03 ago
|
ServiceNow
|
Madrid
Experteer Overview
¡Inscríbase sin demora! Se espera un gran volumen de solicitantes para el puesto que se detalla a continuación, no espere para enviar su CV.
In this role you lead and shape Armis’ application security posture across SaaS and on-prem platforms, embedding security throughout the SDLC. You own vulnerability management within the VIPR framework and ensure findings are contextualized with asset intelligence and business impact. You collaborate with engineering, product security, and DevOps to drive risk-based remediation and secure design. You’ll work on scalable automation and threat modeling to strengthen overall security posture and resilience.
Compensaciones / Incentivos
• Lead the App Security program across all Armis products and embed security in the SDLC
• Perform secure design and architecture reviews with engineering teams
• Lead threat modeling sessions using STRIDE, DREAD, or PASTA
• Own application-layer vulnerability management within VIPR from detection to validation
• Integrate AppSec findings (SAST/DAST/SCA/API testing) into centralized workflows and risk models
• Correlate vulnerabilities with asset context, exploit intelligence,
and business criticality
• Track VMDR metrics (MTTD, MTTR, exposure windows, remediation effectiveness)
• Build and maintain automated AppSec pipelines for SAST/DAST/SCA/API security testing
• Collaborate with DevOps to integrate security scanning into CI/CD pipelines (GitHub Actions, Jenkins, Buildkite)
• Partner with Cloud/Infrastructure Security to secure APIs, microservices, and containers
• Develop and maintain secure coding standards for React/Node.js/Python/Java/Go
• Mentor engineers and deliver secure coding xqbhyrx training and threat modeling workshops
• Translate vulnerabilities into clear risk and remediation guidance for engineering leadership
• Support compliance and audit readiness (SOC 2, ISO 27001, FedRAMP, HIPAA)
Responsabilidades
• 7-10+ years of experience in Application Security, Product Security, or Secure Software Engineering
• Proven expertise in SAST, DAST, SCA, and dependency management tools (Veracode, Checkmarx, Fortify, Snyk, SonarQube, OWASP Dependency-Check)
Requisitos principales
•
📌 PS, Solution Architect (Madrid)
🏢 ServiceNow
📍 Madrid