Vulnerability Management Engineer – Application Security | Valencia
Location: Valencia, Spain Work model: On-site Valencia Experience: 5–7 years in Application Security and/or Vulnerability Management ⏱️ Position: Full-time Contract: B2B / Freelance Languages: English & Spanish
Summary: We’re looking for a
Vulnerability Management Engineer – Application Security
to identify, assess, prioritize, and support the remediation of application vulnerabilities throughout the software development lifecycle. You’ll work across
web, mobile, and cloud-based applications , leveraging vulnerability scanning, manual security testing, automation, and risk-based prioritization to strengthen the organization’s security posture.
Key Responsibilities: Execute and support application vulnerability assessments using
SAST, DAST, SCA, and manual security testing . Validate scanner findings, perform
false-positive analysis , and track vulnerabilities through remediation and retesting. Prioritize vulnerabilities based on
business impact, exploitability, exposure, and likelihood , using frameworks such as CVSS. Manage multiple application security initiatives while meeting remediation timelines and SLAs. Develop dashboards and reports covering
vulnerability severity, remediation SLAs, and MTTR . Support the integration of security scanning and vulnerability management workflows into
CI/CD pipelines . Provide actionable remediation recommendations and coordinate
root cause analysis
with development teams. Support
threat modeling and application risk assessments , identifying insecure design patterns. Participate in
high-severity and zero-day vulnerability response
activities.
Contribute to application and cloud security policies, standards, and security controls.
Required Technical Skills: Application Security & Vulnerability Management Strong understanding of
OWASP Top 10 , common vulnerability classes, secure architecture, and application security principles. Hands-on experience with
SAST, DAST, SCA , vulnerability assessment, and remediation processes. Experience prioritizing vulnerabilities using
CVSS
and risk-based methodologies. Security Testing & Tools Strong hands-on experience with
Burp Suite
for web application and API security testing. Experience with tools such as
Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and Nmap . Ability to identify complex
authentication, authorization, and business-logic vulnerabilities . Automation, Cloud & Security Frameworks Programming/scripting experience with
Python, Java, .NET, or similar technologies . Experience integrating security tools into
CI/CD pipelines . Familiarity with
NIST, MITRE ATT&CK;, and CIS Benchmarks . Experience with
Azure and Azure DevOps
is a plus. Experience with
ServiceNow
and vulnerability tracking is desirable. Knowledge of
Power BI
or similar tools for vulnerability metrics and reporting is a plus.
If you're passionate about
Application Security, vulnerability management, and building secure software environments , we'd love to hear from you.
Send your CV in English to
[email protected]
with reference
“MA/Vuln”
or just apply to this opportunity.
#VulnerabilityManagement #ApplicationSecurity #CyberSecurity #AppSec #OWASP #BurpSuite #SAST #DAST #DevSecOps #Hiring
📌 Vulnerability Management Engineer – Application Security (Marzán)
🏢 Optiwisers
📍 Marzán