Excelia, SL
3 weeks ago
AppSec Specialist Senior
Sign up to save this job, get alerts, and apply with an optimized CV.
Company information
- Company
- Excelia, SL
- Location
- España, Comunidad de Madrid, Madrid, Boadilla del Monte Spain
- Posted
- 3 weeks ago
Job description
At Excelia, a multinational Consulting, Technology, and Professional Services firm, we have over 25 years of experience and a presence in more than 50 countries across Europe, Latin America, and the United States, through our 9 own offices.
We are looking for an AppSec Specialist, with solid experience in Application Security, DevSecOps, Cloud Security, or Offensive Security, to strengthen the team responsible for the evolution of the AppSec framework for one of our main clients.
The selected person will have a specialized role in three key areas: Security by Design, Verification & Continuous Testing, and development of new initiatives, participating in both the definition of frameworks and the evaluation of new security technologies and capabilities.
Responsibilities
- Lead the Security by Design (SbD) practice, defining security requirements and controls and integrating them into the development cycle.
- Conduct sessions with development teams to ensure the correct application of security requirements.
- Design and evolve the Verification & Continuous Testing model, defining the different layers of analysis and testing.
- Establish criteria for vulnerability prioritization and security gates within the production deployment cycle.
- Participate in the evolution of the AppSec framework, identifying new needs and capabilities.
- Lead PoCs and benchmarks of new technologies within the AppSec Laboratory.
- Define evaluation criteria, execute proof-of-concepts, analyze results, and develop adoption recommendations.
- Independently evaluate solutions, identifying the most suitable technology for each need without dependency on a specific vendor.
- Collaborate with development, security, and technology teams to integrate AppSec capabilities into their processes.
- Work with advanced models for vulnerability prioritization, considering factors such as reachability, EPSS, KEV, and asset context.
Requirements
-
Technical degree in Computer Engineering, Telecommunications, Cybersecurity, or similar.
-
Minimum 4 years of experience in AppSec or related disciplines such as Cloud Security, DevSecOps, or Offensive Security.
-
Experience in at least two of the following areas:
- Security by Design.
- Verification & Continuous Testing.
- Design and evolution of AppSec frameworks.
-
Experience evaluating new security technologies, performing PoCs, and documenting adoption recommendations.
-
Ability to analyze and compare security solutions from an independent perspective.
-
Experience with SAST / AI-SAST tools, such as SonarQube, Semgrep, GitHub Advanced Security/CodeQL, Checkmarx, or Snyk Code.
-
Knowledge of SCA and reachability analysis, using tools like Prisma Cloud App Security, JFrog X-Ray, Dependency Track, or Trivy.
-
Experience or knowledge in DAST, IAST, RASP, and API Security.
-
Knowledge of DefectDojo and prioritization models based on EPSS, CISA KEV, reachability, and asset context.
-
Experience with containers and Kubernetes from a security perspective.
-
Fluent English for technical communication with international teams and vendors.
Will be valued
- Experience building or leading an AppSec program from scratch or in a significant evolution phase.
- Knowledge of offensive security and exploit chains, including BOLA, SSRF, IDOR, and vulnerability chaining.
- Experience in AI/ML Security, including OWASP LLM Top 10, security of models in production, and AI supply chain.
- Certifications such as CCSP, OSCP, CSSLP, AWS Security Specialty, CKS, or equivalent.
- Knowledge of regulatory frameworks such as NIS2, ENS, or IEC 62443.
Work modality
100% remote, with the possibility of working from anywhere in Spain.
What do we offer?
Stable employment in an international company.
Salary band commensurate with your experience and responsibilities.
Flexible remuneration.
Continuous training and specialization in AppSec, DevSecOps, and Cloud Security.
Participation in strategic cybersecurity and application security projects.
100% remote work and flexible hours.
Professional development plan within a specialized team with exposure to emerging security technologies.
If you have experience in AppSec and want to participate in the evolution of application security programs, evaluation of new technologies, and definition of Security by Design, we would love to meet you!
Required skills
- kubernetes
- containers
- cloud security
- application security
- ccsp
- oscp
- devsecops
- sonarqube
- benchmarks
- nis2
- pocs
- security by design
- cks
- sast
- dast
- checkmarx
- api security
- trivy
- sca
- iast
- offensive security
- github advanced security
- ens
- iec 62443
- ai/ml security
- csslp
- security gates
- semgrep
- rasp
- defectdojo
- dependency track
- aws security specialty
- codeql
- owasp llm top 10
- reachability analysis
- idor
- epss
- ssrf
- appsec specialist
- verification & continuous testing
- vulnerability prioritization
- appsec framework
- ai-sast
- snyk code
- prisma cloud app security
- jfrog x-ray
- cisa kev
- exploit chains
- bola
- vulnerability chaining
Interested in this position?
Create your free account and tailor your CV to match this job.