Security Delivery Analyst
Hybrid in Pozuelo de Alarcón·Full-time·Added yesterday
Overview
Job details
Permanent contract
Full-time hours.
Hybrid
Office and home days — the ad has the split.
Requirements
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Be near Pozuelo de Alarcón, Spain (Hybrid) for hybrid days
No relocation package mentioned.
You'll most likely need Spanish to apply.This job was automatically translated to English,.
The role
Excelia is a multinational Consulting, Technology, and Professional Services firm with over 25 years of experience. We operate in more than 50 countries across Europe, Latin America, and the United States, participating in high-impact projects and international technological environments.
What you'll do
Manage the complete vulnerability lifecycle of applications.
Analyze and validate vulnerabilities identified by different security tools.
Identify and manage false positives.
Perform triage and prioritization of vulnerabilities based on their criticality.
Apply criteria such as CVSS and EPSS to determine priorities.
Follow up on vulnerabilities until their remediation and closure.
Analyze results from SAST, SCA, DAST, and IAST tools.
Review code to validate and contextualize security findings.
Collaborate with Development and Operations teams to define and monitor remediation plans.
Participate in the integration of security controls within CI/CD pipelines.
Contribute to the evolution of DevSecOps and SSDLC processes and methodologies.
Identify opportunities for improvement and automation within the vulnerability management process.
Communicate security risks clearly to technical teams and different stakeholders.
Work with teams to prioritize vulnerability remediation while maintaining a balance between security, risk, and business needs.
💻 Technical knowledge
How you'll work
📍 Location: Madrid - Las Tablas
🏠 Hybrid model: 1-2 days on-site per week
What are we looking for?
📢 We are looking for a Security Delivery Analyst / Security Transformation Analyst to join our team!
🛠️ Main responsibilities
🔹 What are we looking for?
🛠️ Main responsibilities
Job description
We are looking for professionals in Cybersecurity and AppSec to participate in projects related to Security Delivery, Application Security, and transformation towards DevSecOps models.
The position will be especially focused on comprehensive vulnerability management, from identification and validation to prioritization, monitoring, and remediation, working in a coordinated manner with development and operations teams.
We are looking for both Junior and Senior profiles, adapting the level of responsibility to experience.
Vulnerability Management
Knowledge of the complete vulnerability management cycle:
identification → validation → triage → prioritization → remediation → monitoring and closure.Knowledge of CVSS and EPSS.
Ability to analyze false positives and validate the criticality of findings.
Application Security / AppSec
SAST: Checkmarx, Fortify, SonarQube, Veracode.
SCA: Snyk, Black Duck, Mend / WhiteSource.
DAST / IAST: Burp Suite, OWASP ZAP, or other similar tools.
Knowledge of SSDLC (Secure Software Development Life Cycle).
Programming
Ability to read and understand code with the aim of validating vulnerabilities and security findings.
Experience with the following will be valued:
Python
JavaScript / TypeScript
Java
C#
CI/CD and DevSecOps
Knowledge of pipelines and continuous integration and deployment processes.
Jenkins
GitLab CI
GitHub Actions
Azure DevOps
Integration and automation of security controls within the development cycle.
🔐 Cybersecurity Fundamentals
Solid knowledge of OWASP Top 10.
Knowledge of CWE (Common Weakness Enumeration).
Principles and best practices of secure architectures.
Knowledge of Application Security and Secure by Design.
📌 Required experience
Junior Profile
Between 1 and 2 years of experience in Cybersecurity, software development, AppSec, or technical auditing.
Exposure to Agile environments and methodologies.
Knowledge of vulnerability management and application security fundamentals.
Interest in developing within DevSecOps / SSDLC environments.
Senior Profile
More than 3-4 years of experience in Cybersecurity, AppSec, or related areas.
Experience leading Application Security initiatives.
Experience managing complete vulnerability cycles.
Experience defining or improving DevSecOps / SSDLC processes.
Ability to coordinate with Development, Operations, and Security teams.
🤝 Soft Skills
Good communication and negotiation skills with technical teams.
