DevSecOps / AppSec Information Security Engineer
Madrid, Community of Madrid, Spain
Applications have closed
DevSecOps Engineer
Ryanair Labs is the technology brand of Ryanair. Labs is a state of-the-art digital & IT innovation hub creating Europe's Leading Travel Experience for our customers. The Ryanair platform has over 1 billion visits per year. By joining Ryanair, you will develop cutting edge tech solutions inside Ryanair, transforming aviation for Pilots, Cabin Crew & Ground Ops, as well as driving the tech experience for our customers on Europe’s largest travel website!
Ryanair Labs has more than 550 employees across our offices in Dublin, Madrid, Poland, and Portugal. Our plan is to continue to grow our IT Labs Team so we are always on the lookout for the best talent. Apply today for more information.
The Role
We are looking for an Information Security Engineer, comfortable in working with minimal supervision. Will perform security architecture reviews of new and existing platforms. Partner with business units, departments providing input on security standard methodologies throughout project-lifecycles. Contribute to the Security program by performing reviews and security audits. Talk confidently about our Cyber Security program, and help integrate our business needs with our Cyber Security needs. The SecDevOps Engineer provides operational & security expertise in executing technology strategies implementing secure software development measures into CI/CD pipelines and collaborating with dev teams to apply a shift-left security strategy in the development lifecycle.
Responsibilities:
- Contributing features to internally developed Cybersecurity tools and integrating those tools into the DevOps pipelines
- Oversee development lifecycles and analyze security information related
- Driving continuous improvement to the DevOps pipelines and processes and the Cybersecurity tools, services, and processes
- Performing technology research from a security context for strategic, tactical, and operational business needs and deliver research results to internal stakeholders
- Research appropriate security testing tools
- Whitebox code review of these products, applications, and integrations where appropriate
- Blackbox review of products, applications, and integrations where appropriate
- Aligns security deliverables with legal, regulatory and contractual requirements that conform with security framework and standards such as NIST SP 800-53 rev 4, ISO/IEC 27000 series, OWASP Top 10, SANS Top 20, CIS Top 20.
Requirements
- Experience working with Cloud in a security-enabled environment
- Strong experience with AWS is required
- Proven ability to work independently, collaboratively as part of a global team and deliver to multiple deployment schedules
- Proven experience with Web Application Security Testing, Code Reviews, Vulnerability Assessment, Penetration Testing & Generating Reports
- Experience with (NIST, PCI) security controls, governance & risk management protocols
- Relevant experience with application security, secure software development, and building security into software development workstreams
- Demonstrated proficiency in preparing high-quality documentation and presentation skills
Benefits
- A competitive but flexible career plan.
- We offer a relocation package to people who are coming from another country.
- Travel discounts (of course!).
- Hybrid remote work model (3 remote/ 2 office).
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Audits AWS CI/CD Cloud DevOps DevSecOps Governance NIST OWASP Pentesting Risk management SANS Security strategy Strategy
Perks/benefits: Career development Flex hours Relocation support
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Senior Information Security Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Chief Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Senior Security Architect jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Analyst jobs
- Open o365 Security Architect jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Security Researcher jobs
- Open Product Security Engineer jobs
- Open Application security-related jobs
- Open GCP-related jobs
- Open Governance-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Pentesting-related jobs
- Open Analytics-related jobs
- Open ISO 27001-related jobs
- Open CISM-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open SaaS-related jobs
- Open Security Clearance-related jobs
- Open Malware-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open Java-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open DoD-related jobs
- Open APIs-related jobs
- Open Forensics-related jobs
- Open Splunk-related jobs
- Open EDR-related jobs