15 ago
|
Optiwisers
|
Almería
15 ago
Optiwisers
Almería
? Vulnerability Management Engineer – Application Security | Valencia
? Location: Valencia, Spain
? Work model: On-site Valencia
? Experience: 5–7 years in Application Security and/or Vulnerability Management
⏱️ Position: Full-time
? Contract: B2B / Freelance
? Languages: English & Spanish
Summary:
We’re looking for a Vulnerability Management Engineer – Application Security to identify, assess, prioritize, and support the remediation of application vulnerabilities throughout the software development lifecycle. You’ll work across web, mobile, and cloud-based applications, leveraging vulnerability scanning, manual security testing, automation, and risk-based prioritization to strengthen the organization’s security posture.
Key Responsibilities:
- Execute and support application vulnerability assessments using SAST, DAST, SCA, and manual security testing.
- Validate scanner findings, perform false-positive analysis, and track vulnerabilities through remediation and retesting.
- Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using frameworks such as CVSS.
- Manage multiple application security initiatives while meeting remediation timelines and SLAs.
- Develop dashboards and reports covering vulnerability severity, remediation SLAs, and MTTR.
- Support the integration of security scanning and vulnerability management workflows into CI/CD pipelines.
- Provide actionable remediation recommendations and coordinate root cause analysis with development teams.
- Support threat modeling and application risk assessments, identifying insecure design patterns.
- Participate in high-severity and zero-day vulnerability response activities.
- Contribute to application and cloud security policies, standards, and security controls.
Required Technical Skills:
Application Security & Vulnerability Management
- Strong understanding of OWASP Top 10, common vulnerability classes, secure architecture, and application security principles.
- Hands-on experience with SAST, DAST, SCA, vulnerability assessment, and remediation processes.
- Experience prioritizing vulnerabilities using CVSS and risk-based methodologies.
Security Testing & Tools
- Strong hands-on experience with Burp Suite for web application and API security testing.
- Experience with tools such as Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and Nmap.
- Ability to identify complex authentication, authorization, and business-logic vulnerabilities.
Automation, Cloud & Security Frameworks
- Programming/scripting experience with Python, Java, .NET, or similar technologies.
- Experience integrating security tools into CI/CD pipelines.
- Familiarity with NIST, MITRE ATT&CK;, and CIS Benchmarks.
- Experience with Azure and Azure DevOps is a plus.
- Experience with ServiceNow and vulnerability tracking is desirable.
- Knowledge of Power BI or similar tools for vulnerability metrics and reporting is a plus.
If you're passionate about Application Security, vulnerability management, and building secure software environments, we'd love to hear from you.
? Send your CV in English to with reference “MA/Vuln” or just apply to this opportunity.
#VulnerabilityManagement #ApplicationSecurity #CyberSecurity #AppSec #OWASP #BurpSuite #SAST #DAST #DevSecOps #Hiring
📌 Vulnerability Management Engineer – Application Security - Optiwisers (Almería)
🏢 Optiwisers
📍 Almería