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!

In our recruitment processes you will always have telephone and personal contact, face-to-face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.

We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.

WHAT ARE YOU WAITING FOR? JOIN US
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

DevSecOps / AppSec Engineer
DevSecOps / AppSec Engineer

GMV Spain • Tres Cantos

Híbrido
EUR 50.000 - 80.000
Hybrid working model
Teleworking up to 8 weeks per year
Flexible start and finish times
+1
Application Security and DevSecOps Technical Leader
Application Security and DevSecOps Technical Leader

GMV Spain • Tres Cantos

Híbrido
EUR 75.000 - 110.000
Hybrid working
Relocation package
Flexible hours
+2
Application Security and DevSecOps
Application Security and DevSecOps

GMV • Tres Cantos

Híbrido
EUR 55.000 - 90.000
Hybrid working model
Relocation package
Career development & training
+1
Application Security and Secure Development
Application Security and Secure Development

GMV Spain • Tres Cantos

Híbrido
EUR 65.000 - 90.000
Hybrid working model
Relocation package
Training and language support
Application Security and Secure Development
Application Security and Secure Development

GMV • Tres Cantos

Híbrido
EUR 60.000 - 90.000
Hybrid work model
Relocation package
Career development
+2
Vulnerability Management Analyst
Vulnerability Management Analyst

GMV Spain • Tres Cantos

Híbrido
EUR 42.000 - 56.000
Relocation package
Flexible compensation
Health insurance
+2
Vulnerability Management Analyst
Vulnerability Management Analyst

GMV • Tres Cantos

Híbrido
EUR 40.000 - 56.000
Hybrid work model
Relocation package
Language learning support
+2
Senior pentester
Senior pentester

GMV Spain • Madrid

Híbrido
EUR 70.000 - 100.000
Hybrid work model
Relocation package
Wellbeing program
+1
DevSecOps Engineer: SSDLC & CI/CD Security Automation
DevSecOps Engineer: SSDLC & CI/CD Security Automation

GMV • Tres Cantos

Híbrido
EUR 45.000 - 65.000
Hybrid working model
Relocation package
Flexible hours
+2
Vulnerability Management Team Lead
Vulnerability Management Team Lead

GMV • Tres Cantos

Híbrido
EUR 70.000 - 110.000
Hybrid work model
Relocation package
Wellbeing program