Application & Cloud Security Consultant

Hace 16 horas

Madrid, España Kyndryl Jornada completa

This job is with Kyndryl, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.

Who We Are

At Kyndryl, we run and reimagine the mission-critical technology systems that drive advantage for the world's leading businesses.  We are at the heart of progress; with proven expertise and a continuous flow of AI-powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people-Kyndryls-that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well-being is prioritized and your potential can thrive.


The Role

The Application & Cloud Security Consultant will support the design, implementation, and continuous improvement of secure-by-design principles across application development, cloud environments, and modern access architectures. The role combines hands-on technical expertise and consulting capabilities to help organizations embed security throughout the software lifecycle while strengthening cloud security posture and Zero Trust access frameworks.


Who You Are

MIN. REQUIRED EXPERIENCE

  • 5+ years of experience in Cybersecurity Services, with a focus on Application Security, Cloud Security, and Secure Software Development Lifecycle (Secure SDLC).
  • Proven experience working within enterprise-scale cloud and hybrid environments.

LANGUAGES

  • Spanish and English (B2 level or higher).

EDUCATION AND CERTIFICATION

  • Bachelor's or Master's degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, or equivalent experience.
  • Highly desired certifications:
    • CCSK (Certificate of Cloud Security Knowledge)
    • CCSP (Certified Cloud Security Professional)
    • AZ-500 Microsoft Azure Security Technologies
    • AWS Certified Security - Specialty
    • Kubernetes Security Specialist (CKS)
    • Relevant Secure SDLC, DevSecOps, or Cloud Security certifications

CORE REQUIRED COMPETENCIES

  • Secure SDLC Governance: Definition and implementation of secure development frameworks and security gates.
  • DevSecOps Automation: Integration of security tools into CI/CD platforms and developer workflows.
  • Application Security Testing: Expertise in SAST, DAST, API Security Testing, SCA, and container security assessments.
  • Cloud Security Architecture: Deep understanding of Azure, AWS, and cloud-native security controls, including identity, networking, encryption, and workload protection.
  • Cloud Security Posture Management (CSPM): Experience assessing and improving cloud configurations, policies, and governance frameworks.
  • SASE & Zero Trust Architectures: Understanding of Secure Service Edge (SSE), Secure Web Gateway (SWG), CASB, ZTNA, and modern secure access architectures.
  • Threat Modeling & Risk Assessment: Ability to identify security risks in applications and cloud workloads and define pragmatic mitigation strategies.
  • Analytical Thinking: Strong troubleshooting and problem-solving skills in complex enterprise environments.
  • Documentation & Stakeholder Management: Ability to communicate security requirements and collaborate effectively with development, infrastructure, and security teams.

KEY RESPONSIBILITIES

  • Drive Secure SDLC adoption across development programs.
  • Support implementation of DevSecOps tooling and automated security controls.
  • Perform application security assessments and architecture reviews.
  • Define secure coding standards and developer awareness initiatives.
  • Monitor application security posture and support remediation efforts.
  • Collaborate with cloud, infrastructure, and development teams to reduce application-related risks
  • Cloud Security Hardening: Assist in implementing cloud security controls, governance models, and remediation plans across Azure, CGP and AWS environments.
  • SASE/ZTNA Adoption: Support the deployment and optimization of modern secure access solutions aligned with Zero Trust principles (ZScaler, Netskope, etc)
  • Risk Mitigation & Governance: Identify security gaps, propose remediation roadmaps, and help ensure compliance with organizational security policies and industry standards.


Being You

The "Kyn" in Kyndryl means kinship, which represents the strong bonds