Ability to explain vulnerabilities and risks clearly.
Orientation toward collaboration with Development and Operations teams.
Ability to advocate for the need for remediation without unnecessarily blocking the business.
Orientation toward continuous improvement and the automation of security processes.
Pay & benefits
What you'll get
📝 Permanent contract and professional stability.
🌍 Participation in Cybersecurity and technological transformation projects in international environments.
🚀 Projects related to Application Security, DevSecOps, SSDLC, and vulnerability management.
📚 Continuous training and professional development opportunities.
🤝 Collaborative, international, and innovation-oriented work environment.
💰 Competitive compensation according to experience and knowledge.
If you have experience in Cybersecurity, AppSec, or secure development, knowledge of vulnerability management, and you are interested in working on DevSecOps and SSDLC projects, we want to meet you!
The role
Excelia es una firma multinacional de Consultoría, Tecnología y Servicios Profesionales con más de 25 años de experiencia. Operamos en más de 50 países de Europa, América Latina y Estados Unidos, participando en proyectos de alto impacto y entornos tecnológicos internacionales.
What you'll do
Gestionar el ciclo de vida completo de vulnerabilidades de aplicaciones.
Analizar y validar vulnerabilidades identificadas por diferentes herramientas de seguridad.
Identificar y gestionar falsos positivos.
Realizar el triaje y priorización de vulnerabilidades en función de su criticidad.
Aplicar criterios como CVSS y EPSS para determinar prioridades.
Realizar seguimiento de las vulnerabilidades hasta su remediación y cierre.
Analizar resultados procedentes de herramientas SAST, SCA, DAST e IAST.
Revisar código para validar y contextualizar los hallazgos de seguridad.
Colaborar con equipos de Desarrollo y Operaciones para definir y hacer seguimiento de planes de remediación.
Participar en la integración de controles de seguridad dentro de pipelines CI/CD.
Contribuir a la evolución de procesos y metodologías de DevSecOps y SSDLC.
Identificar oportunidades de mejora y automatización dentro del proceso de gestión de vulnerabilidades.
Comunicar riesgos de seguridad de forma clara a equipos técnicos y diferentes stakeholders.
Trabajar con los equipos para priorizar la remediación de vulnerabilidades manteniendo el equilibrio entre seguridad, riesgo y necesidades de negocio.
How you'll work
📍 Ubicación: Madrid - Las Tablas
🏠 Modelo híbrido: 1-2 días presenciales a la semana
¿Qué buscamos?
📢 ¡Estamos buscando un/a Security Delivery Analyst / Security Transformation Analyst para unirse a nuestro equipo!
🛠️ Responsabilidades principales
🔹 ¿Qué buscamos?
🛠️ Responsabilidades principales
Descripción del puesto
Buscamos profesionales de Ciberseguridad y AppSec para participar en proyectos relacionados con Security Delivery, Application Security y transformación hacia modelos DevSecOps.
La posición estará especialmente enfocada en la gestión integral de vulnerabilidades, desde su identificación y validación hasta la priorización, seguimiento y remediación, trabajando de forma coordinada con equipos de desarrollo y operaciones.
Buscamos perfiles tanto Junior como Senior, adaptando el nivel de responsabilidad a la experiencia.
Gestión de Vulnerabilidades
Conocimiento del ciclo completo de gestión de vulnerabilidades:
identificación → validación → triaje → priorización → remediación → seguimiento y cierre.Conocimientos de CVSS y EPSS.
Capacidad para analizar falsos positivos y validar la criticidad de los hallazgos.
Application Security / AppSec
SAST: Checkmarx, Fortify, SonarQube, Veracode.
SCA: Snyk, Black Duck, Mend / WhiteSource.
DAST / IAST: Burp Suite, OWASP ZAP u otras herramientas similares.
Conocimientos de SSDLC (Secure Software Development Life Cycle).
Programación
Capacidad para leer y comprender código con el objetivo de validar vulnerabilidades y hallazgos de seguridad.
Se valorará experiencia con:
Python
JavaScript / TypeScript
Java
C#
CI/CD y DevSecOps
Conocimientos de pipelines y procesos de integración y despliegue continuo.
