Overview
Usted podría ser el solicitante perfecto para este trabajo. Lea toda la información asociada y asegúrese de presentar su candidatura.
In this role you help evolve a corporate security service by combining technical leadership with hands-on AppSec work. You will coordinate the security service while implementing and advancing SSDLC and DevSecOps capabilities within a large organization. Expect to drive security gates, automate controls in CI/CD, and guide risk management and reporting. This is a hands-on, cross-functional role with a strong focus on impact, automation, and AI-enabled security. You will collaborate with development teams to shape secure software delivery.
Compensaciones / Ventajas
Hybrid working model
8 weeks teleworking per year
Flexible start/end times; intensive Fridays and summer
Personalized career plan development; training and language learning support
National and international mobility; relocation package
Competitive compensation with ongoing reviews; flexible compensation; brand discounts
Responsabilidades
Technically coordinate the security service, manage demand, plan priorities, capacity, SLAs and KPIs
Integrate, configure and optimize SAST/SCA controls in CI/CD pipelines
Coordinate application onboarding and define Security Gates
Contribute to vulnerability triage, remediation and revalidation
Act as technical point of contact for customers, providing reporting and follow-up
Drive automation and industrialization through APIs and scripting
Manage risks, incidents, deviations and escalations
Advise development teams and coordinate with different technical areas
Drive evolution of the SSDLC/DevSecOps model, including AI governance and supervised adoption
Requisitos principales
Solid experience in Application Security, SSDLC and DevSecOps with service or team coordination
Knowledge of SAST/SCA, vulnerability management, and CI/CD security
Familiarity with OWASP, CWE, CVE, CVSS and Secure Coding
Experience with Git, pipelines and Security Gates
Understanding of SLA, KPI, demand, capacity and risk management
Experience with APIs, scripting and automation
Customer interaction and technical/executive reporting
AI governance xqbhyrx and risk management, including traceability and human oversight
Experience with Checkmarx, Fortify, SonarQube and CI/CD platforms (Azure DevOps, Jenkins, GitHub Actions, GitLab CI/CD) is valued
Knowledge of Cloud, containers, IaC and software supply chain security
Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF; security automation; and applying AI to AppSec/DevSecOps
Relevant training or certifications are valued
Strong communication and stakeholder management
Collaborative team player with cross-functional coordination
Problem-solving and analytical mindset
SAST/SCA and vulnerability management
CI/CD security and pipelines
Security Gates and gate-based on-boarding
📌 Application Security and DevSecOps Technical Leader (Madrid)
🏢 GMV
📍 Madrid