Overview In this role you will specialize in Application Security and SSDLC, collaborating with development teams to reduce security risks from early in the development lifecycle. You will conduct SAST and SCA reviews on large-scale services and help translate findings into actionable remediations. You will triage vulnerabilities, contextualize risk, and support developers with fixes. This position offers growth in a security-focused team that shapes secure development practices and continuous improvement.
Compensaciones / Beneficios Hybrid working model
teleworking up to 8 weeks/year
versátil start/finish times
career plan development and training
relocation package
competitive compensation and wellbeing program
Responsabilidades Perform and analyze SAST and SCA reviews, including configuring projects and tools
Triage vulnerabilities, validate findings and false positives
Classify vulnerabilities and prepare technical reports with evidence and recommendations
Advise developers on remediation and verify fixes
Review vulnerabilities in libraries and dependencies
Apply secure development practices and collaborate with DevSecOps for service improvement
Requisitos principales Knowledge of OWASP Top 10, CWE, CVE and CVSS
Ability to analyze code and identify contextual vulnerabilities
Knowledge of secure development and secure coding best practices
Experience with Git and code repositories
Ability to prepare technical documentation and communicate remediation to developers
Experience with Fortify, Checkmarx or equivalent platforms is a plus
Knowledge of SCA, dependency analysis and manual code review is valued
Analytical mindset
Clear communication with development teams
Collaborative, team-oriented
SAST
SCA
OWASP Top 10
📌 Vulnerability Management Team Lead (Tres Cantos)
🏢 GMV
📍 Tres Cantos
Postulate a este anuncio
Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.