DevSecOps & Application Security Lead

JustMarkets
JustMarkets
Remote, EuropeRemoteCompetitivoPublicado hace 16 días
🇬🇧Inglés requeridoSecurity

Anuncio original

We are looking for a DevSecOps and Application Security Lead to join our team and build our application security from scratch. In this role, you will lead the security direction within our department, focusing on integrating security into the software development process. By balancing automation with practical DevSecOps practices, you will help our engineering teams find and fix vulnerabilities early, ensuring our products are safe and strong without slowing down development.

Responsibilities

  • Build the DevSecOps/AppSec function from scratch, and create the roadmap, KPIs, and metrics for leadership
  • Create secure development processes, including release security gates and vulnerability management
  • Choose, configure, and integrate security scanners (SAST, SCA, secrets) with a focus on automation and AI-assisted workflows
  • Integrate security checks into pipelines and development processes together with Engineering, DevOps, and Product teams
  • Run threat modeling and security reviews for high-risk systems and major architecture changes
  • Create clear security standards, checklists, and practical guidelines for developers (covering code, APIs, and secrets)
  • Launch and grow a Security Champions program to involve engineers in security processes
  • Help investigate incidents related to application vulnerabilities, leaked secrets, and supply-chain attacks

Requirements

  • 5+ years of experience in DevOps, SRE, Platform Engineering, or related  infrastructure/security roles
  • 3+ years focused on DevSecOps and Application Security
  • 1+ years in a lead/ownership role
  • Deep understanding of modern software development, Git workflows, and hands-on experience integrating security checks into CI/CD pipelines without creating bottlenecks
  • Practical experience with SAST, SCA, secrets scanning, and vulnerability management (triage, risk rating, remediation, and validation)
  • Ability to select and scale security tools based on accuracy, false-positive rates, and developer experience
  • Strong knowledge of web/API/mobile risks (OWASP Top 10, auth, supply-chain risks) and ability to run threat modeling and secure design reviews
  • Good scripting skills (Python, Bash, or similar) and understanding of cloud-native/containerized environments
  • Ability to write clear security requirements and guidelines for developers
  • English - Intermediate+ or higher

Nice to Have

  • Experience building AppSec/DevSecOps functions from scratch or early maturity stages
  • Hands-on experience with tools like Snyk, Aikido, Semgrep, Trivy, Gitleaks, GitHub/GitLab Security, or SonarQube
  • Experience with cloud/IaC security, Kubernetes, and mobile app security
  • Knowledge of compliance standards (SOC 2, ISO 27001, PCI DSS, DORA) and experience with Bug Bounty or pentest coordination
  • Experience with Security Champions programs and AI-assisted security tools

We offer

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company's approved Public holiday list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)

Technical Product Manager - Wallet & Custody Infrastructure

Europe
2sem

Product Manager (Trading Core & Infrastructure)

Europe
1m

Beca para el área de Diseño Seguro (CISO)

Madrid
Nuevo

Tech_Técnico/a SSE - Netskope (Security Service Edge)

Madrid
Nuevo

Incident Response Technology Risk & Cybersecurity Specialist - Santander Digital Services

Madrid
Nuevo

Sovereign Cloud Security Senior Specialist (f/m/d)

St. leon-rot
Nuevo

IT Security Adaptative Threat Intelligence

Martorell
Nuevo

Site Security and Automation Lead -Viana (Cerca de Logroño)

Viana
Nuevo

Ingeniero de Software de Plataforma Junior (DevSecOps & Observabilidad)

Madrid
Nuevo

Cloud, Infrastructure & Cybersecurity Manager

Madrid
Nuevo

Cloud Security Consultant

Madrid
Nuevo

DevSecOps Lead

Madrid
Nuevo

Cybersecurity Presales Senior

Madrid
Nuevo

Systems & Cybersecurity Architect - Alcobendas

Madrid
Nuevo
Remoto

Software Developer

Madrid (Remote)
Nuevo
Remoto

Conversational AI Reviewer

Madrid (Remote)
Nuevo
Remoto

Medical Director

Madrid (Remote)
Nuevo
Remoto

Director of Engineering

Madrid (Remote)
Nuevo
Remoto

Key Account Manager - Public Healthcare

Madrid (Remote)
Nuevo
Remoto

Director of Customer Success

Madrid (Remote)
Nuevo

Business Development Representative

Madrid, ES / Stockholm, SE / London, GB / EU, EU (Remote)
Nuevo

Account Executive

EU, EU (Remote) / London, GB / Madrid, ES / Stockholm, SE
Nuevo

Pre-sales Specialist

US (Remote), US (Remote), US
Nuevo

AI Data Architect

Remote, ES / Milano, Italy, IT / Verona, Italy, IT / Firenze, Italy, IT
45 mil € - 75 mil €Nuevo

Data Model & Semantics Architect

Remote, ES
Nuevo

Tech Lead | Software Architecture & AI

Barcelona, ES / Logroño, ES / Madrid, ES / Remote, ES / Santiago de Compostela, ES / València, ES
Nuevo

Candidatura gestionada por JustMarkets