Faster chat, better deals — Get the App

JUNIOR AUTOMATION SPECIALIST

Indeed

Company

Job typeFull-time
Workplace typeOnsite
Experience levelNo experience limit
Education levelNo degree limit

Description

Job Summary: This position seeks an Application Security Specialist to ensure the implementation and continuous improvement of security controls within the DevSecOps model. Key Highlights: 1. Drives transformation and innovation in the financial sector. 2. Exciting challenges in application and cloud environment security. 3. Collaborates with development teams to promote DevSecOps. **Location:** MEXICO CITY, Ciudad de México, MX **Category:** Digital Business Development **Requisition ID:** 121824 **Application Security Specialist** **(Tlalpan, CDMX)** At Banorte, we seek unique, strong, and extraordinary talent that drives the transformation and innovation of our country, positioning us as a powerful ally for robust growth alongside Mexico. We firmly believe that the combination of solidarity, innovation, respect, loyalty, and responsibility is the perfect formula to become the best team in the financial sector. **Job Objective:** Ensure the implementation and continuous improvement of security controls throughout the development and deployment of applications under the DevSecOps model, including conducting penetration tests (Pentesting) to identify vulnerabilities in critical applications and services. Coordinate and verify compliance with the vulnerability management process across the Financial Group’s applications and systems, identifying information security risks associated with vulnerability assessments. Each day, you will face **new and exciting challenges** in your role, where you will be responsible for: * CI/CD Pipeline Security: * Integrate security scanning tools into GitLab pipelines to detect code vulnerabilities, insecure dependencies, and misconfigurations. * Implement automated security policy validations at CI/CD stages. * Dynamic Application Security Testing (DAST) and Pentesting for Applications * Configure DAST engine rules in CI/CD pipelines and complement them with advanced controlled exploitation techniques. * Execute manual and automated penetration tests on web, mobile, and API applications to identify vulnerabilities beyond the scope of DAST/SAST tools. * Document findings, assess impact, and coordinate remediation with development teams. * Cloud Security: * Monitor and manage vulnerabilities in cloud environments (AWS, Azure, GCP), including penetration testing of critical configurations and exposed services. * API Security: * Manage API security tools, including configuration of protection policies, traffic monitoring, and anomaly detection. * Analyze risks associated with endpoint exposure and ensure compliance with authentication and authorization standards. * Collaboration and Training: * Work jointly with development and operations teams to foster a DevSecOps culture. * Provide guidance on security best practices for containers and CI/CD. * Compliance and Reporting: * Ensure compliance with applicable security regulations and standards (e.g., ISO 27001, NIST, PCI\-DSS). * Generate detailed penetration test reports and security status reports for pipelines, containers, and cloud environments **Requirements:** * Professional Education: Bachelor’s degree or engineering degree in Information Systems, Information Security, or related fields * Years of Experience: 3 years * Areas of Experience + Experience configuring and managing pipelines in GitLab or GitHub. + Practical experience with Docker and Kubernetes. + Practical experience in Pentesting (OWASP Testing Guide, OSSTMM methodologies). + Knowledge of CI/CD security tools (e.g., SonarQube, Checkmarx, HCL AppScan, Snyk). + Knowledge of platforms such as Prisma Cloud or Sysdig Secure. + Experience in risk analysis and security configuration monitoring in native cloud environments (AWS, Azure, GCP). + Familiarity with standards such as OWASP, CIS Benchmarks, and DevSecOps + Proficiency with Infrastructure-as-Code tools (e.g., Terraform or Ansible) * Required Knowledge + Application, container, and CI/CD security + Use of ticketing tools + Dashboard and/or operational reporting generation + Agile mindset * Languages: English (preferred, not mandatory) * Willingness to travel: NA * Willingness to relocate: NA At Banorte, we operate under a principle of equal opportunity. Therefore, we do not discriminate based on age, ethnicity, nationality, gender, sexual orientation, marital status, social condition, health status, religious beliefs, political doctrine, or disability.

Some content was automatically translated

Posted by

Juan García

Indeed · HR

Location

Juan García

Indeed · HR

Similar jobs

JUNIOR AUTOMATION SPECIALIST job by Indeed in 2026 | ok.com