13 sep
|
Gmv Spain
|
Tres Cantos
13 sep
Gmv Spain
Tres Cantos
If you want todevelop your career in cybersecurity andwork on integrating security into the software development lifecycle, thisopportunity will allow you to drive an automated,scalable and continuous DevSecOps model within a large organization.
Si desea conocer los requisitos para este puesto, siga leyendo para obtener toda la información relevante.
We´ll get to the point; we'll tell you what's not on the web.If you want to know more about deGMV
WHAT CHALLENGE WILL YOU BE TAKING ON?
You will join an Application Security and SSDLC service, helpingimplement and evolve the DevSecOps modeland integrate security controls from the early stages of development.
Your mainresponsibilities will include:
- Integrating and automating SAST/SCA controls into CI/CD pipelines.
- Configuring, administeringand optimizing security tools and onboarding applications into the DevSecOps model.
- Defining and maintaining SecurityGates andscanning strategies.
- Analyzing vulnerabilities,managing false positives and performing rule tuning.
- Developing automation andintegrations using APIs and scripting.
- Troubleshooting issues acrosssecurity tools, pipelines and integrations.
- Supporting developers with vulnerabilityremediation and revalidation.
- Contributing to thecontinuous improvement of SSDLC controls and the secure management of credentials andsecrets.
- You will work in atechnical and collaborative environment, helping integrate security intodevelopment processes in an automated andcontinuous way.
WHAT DO WE NEED IN OUR TEAM?
We are looking for aprofessional with practical experience in ApplicationSecurity and DevSecOps, particularly integrating SAST/SCA into CI/CD environments.
You should haveknowledge of:
- CI/CD, Gitand code repositories.
- OWASP Top10, CWE, CVE and CVSS, as well as vulnerability and false-positive analysis.
- Securedevelopment and SSDLC, including automated controls and Security Gates.
- APIs andscripting,particularly Python, PowerShell or Bash.
- Tool and pipeline integrationand troubleshooting.
- Secure management of credentials,tokens and secrets.
- The ability to analyze codeand collaborate effectively with development teams.
We will also value previous experience, and knowledge inCheckmarx/Checkmarx One, Fortify, SonarQube andCI/CD platforms such as Azure DevOps, Jenkins,GitHub Actions or GitLab CI/CD will be valued.
Knowledge of SBOM, software supply chain security, Docker,Kubernetes, IaC and container security, as well as SARIF, APIs and automation, will also bevalued. Training or certifications in DevSecOps,Application Security or Secure Coding will be a plus.
WHAT DO WE OFFER?
Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area.
Flexible start and finish times, and intensive working hours Fridays and insummer.
Personalizedcareer plan development, training and language learning support.
National and international mobility. Do you come from another country?We can offer you a relocation package.
Competitivecompensation with ongoing reviews, versátil compensation anddiscount on brands.
Wellbeingprogram: Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more!
In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team. In addition, bank transfers and bank cards will neverbe requested. If you are contacted through another process, please get in touch with the person responsible for the selection process. xcskxlj
We promote equal opportunities inrecruitment, and we are committed to inclusion and diversity.
#J-18808-Ljbffr
📌 DevSecOps / AppSec Engineer (Tres Cantos)
🏢 Gmv Spain
📍 Tres Cantos