14 sep
|
Gmv Spain
|
Madrid
Application Security and DevSecOps Technical Leader
If you want to takethe next step in your cybersecurity career,combining technical service management with a hands-on role in
Application Security andDevSecOps,
this opportunity will allow you to contribute to theevolution of a corporate security service within a large organization. We´ll get to the point; we'll tell you what's not on the web.If you want to know more about deGMV WHAT CHALLENGE WILL YOU BE TAKING ON? You will combine twokey responsibilities:
acting as the technicalreference and customer point of contact, while also contributinghands-on to the implementation and evolution of
ApplicationSecurity, SSDLC and DevSecOps capabilities. Your mainresponsibilities will include: Technically coordinating theservice, managing demand, planning, priorities, capacity,
SLAs and
KPIs . Integrating, configuring andoptimizing
SAST/SCA controls in
CI/CD pipelines. Coordinating applicationonboarding anddefining
Security Gates. Contributing to vulnerabilitytriage, prioritization, remediation and revalidation. Acting as the technical pointof contact for the customer, providing reporting and service follow-up. Driving automationand industrialization through APIs and scripting. Managing risks, incidents,deviations and escalations. Advising development teamsand coordinating with different technical areas. Driving the evolution of the
SSDLC/DevSecOpsmodel , includingthe safe and supervised adoption of AI. WHAT DO WE NEED IN OUR TEAM? We are looking for aprofessional with solid experience in
ApplicationSecurity, SSDLC and DevSecOps , combining technical expertise withexperience in service or team coordination. You should haveknowledge of: SAST/SCA ,vulnerability management and
CI/CD security. OWASP, CWE,CVE,
CVSS and
Secure Coding. Git , pipelines and
Security Gates. SLA, KPI, demand, capacity and risk management. APIs , scripting and automation . Customer interaction and technical/executivereporting. AIgovernance and risk management, including traceability and human oversight. We will also value previous experiencewith Checkmarx, Fortify, SonarQube and CI/CDplatforms such as Azure DevOps, Jenkins, GitHubActions or GitLab CI/CD will be valued, as well as knowledge of Cloud, containers, IaC and software supply chainsecurity. Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF and securityautomation will also be valued, as well as experience applying AI to AppSec/DevSecOps and relevant training orcertifications. WHAT DO WE OFFER? Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area. Flexible start and finish times, and intensive working hours Fridays and insummer. Personalizedcareer plan development, training and language learning support. National and international mobility. Do you come from another country?We can offer you a relocation package. Competitivecompensation with ongoing reviews, adaptable compensation anddiscount on brands.
Wellbeingprogram: Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more! In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team. In addition, bank transfers and bank cards will neverbe requested. If you are contacted through another process, please get in touch with the person responsible for the selection process. We promote equal opportunities inrecruitment, and we are committed to inclusion and diversity.
📌 Application Security and DevSecOps Technical Leader (Madrid)
🏢 Gmv Spain
📍 Madrid