13 sep
|
GMV
|
Tres Cantos
Experteer Overview In this role you help evolve a corporate security service by combining technical leadership with hands-on AppSec work. You will coordinate the security service while implementing and advancing SSDLC and DevSecOps capabilities within a large organization. Expect to drive security gates, automate controls in CI/CD, and guide risk management and reporting. This is a hands-on, cross-functional role with a strong focus on impact, automation, and AI-enabled security. You will collaborate with development teams to shape secure software delivery.Compensaciones / Beneficios
- Technically coordinate the security service, manage demand, plan priorities, capacity, SLAs and KPIs
- Integrate, configure and optimize SAST/SCA controls in CI/CD pipelines
- Coordinate application onboarding and define Security Gates
- Contribute to vulnerability triage, remediation and revalidation
- Act as technical point of contact for customers, providing reporting and follow-up
- Drive automation and industrialization through APIs and scripting
- Manage risks, incidents, deviations and escalations
- Advise development teams and coordinate with different technical areas
- Drive evolution of the SSDLC/DevSecOps model, including AI governance and supervised adoptionResponsabilidades
- Solid experience in Application Security,
SSDLC and DevSecOps with service or team coordination
- Knowledge of SAST/SCA, vulnerability management, and CI/CD security
- Familiarity with OWASP, CWE, CVE, CVSS and Secure Coding
- Experience with Git, pipelines and Security Gates
- Understanding of SLA, KPI, demand, capacity and risk management
- Experience with APIs, scripting and automation
- Customer interaction and technical/executive reporting
- AI governance and risk management, including traceability and human oversight
- Experience with Checkmarx, Fortify, SonarQube and CI/CD platforms (Azure DevOps, Jenkins, GitHub Actions, GitLab CI/CD) is valued
- Knowledge of Cloud, containers, IaC and software supply chain security
- Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF; security automation; and applying AI to AppSec/DevSecOps
- Relevant training or certifications are valuedRequisitos principales
- Hybrid working model
- 8 weeks teleworking per year
- Flexible start/end times; intensive Fridays and summer
- Personalized career plan development; training and language learning support
- National and international mobility; relocation package
- Competitive compensation with ongoing reviews; adaptable compensation; brand discounts
📌 Application Security And Devsecops Technical Leader (Tres Cantos)
🏢 GMV
📍 Tres Cantos