Applications Security Specialist

hace 7 horas


Bogotá Cundinamarca, Colombia GSB A tiempo completo

Main Activities / Responsibilities:

- Generation of threat modeling analysis, security requirements and abuse cases for all
developments carried out in ADC.
- Analyze changes to existing software looking for security risks that can be implemented in the
coding process.
- Determine and advise on the recommended security controls required to remediate findings and
issues in an efficient and concise manner.
- Generate awareness campaigns to all stakeholders of the software process.
- Help developers to use secure coding practices, as well as resolve specific doubts about
vulnerabilities identified in the different testing scenarios.
- Align security solutions to Holcim methodologies and standards.
- Design, implement, and support the security model for general security solutions
- Develop and drive the implementation of security best practices and standards.
- Review requests for new systems or changes to existing systems and evaluate the impact to
security.
- Conduct pre-audits on security issues of concern, work with the user community on remediation;
conduct spot checks of user security to ensure compliance.
code and cloud services.
- Provide support to other colleagues in terms of technical/functional expertise with the assigned
business processes.
- Expert in Vulnerability Management tools like Qualys or Nessus.

Qualifications:

- Bachelor’s degree in Computer Science, Engineering, or related discipline with an IT focus.
- Certifications: CISSP, CISM, CISA, CRISC ITIL, CMMI, ISO 27001, GSEC, CSSLP.
- Ethical Hacking certifications desired.
- Secure coding certifications desired.

Required Experience:
focus, assessments and audits.
- Experience in fullstack development, object-oriented programming, microservices oriented
architecture, with knowledge in agile methodologies and DevOps model.

Desired Experience:

- Experience on secure development and ethical hacking.
- Experience with vulnerabilities and fixes for different languages (C, C#, Java, Javascript)

Soft skills:

- Experience coordinating and completing multiple tasks within established and changing deadlines.
- Excellent organizational, analytical, and independent problem solving skills.
- Demonstrated excellent oral and written communication skills necessary to interact effectively with
colleagues and with users of varying technological skill levels.
- Strong customer / end-user / client service orientation.
- Thrives working in a highly collaborative and team environment.
- Highly self-motivated and directed.
- Ability to provide 24/7 support to respond to critical incidents or business impacting project
deliverables.
- Keen attention to detail.
- Capability for problem solving, decision making, sound judgment, assertiveness.
- Ability to deal with difficult situations, unclear priorities and blocking stakeholders.
- Ability to work decisively under heavy workload considering the criticality, urgency and extended
work hours required to ensure availability of the service in accordance with service level
commitments.
- Ability to manage multi-cultural and multi-located teams.
Leadership skills:

- Lead by example on values and culture.
- A natural leader whose personality and communication skills instill a sense of credibility and trust.
- Able to coherently explain the proposed design and gain stakeholder buy-in to the proposed
solution.
- Cost conscious and keeps a big picture perspective.

Required skills:

- Authentication and Access Control Tools, Management and Administration.
- Application Security Architecture & Cloud Computing Concepts.
- Change & Security Configuration Audit and Control.
- Encryption Processes, Management and Administration.
- Experience in static and dynamic security testing (code review, vulnerability analysis, Ethical
Hacking)
- Knowledge in offensive security methodologies (OWASP, MASVS, OPENSAMM, CKC, etc).
Knowledge in tools such as OwaspZap, Burpsuite, Nessus, Service Manager, Git, Fortify, Codacy,
Sonarqube.

Desired skills:

- Knowledge in AWS cloud security.

Languages:

- English desired (written & spoken)
- Spanish required (written & spoken)

**Benefits**:

- Law benefits
- Courses and certifications



  • Bogotá, Colombia HCO ORTHOPEDICS, LLC A tiempo completo

    **Overview** Front Desk & IT Security Support Specialist Small Medical Clinic - United States Job Summary Our clinic is looking for a friendly, reliable team member to manage front-desk operations—answering phones, scheduling appointments, and assisting patients—while also supporting basic IT security needs. **Responsibilities**: Answer phones,...


  • Tocancipá, Cundinamarca, Colombia CANPACK A tiempo completo

    We are seeking a Global IT Security Specialist who will play a crucial role in maintaining the security of our IT systems at GGH. Your main responsibility will be to ensure that IT Security is continuously upheld throughout our environment. - In addition, you will actively participate in analyzing requirements and implementing new security products to...


  • Bogotá, Colombia Mastercard A tiempo completo

    **Our Purpose** - Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation,...


  • Bogotá, Colombia B. Braun Melsungen AG A tiempo completo

    Role Summary As part of the Information Security Office, you will lead the design, implementation, and optimization of security tools and architectures across the organization. Your focus will be on building scalable, secure, and resilient solutions that support our Zero Trust strategy and broader cybersecurity goals. You will work closely with global IT and...


  • Bogotá, Colombia Emmes Global A tiempo completo

    Overview: **Information Security Analyst** **LATAM Remote** Emmes Group: Building a better future for us all. Emmes Group is transforming the future of clinical research, bringing the promise of new medical discovery closer within reach for patients. Emmes Group was founded as Emmes more than 47 years ago, becoming one of the primary clinical research...

  • Security Compliance

    hace 2 días


    Bogotá, Colombia OpsArmy A tiempo completo

    **Position Type**: Full-Time **Location**: Remote **About the Role**: Were looking for a **Security Compliance & Sales Enablement Specialist** to help bridge the gap between our Security, Sales, and Client teams. You'll own client-facing security documentation, manage security questionnaires, and support RFP/RFI submissions ensuring our security posture...


  • Bogotá, Cundinamarca, Colombia Rainforest Alliance A tiempo completo

    The Opportunity: We are seeking an experienced and highly motivated Information Security Analyst to join our security team. This role will be critical in protecting our digital assets, detecting and responding to security incidents, and ensuring the continuous improvement of our security posture. You will work proactively to identify security risks,...


  • Bogotá, Colombia Addi A tiempo completo

    A leading fintech company in Colombia seeks an experienced security leader to own the execution of operational security. You will manage the Application Security and Security Operations teams, implementing key frameworks to protect applications and customer data. The ideal candidate will have over 4 years of experience in security engineering, a deep...


  • Bogotá, Colombia Hostaway A tiempo completo

    Hostaway is the market-leading SaaS scale-up transforming the vacation rental industry. With innovative solutions and partnerships with giants like Airbnb, VRBO, and Booking, we're taking on the competition and winning. Leveraging our customer-centric core values, we consistently deliver results that encourage growth, learning, and innovation for our team,...


  • Bogotá, Colombia Scotiabank A tiempo completo

    **Requisition ID**: 223102 **Employee Referral Program - Potential Reward**: $400,000.00 We are committed to investing in our employees and helping you continue your career at ScotiaTech. **Position: Engineer, Security Platform Engineering, Orchestration and Logistics**: **_Purpose_** Engineer in Security Platform Engineering, Orchestration and Logistics...