Application Security and DevSecOps Technical Leader - tres cantos
5 days ago
Tres Cantos
Overview In this role you help evolve a corporate security service by combining technical leadership with hands-on AppSec work. You will coordinate the security service while implementing and advancing SSDLC and DevSecOps capabilities within a large organization. Expect to drive security gates, automate controls in CI/CD, and guide risk management and reporting. This is a hands-on, cross-functional role with a strong focus on impact, automation, and AI-enabled security. You will collaborate with development teams to shape secure software delivery. Compensaciones / Beneficios • Hybrid working model, • 8 weeks teleworking per year, • Flexible start/end times; intensive Fridays and summer, • Personalized career plan development; training and language learning support, • National and international mobility; relocation package, • Competitive compensation with ongoing reviews; flexible compensation; brand discounts Responsabilidades, • Technically coordinate the security service, manage demand, plan priorities, capacity, SLAs and KPIs, • Integrate, configure and optimize SAST/SCA controls in CI/CD pipelines, • Coordinate application onboarding and define Security Gates, • Contribute to vulnerability triage, remediation and revalidation, • Act as technical point of contact for customers, providing reporting and follow-up, • Drive automation and industrialization through APIs and scripting, • Manage risks, incidents, deviations and escalations, • Advise development teams and coordinate with different technical areas, • Drive evolution of the SSDLC/DevSecOps model, including AI governance and supervised adoption Requisitos principales, • Solid experience in Application Security, SSDLC and DevSecOps with service or team coordination, • Knowledge of SAST/SCA, vulnerability management, and CI/CD security, • Familiarity with OWASP, CWE, CVE, CVSS and Secure Coding, • Experience with Git, pipelines and Security Gates, • Understanding of SLA, KPI, demand, capacity and risk management, • Experience with APIs, scripting and automation, • Customer interaction and technical/executive reporting, • AI governance and risk management, including traceability and human oversight, • Experience with Checkmarx, Fortify, SonarQube and CI/CD platforms (Azure DevOps, Jenkins, GitHub Actions, GitLab CI/CD) is valued, • Knowledge of Cloud, containers, IaC and software supply chain security, • Knowledge of NIST SSDF, OWASP ASVS/SAMM, SBOM, SARIF; security automation; and applying AI to AppSec/DevSecOps, • Relevant training or certifications are valued, • Strong communication and stakeholder management, • Collaborative team player with cross-functional coordination, • Problem-solving and analytical mindset, • SAST/SCA and vulnerability management, • CI/CD security and pipelines, • Security Gates and gate-based on-boarding