Vulnerability Management Engineer – Application Security | Valencia
Location: Valencia, Spain
Work model: On-site Valencia
Experience: 5–7 years in Application Security and/or Vulnerability Management
⏱️ Position: Full-time
Contract: B2B / Freelance
Languages: English & Spanish
Summary:
We’re looking for a Vulnerability Management Engineer – Application Security to identify, assess, prioritize, and support the remediation of application vulnerabilities throughout the software development lifecycle. You’ll work across web, mobile, and cloud-based applications , leveraging vulnerability scanning, manual security testing, automation, and risk-based prioritization to strengthen the organization’s security posture.
Key Responsibilities:
Execute and support application vulnerability assessments using SAST, DAST, SCA, and manual security testing .
Validate scanner findings, perform false-positive analysis , and track vulnerabilities through remediation and retesting.
Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood , using frameworks such as CVSS.
Manage multiple application security initiatives while meeting remediation timelines and SLAs.
Develop dashboards and reports covering vulnerability severity, remediation SLAs, and MTTR .
Support the integration of security scanning and vulnerability management workflows into CI/CD pipelines .
Provide actionable remediation recommendations and coordinate root cause analysis with development teams.
Support threat modeling and application risk assessments , identifying insecure design patterns.
Participate in high-severity and zero-day vulnerability response activities.
Contribute to application and cloud security policies, standards, and security controls.
Required Technical Skills:
Application Security & Vulnerability Management
Strong understanding of OWASP Top 10 , common vulnerability classes, secure architecture, and application security principles.
Hands-on experience with SAST, DAST, SCA , vulnerability assessment, and remediation processes.
Experience prioritizing vulnerabilities using CVSS and risk-based methodologies.
Security Testing & Tools
Strong hands-on experience with Burp Suite for web application and API security testing.
Experience with tools such as Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and Nmap .
Ability to identify complex authentication, authorization, and business-logic vulnerabilities .
Automation, Cloud & Security Frameworks
Programming/scripting experience with Python, Java, .NET, or similar technologies .
Experience integrating security tools into CI/CD pipelines .
Familiarity with NIST, MITRE ATT&CK;, and CIS Benchmarks .
Experience with Azure and Azure DevOps is a plus.
Experience with ServiceNow and vulnerability tracking is desirable.
Knowledge of Power BI or similar tools for vulnerability metrics and reporting is a plus.
If you're passionate about Application Security, vulnerability management, and building secure software environments , we'd love to hear from you.
Send your CV in English to
[email protected] with reference “MA/Vuln” or just apply to this opportunity.
#VulnerabilityManagement #ApplicationSecurity #CyberSecurity #AppSec #OWASP #BurpSuite #SAST #DAST #DevSecOps #Hiring
📌 Vulnerability Management Engineer – Application Security (Valencia)
🏢 Optiwisers
📍 Valencia