Security Champion
Security Champion
Security Champion
Need a visa? No sponsorship mentioned here. Browse visa jobs.
About the role
Are you passionate about technology? Do you want to grow in a dynamic, constantly expanding company? We are looking for you! At Nunsys Group we are expanding our team, and we are looking for a Security Champion to join us in Barcelona.
Our journey began in 2007 and we have one goal: to be the leading Spanish technology company. We are passionate about digital transformation and have a broad portfolio of technology solutions. Thanks to this, we can guarantee that we can take on any challenge our clients present to us.
We currently have more than 2,600 professionals and a presence in 25 Spanish cities, Portugal, the USA, Colombia, and Ecuador. And this is only the beginning!
Your mission will be to ensure that security is embedded across the entire application lifecycle. The selected candidate will act as the cybersecurity point of reference within the team, combining technical security expertise with a perspective close to software development and architecture.
And what does the project involve? The day-to-day work is very varied, but some of the main duties you will take part in are:
What you'll do
- Verify that all applications in the squad have their Risk Profile correctly assigned, in accordance with the internal risk assessment methodology.
- Check that each application follows the architecture pattern defined in the corporate blueprints.
- Generate and keep the Security Requirements of the squad's applications up to date, reviewing them in response to any functional change.
- Prepare and update the threat modeling of the applications, adapting it to the evolution of the functionality.
- Request and analyze the results of the Security Tests to define and implement the appropriate mitigations.
- Analyze new functional requirements to apply the relevant security measures from the initial phases (Security by Design).
- Review the results of the SAST and SCA tools, and manage the creation and tracking of tickets (Jira) to ensure the resolution of vulnerabilities within the established deadlines, in collaboration with the security gates defined for production deployment.
How you'll work
Permanent
remote
About the company & team
Cybersecurity and information security
About the role
¿Te apasiona la tecnología? ¿Quieres desarrollarte en una empresa dinámica y en constante crecimiento? ¡Te estamos buscando! En Nunsys Group estamos ampliando nuestro equipo, buscamos un/a Security Champion para incorporarse en Barcelona.
Nuestro viaje empezó en 2007 y tenemos una meta: ser la empresa española líder en tecnología. Nos apasiona la transformación digital y contamos con un gran portfolio de soluciones tecnológicas. Gracias a esto garantizamos que podemos afrontar cualquier reto que nos planteen nuestros clientes.
Actualmente somos más de 2.600 profesionales y tenemos presencia en 25 ciudades españolas, Portugal, USA, Colombia y Ecuador. ¡Y esto es solo el principio!
Tu misión será garantizar que la seguridad se incorpora de forma transversal en todo el ciclo de vida de las aplicaciones. La persona seleccionada actuará como punto de referencia en materia de ciberseguridad dentro del equipo, combinando conocimientos técnicos de seguridad con una visión cercana al desarrollo y la arquitectura de software.
Y el proyecto ¿en qué consiste? El día a día es muy variado, pero algunas de las funciones principales en las que participarás son:
What you'll do
- Verificar que todas las aplicaciones del squad tienen asignado correctamente su Risk Profile, conforme a la metodología interna de evaluación de riesgos.
- Comprobar que cada aplicación sigue el patrón de arquitectura definido en los blueprints corporativos.
- Generar y mantener actualizados los Security Requirements de las aplicaciones del squad, revisándolos ante cualquier cambio funcional.
- Elaborar y actualizar el modelado de amenazas (Threat Modeling) de las aplicaciones, adaptándolo a la evolución de la funcionalidad.
- Solicitar y analizar los resultados de los Security Tests para definir e implementar las mitigaciones adecuadas.
- Analizar nuevos requisitos funcionales para aplicar las medidas de seguridad pertinentes desde las fases iniciales (Security by Design).
- Revisar los resultados de las herramientas SAST y SCA, y gestionar la creación y seguimiento de tickets (Jira) para asegurar la resolución de vulnerabilidades dentro de los plazos establecidos, en colaboración con los security gates definidos para el paso a producción.
How you'll work
permanent
remote
About the company & team
Ciberseguridad y seguridad de la información
You'll most likely need Spanish to apply.This job was automatically translated to English, .