Ofertas de empleo Vulnerability Management Engineer | Hybrid in Valencia, Spain

Acerca del puesto Vulnerability Management Engineer | Hybrid in Valencia, Spain

Vulnerability Management Engineer – Application Security

At Vortech PCI Group, we are looking for a Vulnerability Management Engineer with a strong focus on Application Security to join an international technology environment based in Valencia, Spain.

What will you do?

You will work on identifying, validating, prioritizing and tracking application vulnerabilities across web, mobile and cloud-based environments. You will collaborate closely with development, security and technical teams to improve the security posture throughout the software development lifecycle.

Main responsibilities:

  • Perform and support application security assessments using SAST, DAST, SCA and manual testing.
  • Validate scanner results, analyze false positives and ensure findings are technically accurate.
  • Use Burp Suite for manual testing of web applications and APIs.
  • Prioritize vulnerabilities based on severity, exploitability, exposure and business impact.
  • Coordinate remediation plans with development and security teams.
  • Track vulnerability metrics, remediation SLAs and MTTR.
  • Support the integration of security testing into CI/CD pipelines.
  • Participate in the response to high-severity vulnerabilities or zero-day situations when required.

What are we looking for?

  • 5+ years of experience in Application Security, Vulnerability Management or similar cybersecurity roles.
  • Strong knowledge of OWASP Top 10 and common vulnerabilities in web applications and APIs.
  • Hands-on experience with Burp Suite.
  • Experience with SAST, DAST or SCA tools such as Fortify, Checkmarx, SonarQube, Black Duck, Tenable or similar.
  • Programming or scripting knowledge in Python, Java, .NET or similar.
  • Ability to communicate technical risks clearly to different stakeholders.
  • Advanced English level, C1 or equivalent.
  • Spanish fluency.

Nice to have:

  • Experience with Azure or Azure DevOps.
  • Experience with ServiceNow for vulnerability or incident tracking.
  • Knowledge of NIST, MITRE ATT&CK or CIS Benchmarks.
  • Experience with Power BI or similar reporting tools.
  • Cybersecurity certifications such as Security+, SSCP, GWAPT, CISSP or OSCP.

Location and modality:

  • Based in Valencia, Spain.
  • Hybrid work model.