Jenkins
GitLab CI
GitHub Actions
Azure DevOps
Integración y automatización de controles de seguridad dentro del ciclo de desarrollo.
Conocimiento sólido de OWASP Top 10.
Conocimientos de CWE (Common Weakness Enumeration).
Principios y buenas prácticas de arquitecturas seguras.
Conocimientos de Application Security y Secure by Design.
Perfil Junior
Entre 1 y 2 años de experiencia en Ciberseguridad, desarrollo de software, AppSec o auditoría técnica.
Exposición a entornos y metodologías Agile.
Conocimientos de gestión de vulnerabilidades y fundamentos de seguridad de aplicaciones.
Interés por desarrollarse en entornos DevSecOps / SSDLC.
Perfil Senior
Más de 3-4 años de experiencia en Ciberseguridad, AppSec o áreas relacionadas.
Experiencia liderando iniciativas de Application Security.
Experiencia gestionando ciclos completos de vulnerabilidades.
Experiencia definiendo o mejorando procesos de DevSecOps / SSDLC.
Capacidad para coordinarse con equipos de Desarrollo, Operaciones y Seguridad.
Buena capacidad de comunicación y negociación con equipos técnicos.
Capacidad para explicar vulnerabilidades y riesgos de forma clara.
Orientación a la colaboración con equipos de Desarrollo y Operaciones.
Capacidad para defender la necesidad de remediación sin bloquear innecesariamente el negocio.
Orientación a la mejora continua y a la automatización de procesos de seguridad.
Pay & benefits
What you'll get
📝 Contrato indefinido y estabilidad profesional.
🌍 Participación en proyectos de Ciberseguridad y transformación tecnológica en entornos internacionales.
🚀 Proyectos relacionados con Application Security, DevSecOps, SSDLC y gestión de vulnerabilidades.
📚 Formación continua y oportunidades de desarrollo profesional.
🤝 Entorno de trabajo colaborativo, internacional y orientado a la innovación.
💰 Retribución competitiva acorde a experiencia y conocimientos.
Si tienes experiencia en Ciberseguridad, AppSec o desarrollo seguro, conocimientos de gestión de vulnerabilidades y te interesa trabajar en proyectos de DevSecOps y SSDLC, ¡queremos conocerte!
About Excelia
Excelia is a Canadian IT services and consulting company headquartered in Montreal, specializing in cybersecurity, cloud solutions, data analytics, and enterprise software implementation. The company operates across multiple countries, offering services such as managed IT support, security consulting, and implementation of platforms like Microsoft Dynamics 365 and Azure. With a workforce of several hundred employees, Excelia serves clients in various industries, focusing on digital transformation and IT security.
In Spain, Excelia has established a significant presence with offices in Madrid, Barcelona, and Bilbao, and is actively hiring for over 50 roles in cybersecurity, cloud architecture, software development, and data engineering. The company's work culture emphasizes technical expertise and professional growth, making it an attractive option for international professionals with skills in Microsoft technologies, cybersecurity, and data. Excelia offers opportunities for both junior and senior roles, including internships, and supports relocation for qualified candidates.
- Founded
- 1998
- Employees
- 500–1,000
- Headquarters
- Toronto, Canada
- In Spain
- Madrid, Barcelona, Bilbao
- Website
- excelia.com
Good to know if you are moving
- Excelia has offices in Madrid, Barcelona, and Bilbao, offering multiple locations for international hires in Spain.
- The company is actively hiring for over 50 roles in Spain, including junior and senior positions, indicating a strong demand for tech talent.
- Excelia provides opportunities for internships and junior roles, which can be a good entry point for international professionals starting their careers in Spain.
- The company works with major technologies like Microsoft Dynamics 365, Azure, AWS, and cybersecurity tools, which are valuable skills for the Spanish tech market.
- Excelia's global presence may offer opportunities for cross-border projects and career mobility.
More jobs like this
or browse Mid-level·Hybrid·Cybersecurity·Python·Java·JavaScript·TypeScript



