Senior Application Security Engineer

hace 4 días


Zaragoza provincia, España Adidas A tiempo completo

Purpose & Overall Relevance for the Organization: - The selection, design, justification, implementation and operation of controls and management strategies to maintain the security, confidentiality, integrity, availability, accountability and relevant compliance of information systems with legislation, regulation and relevant standards. Key Responsibilities: - Information security - Provides advice and guidance on security strategies to manage identified risks and ensure adoption and adherence to standards. - Obtains and acts on vulnerability information and conducts security risk assessments, business impact analysis and accreditation on complex information systems. - Investigates major breaches of security, and recommends appropriate control improvements. - Contributes to development of information security policy, standards and guidelines. - Specialist advice - Actively maintains recognisedexpert level knowledge in one or more identifiable specialisms. - Provides definitive and expert advice in their specialist area(s). - Oversees the provision of specialist advice by others, consolidates expertise from multiple sources, including third partyexperts, to provide coherent advice to further organisational objectives. - Supports and promotes the development and sharing of specialist knowledge within the organisation. - Research - Within given research goals, builds on and refines appropriate outline ideas for research, including evaluation, development, demonstration and implementation. - Applies standard methods to collect and analyse quantitative and qualitative data. - Creates research reports to communicate research methodology and findings and conclusions. Contributes sections of material of publication quality. - Uses available resources to update knowledge of any relevant field and curates a personal collection of relevant material. Participates in research communities. - Emerging technology monitoring - Supports monitoring of the external environment and assessment of emerging technologies to evaluate the potential impacts, threats and opportunities to the organization. - Contributes to the creation of reports, technology road mappingand the sharing of knowledge and insights. - Security administration - Maintains security administration processes and checks that all requests for support are dealt with according to agreed procedures. - Provides guidance in defining access rights and privileges. - Investigates security breaches in accordance with established procedures and recommends required actions and supports / follows up to ensure these are implemented. - Digital Forensic - Contributes to digital forensic investigations. Processes and analyses evidence in line with policy, standards and guidelines and supports production of forensics findings and reports. - Penetration testing - Maintains current knowledge of malware attacks, and other cyber security threats. - Creates test cases using in-depth technical analysis of risks and typical vulnerabilities. - Produces test scripts, materials and test packs to test new and existing software or services. - Specifies requirements for environment, data, resources and tools. - Interprets, executes and documents complex test scripts using agreed methods and standards. - Records and analyses actions and results. - Reviews test results and modifies tests if necessary. - Provides reports on progress, anomalies, risks and issues associated with the overall project. - Reports on system quality and collects metrics on test cases. - Provides specialist advice to support others. - Relationship management - Implements stakeholder engagement/communications plan. - Deals with problems and issues, managing resolutions, corrective actions, lessons learned and the collection and dissemination of relevant information. - Collects and uses feedback from customers and stakeholders to help measure effectiveness of stakeholdermanagement. - Helps develop and enhance customer and stakeholder relationships. - Identify, reproduce, and report security issues - Conduct internal security reviews - Collaborate with software engineers to make our software better - Collaborate with Product Owners and Architects to identify and understand vulnerabilities related to its products - Keeping abreast of new vulnerabilities and attack vectors, and associated countermeasures - Participate in security issue management processes - Penetration test reports analysis - Red Team exercises technical support - Bug bounty triage. - Key Relationships: - Global IT - Respective business function(GOPS, Finance, HR, Brand Marketing, Wholesale/Retail) - HR Management - Controlling - Knowledge, Skills and Experience - A "breaker" mentality, but effective at crafting the mitigating controls - Provide hands-on remediation guidance to product teams - Penetration testing and red teaming experience in corporate environments (Burp, cobalt strike, Mittre Att&ack framework) - Knowledge of DevSecOps or secure SDLC li



  • Ourense provincia, España Flywire A tiempo completo

    Company Description **Are you ready to trade your job for a journey? Become a FlyMate!** Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. We use our Flywire Advantage - the combination of our next-gen payments platform,...


  • Zaragoza, España Amazon A tiempo completo

    Job ID: | Amazon.com Services LLCWe are open to hiring candidates to work out of one of the following locations: New York, NY, USAThe Amazon Artificial General Intelligence (AGI) organization is focused on building world-class general-purpose intelligence services. Its primary mission involves developing highly autonomous systems through novel model...


  • Zaragoza, España Hitachi A tiempo completo

    Location: Cordoba Cordoba Spain Job Schedule: Full time Remote: No Job Description: The Opportunity The Distribution & DRY Application Engineer acts as a senior technical specialist and trusted advisor for Hitachi Energys DTR & Dry Distribution Transformer portfolio. This role focuses on early customer engagementprospecting and opportunity pursuitby...


  • zaragoza, España Amazon A tiempo completo

    Job ID: | Amazon Web Services Australia Pty Ltd Amazon Web Services (AWS) is the leading cloud service provider, providing virtualised infrastructure, storage, networking, messaging, and many other services to customers all over the world. AWS runs a globally distributed environment, operating at massive levels of scale. Businesses, from start‑ups to...


  • Zaragoza, España Amazon A tiempo completo

    Job ID: | Amazon Web Services Australia Pty LtdAmazon Web Services (AWS) is the leading cloud service provider, providing virtualised infrastructure, storage, networking, messaging, and many other services to customers all over the world. AWS runs a globally distributed environment, operating at massive levels of scale. Businesses, from start‑ups to...


  • Zaragoza, España Amazon A tiempo completo

    Job ID: 3128132 | Amazon Web Services Australia Pty LtdSea uno de los primeros solicitantes, lea la descripción completa del puesto a continuación y luego envíe su candidatura para que sea considerada.Amazon Web Services (AWS) is the leading cloud service provider, providing virtualised infrastructure, storage, networking, messaging, and many other...


  • Zaragoza, España Amazon A tiempo completo

    Job ID: | Amazon.com Services LLC We are open to hiring candidates to work out of one of the following locations: New York, NY, USA The Amazon Artificial General Intelligence (AGI) organization is focused on building world-class general-purpose intelligence services. Its primary mission involves developing highly autonomous systems through novel model...


  • Zaragoza, España Amazon A tiempo completo

    A leading tech company in Spain is seeking a Security Engineer to ensure AGI models and applications are secure and reliable. You will address a range of security challenges, collaborate with teams, and foster a culture of security ownership. Ideal candidates will have a strong background in identifying vulnerabilities and mentoring others. The position...


  • Zaragoza, España Adidas A tiempo completo

    At adidas, we believe that "Through Sport, we have the power to change lives”._ - To change lives, we have to create direct relationships with consumers, and the best way to accelerate this process is through Digital_ SENIOR PLATFORM ENGINEER NETWORK SECURITY Purpose & Overall Relevance for the Organization: Connectivity Team work to provide the...


  • Zaragoza, España Wise Security Global A tiempo completo

    **What are we looking for?**: Technical education (Bachelor's degree in Computer Science, a related field, or equivalent) will be necessary. High level of English and Spanish will be necessary. Specific experience required: - Implementing security governance and compliance projects. - Analyzing, designing and implementing Information Security Management...