15 sep
|
Isg Personalmanagement
|
Granada
15 sep
Isg Personalmanagement
Granada
Overview
In this role you will help secure customer-facing applications within a regulated betting environment. You will work with the Sofia cybersecurity team to integrate security into Agile development, focusing on vulnerability management, code reviews, and compliance. You’ll bridge development and security across Java, .NET, Python, and PHP stacks, addressing risk and threats. This position offers impact at scale in integral cybersecurity operations, with a practical DevSecOps focus and opportunities to shape secure coding practices.
Compensaciones / Beneficios
- Competitive salary
- hybrid work in Sofias tech hub
- growth in global cybersecurity operations
Responsabilidades
- Perform SAST, DAST, and penetration testing using Checkmarx, Burp Suite, OWASP ZAP, and Snyk
- Review code, manage software composition analysis for third-party libraries, and embed security into CI/CD pipelines using Jenkins or Azure DevOps
- Investigate security incidents, support SOC operations, and ensure PCI DSS/ISO compliance while educating developers on OWASP Top 10 risks
Requisitos principales
- 3+ years in software development (Java, .NET, Python, PHP) with transition to application security
- Proficiency with SAST/DAST tools (SonarQube, Veracode, Semgrep), WAF configuration, and runtime monitoring (Contrast Security)
- Knowledge of secure frameworks (Spring, ASP.NET), Unix systems, and regulated industry standards
- problem-solving
- team collaboration
- effective communication
- SAST/DAST tooling (Checkmarx, Burp Suite, OWASP ZAP, Snyk, SonarQube, Veracode, Semgrep)
- CI/CD security integration (Jenkins, Azure DevOps, GitHub Actions)
- runtime application security (Contrast Security)
📌 Security Application Analyst (Granada)
🏢 Isg Personalmanagement
📍 Granada