Vulnerability Management Engineer

Vulnerability Management Engineer

Initium Software
Initium Software
València, SpainCompetitiveOn-siteAdded 1 month agoSenior · 5+ years🇬🇧English: Required

Need a visa? No sponsorship mentioned here. Browse visa jobs.

About the role

Are you the Guardian of Security who will protect the future of elite software?

Location: Valencia (On-site) Schedule: 09:00 - 18:00

We are not looking for someone who just runs automated reports; we are looking for an engineer with deep technical curiosity ready to take control of the security posture of our web, mobile, and cloud applications. At Initium Software, your mission will be to identify, manage, and remediate vulnerabilities throughout the entire software development lifecycle, working side by side with high-performance teams.

What you'll do

Your Challenges and Responsibilities

  • Lead Security Assessments: Execute and support vulnerability analyses in applications using SAST, DAST, SCA, and manual code reviews.

  • Critical Analysis: Validate scan results, perform false positive analysis, and rigorously track until effective remediation is confirmed through retesting.

  • Strategic Prioritization: Classify vulnerabilities based on business impact, criticality, and likelihood of exploitation, using standard methodologies such as CVSS.

  • Automation and Integration: Drive the integration of security workflows and scans directly into CI/CD pipelines.

  • Metrics and Indicators Management: Develop and maintain dashboards to measure severity distribution, SLA compliance, and mean time to remediation (MTTR).

  • Incident Response: Actively participate in responding to high-severity or zero-day vulnerabilities, coordinating mitigation plans.

What we're looking for

  • Experience: More than 5 years of solid track record in application security and/or vulnerability management.

  • Education: Professional graduated in Systems Engineering, Cybersecurity, Computer Science, or equivalent experience.

  • Technical Mastery: Deep understanding of common vulnerability classes (such as the OWASP Top 10) and secure architecture principles.

  • Manual Testing: High proficiency in using Burp Suite for manual security testing on web applications and APIs (validation of business logic, authentication, and complex authorization).

  • Industry Tools: Hands-on experience with platforms such as Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and network discovery tools like Nmap.

  • Frameworks: Familiarity with NIST standards, MITRE ATT&CK, and CIS benchmarks.

  • Code/Scripting: Ability to program or automate in languages such as Python, Java, or .NET.

  • Languages: Advanced English level (C1), capable of interacting with global teams and environments.

  • Soft Skills: Excellent documentation, communication, and stakeholder management skills.

Nice to have

We especially value if you also have (Desirable):

  • Professional industry certifications (such as Security+, SSCP, GWAPT, or being on the path toward CISSP or OSCP).

  • Experience using the ServiceNow platform for tracking vulnerabilities or incidents.

  • Experience in Azure cloud environments and Azure DevOps ecosystems.

  • Skill in using Power BI for visualizing security metrics for technical and executive audiences.

  • You are passionate about learning, sharing ideas, and evolving together with the team.

What you'll get

What do we offer you?

  • Compensation: Competitive fixed salary commensurate with your elite experience.

  • Work mode: Stable schedule from 09:00 to 18:00 at the office of one of our clients in Valencia.

  • Challenging Projects: You will work with cutting-edge technologies, protecting complex ecosystems and completely avoiding monotony.

  • Initium Culture: An environment based on autonomy, collaboration, and dynamism. A space where your initiative is valued, your impact is recognized, and your growth and constant mentorship are firmly supported.

"At Initium we do not just develop technology: we create an environment where people can evolve, add value, and leave their mark."

Are you ready for the challenge? If you are looking for a place where your knowledge has a real impact and your curiosity is the driving force to protect critical systems, let's talk about the future you can build with us.

Apply now and let's talk

How you'll work

full-time

How will we measure your impact?

  • Monthly compliance with efficiency and mitigation objectives in assigned projects.

  • Alignment and effective execution of the company's application security strategic plan.

This job was automatically translated to English, .

Apply at Initium Software