28 sep
|
ServiceNow
|
Madrid
Experteer Overview
Por favor, asegúrese de leer atentamente los siguientes detalles antes de enviar cualquier solicitud.
In this hands-on leadership role, you will architect and advance Armis' application security posture within the VIPR framework, spanning SaaS and on-prem platforms. You’ll partner across engineering, product security, and vulnerability management to identify, prioritize, and remediate risks, ensuring findings are contextualized with asset intelligence and business impact. You’ll drive security through the SDLC, automate AppSec testing, and enable a risk-based remediation culture.
This is a chance to shape secure design and foster cross-functional security collaboration at scale.
Compensaciones / Incentivos
- Lead the Application Security program across all products and embed security into the SDLC
- Conduct secure design reviews and collaborate with engineering to mitigate risk early
- Lead threat modeling sessions using STRIDE, DREAD, or PASTA
- Own application-layer vulnerability management within VIPR from detection to remediation
- Integrate AppSec findings (SAST, DAST, SCA, API testing) into centralized workflows and risk scoring
- Correlate vulnerabilities with asset context, exploit intelligence, and business criticality for remediation
- Track VMDR metrics (MTTD, MTTR, exposure windows, remediation effectiveness)
- Build and maintain automated AppSec pipelines for SAST/DAST/SCA/API security testing
- Collaborate with DevOps to integrate security scanning into CI/CD pipelines (GitHub Actions, Jenkins, Buildkite)
- Partner with Cloud and Infrastructure Security to secure APIs, microservices, and container workloads
- Develop and maintain secure coding standards for React, Node.js, Python, Java, Go
- Mentor engineers and security champions; deliver secure coding training and threat modeling workshops
- Act as trusted advisor to engineering leadership, translating vulnerabilities into actionable risk guidance
- Support compliance xugodme and audit readiness (SOC 2, ISO 27001, FedRAMP, HIPAA)
Responsabilidades
- 7-10+ years of experience in Application Security, Product Security, or Secure Software Engineering
- Proven expertise in SAST, DAST, SCA, and dependency management tools (Veracode, Checkmarx, Fortify, Snyk, SonarQube, OWASP Dependency-Check)
- Hands-on coding proficiency in at least two modern languages (Python, JavaScript/TypeScript, Java, Go)
- Strong knowledge of OWASP Top 10, CWE, CVE and exploitability concepts
- Experience with CI/CD pipelines, Git-based workflows, and secure build automation
Requisitos principales
•
📌 PS, Solution Architect ( Armis/Veza) (Madrid)
🏢 ServiceNow
📍 Madrid