Security Delivery Analyst

Hybrid in Pozuelo de Alarcón·Full-time·Added yesterday

Excelia

73 open roles

Overview

Job details

  • Permanent contract

    Full-time hours.

  • Hybrid

    Office and home days — the ad has the split.

Requirements

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Be near Pozuelo de Alarcón, Spain (Hybrid) for hybrid days

    No relocation package mentioned.

You'll most likely need Spanish to apply.This job was automatically translated to English,.

The role

Excelia is a multinational Consulting, Technology, and Professional Services firm with over 25 years of experience. We operate in more than 50 countries across Europe, Latin America, and the United States, participating in high-impact projects and international technological environments.

What you'll do

  • Manage the complete vulnerability lifecycle of applications.

  • Analyze and validate vulnerabilities identified by different security tools.

  • Identify and manage false positives.

  • Perform triage and prioritization of vulnerabilities based on their criticality.

  • Apply criteria such as CVSS and EPSS to determine priorities.

  • Follow up on vulnerabilities until their remediation and closure.

  • Analyze results from SAST, SCA, DAST, and IAST tools.

  • Review code to validate and contextualize security findings.

  • Collaborate with Development and Operations teams to define and monitor remediation plans.

  • Participate in the integration of security controls within CI/CD pipelines.

  • Contribute to the evolution of DevSecOps and SSDLC processes and methodologies.

  • Identify opportunities for improvement and automation within the vulnerability management process.

  • Communicate security risks clearly to technical teams and different stakeholders.

  • Work with teams to prioritize vulnerability remediation while maintaining a balance between security, risk, and business needs.

💻 Technical knowledge

How you'll work

📍 Location: Madrid - Las Tablas
🏠 Hybrid model: 1-2 days on-site per week

What are we looking for?

📢 We are looking for a Security Delivery Analyst / Security Transformation Analyst to join our team!

🛠️ Main responsibilities

🔹 What are we looking for?

🛠️ Main responsibilities

Job description

We are looking for professionals in Cybersecurity and AppSec to participate in projects related to Security Delivery, Application Security, and transformation towards DevSecOps models.

The position will be especially focused on comprehensive vulnerability management, from identification and validation to prioritization, monitoring, and remediation, working in a coordinated manner with development and operations teams.

We are looking for both Junior and Senior profiles, adapting the level of responsibility to experience.

Vulnerability Management

  • Knowledge of the complete vulnerability management cycle:
    identification → validation → triage → prioritization → remediation → monitoring and closure.

  • Knowledge of CVSS and EPSS.

  • Ability to analyze false positives and validate the criticality of findings.

Application Security / AppSec

  • SAST: Checkmarx, Fortify, SonarQube, Veracode.

  • SCA: Snyk, Black Duck, Mend / WhiteSource.

  • DAST / IAST: Burp Suite, OWASP ZAP, or other similar tools.

  • Knowledge of SSDLC (Secure Software Development Life Cycle).

Programming

  • Ability to read and understand code with the aim of validating vulnerabilities and security findings.

  • Experience with the following will be valued:

    • Python

    • JavaScript / TypeScript

    • Java

    • C#

CI/CD and DevSecOps

  • Knowledge of pipelines and continuous integration and deployment processes.

  • Jenkins

  • GitLab CI

  • GitHub Actions

  • Azure DevOps

  • Integration and automation of security controls within the development cycle.

🔐 Cybersecurity Fundamentals

  • Solid knowledge of OWASP Top 10.

  • Knowledge of CWE (Common Weakness Enumeration).

  • Principles and best practices of secure architectures.

  • Knowledge of Application Security and Secure by Design.

📌 Required experience

Junior Profile

  • Between 1 and 2 years of experience in Cybersecurity, software development, AppSec, or technical auditing.

  • Exposure to Agile environments and methodologies.

  • Knowledge of vulnerability management and application security fundamentals.

  • Interest in developing within DevSecOps / SSDLC environments.

Senior Profile

  • More than 3-4 years of experience in Cybersecurity, AppSec, or related areas.

  • Experience leading Application Security initiatives.

  • Experience managing complete vulnerability cycles.

  • Experience defining or improving DevSecOps / SSDLC processes.

  • Ability to coordinate with Development, Operations, and Security teams.

🤝 Soft Skills

  • Good communication and negotiation skills with technical teams.

  • Ability to explain vulnerabilities and risks clearly.

  • Orientation toward collaboration with Development and Operations teams.

  • Ability to advocate for the need for remediation without unnecessarily blocking the business.

  • Orientation toward continuous improvement and the automation of security processes.

Pay & benefits

What you'll get

📝 Permanent contract and professional stability.

🌍 Participation in Cybersecurity and technological transformation projects in international environments.

🚀 Projects related to Application Security, DevSecOps, SSDLC, and vulnerability management.

📚 Continuous training and professional development opportunities.

🤝 Collaborative, international, and innovation-oriented work environment.

💰 Competitive compensation according to experience and knowledge.

If you have experience in Cybersecurity, AppSec, or secure development, knowledge of vulnerability management, and you are interested in working on DevSecOps and SSDLC projects, we want to meet you!

About Excelia

Excelia is a Canadian IT services and consulting company headquartered in Montreal, specializing in cybersecurity, cloud solutions, data analytics, and enterprise software implementation. The company operates across multiple countries, offering services such as managed IT support, security consulting, and implementation of platforms like Microsoft Dynamics 365 and Azure. With a workforce of several hundred employees, Excelia serves clients in various industries, focusing on digital transformation and IT security.

In Spain, Excelia has established a significant presence with offices in Madrid, Barcelona, and Bilbao, and is actively hiring for over 50 roles in cybersecurity, cloud architecture, software development, and data engineering. The company's work culture emphasizes technical expertise and professional growth, making it an attractive option for international professionals with skills in Microsoft technologies, cybersecurity, and data. Excelia offers opportunities for both junior and senior roles, including internships, and supports relocation for qualified candidates.

Founded
1998
Employees
500–1,000
Headquarters
Toronto, Canada
In Spain
Madrid, Barcelona, Bilbao

Good to know if you are moving

  • Excelia has offices in Madrid, Barcelona, and Bilbao, offering multiple locations for international hires in Spain.
  • The company is actively hiring for over 50 roles in Spain, including junior and senior positions, indicating a strong demand for tech talent.
  • Excelia provides opportunities for internships and junior roles, which can be a good entry point for international professionals starting their careers in Spain.
  • The company works with major technologies like Microsoft Dynamics 365, Azure, AWS, and cybersecurity tools, which are valuable skills for the Spanish tech market.
  • Excelia's global presence may offer opportunities for cross-border projects and career mobility.
All open roles at Excelia
WhatsApp