The English-language job board for Spain

Vulnerability Management Expert

On-site in Barcelona·Full-time·Added 3 days ago

Pasiona

34 open roles

Overview

Job details

  • Permanent contract

    Full-time hours.

Requirements

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Work in English

    English is required, per the ad.

  • Work on-site in Barcelona

    No relocation package mentioned.

  • Have 3+ years of experience

    Mid-level role.

  • University degree

    “Formación en Ingeniería Informática, Telecomunicaciones, Ciberseguridad, Sistemas o similar.” — per the ad.

This job was automatically translated to English.

Pay & benefits

What you'll get

A day off for your birthday so you can celebrate it however you want!

Improved paid leave for a better personal and professional balance.

Access to private health insurance for your peace of mind.

Extra vacation days based on seniority, because we value your rest and well-being.

Requirements

What we're looking for

  • Minimum 3 years of experience in Vulnerability Management, Application Security, Software Security, DevSecOps, or similar positions.

  • Real experience working with SAST, DAST, and SCA tools.

  • Experience with tools such as SonarQube, Checkmarx, OWASP ZAP, and Dependabot.

  • Knowledge of dependency management in ecosystems such as npm, Maven, pip, NuGet, or Go modules.

  • Experience automating security processes within CI/CD pipelines.

  • Practical knowledge of Python and/or Bash for scripting and automation.

  • Experience with Git, GitHub, and Jira.

  • Knowledge of OWASP Top 10, CWE, and CVSS methodology.

  • Experience with Docker and/or OpenShift, especially from a security perspective.

  • Knowledge of DevSecOps practices and Secure Software Development Lifecycle.

  • The initial contract will run until March 7, 2027, with the possibility of joining the permanent staff. In addition, at Adecco

  • Autonomous, technical profile oriented toward continuous improvement.

  • Ability to work with Development, DevOps, Security teams, and different stakeholders.

Nice to have

  • Experience with vulnerability management platforms such as Tenable, Qualys, or Rapid7.

  • Knowledge of cloud security in AWS, Azure, or GCP.

  • Experience in container security and cloud-native architectures.

  • Experience in corporate environments and large-scale projects.

  • Knowledge of ISO 27001, NIST, GDPR, and SOC 2.

  • Certifications such as CISSP, OSCP, CEH, or CCSP.

  • Experience in advanced automation of security processes.

  • Knowledge of management and response to critical vulnerabilities and zero-days.

Education & certifications

Degree in Computer Engineering, Telecommunications, Cybersecurity, Systems, or similar.

We also value equivalent professional experience in application security, DevSecOps, or vulnerability management.

Languages

Spanish and working English

The role

Are you passionate about cybersecurity, vulnerability management, and the automation of security processes?

We are looking for a Vulnerability Management Expert to join the Mythos program, participating in the continuous improvement of the security of applications, dependencies, development pipelines, and deployment environments.

What you'll do

  • The selected person will work alongside Development, DevOps, and Security teams to identify, analyze, prioritize, and manage the remediation of vulnerabilities throughout the software lifecycle.

  • Monitor, analyze, classify, and prioritize vulnerabilities in third-party dependencies, libraries, and frameworks.

  • Analyze results from security tools SAST, DAST, and SCA such as SonarQube, Checkmarx, OWASP ZAP, and Dependabot.

  • Define and follow up on remediation plans according to criticality, risk, exploitability, and CVSS.

  • Implement and automate detection, update, and vulnerability remediation processes within CI/CD pipelines.

  • Work with dependency management systems in ecosystems such as npm, Maven, pip, NuGet, and Go modules.

  • Develop scripts and automations using Python and Bash.

  • Integrate security best practices into DevOps processes and container environments such as Docker and OpenShift.

  • Manage and document vulnerabilities, remediation actions, and compliance evidence using tools like Jira.

  • Define and apply secure coding standards, dependency management, and security best practices.

  • Prepare reports on the status of vulnerabilities, evolution of remediations, risks, and trends.

  • Collaborate in the response to critical vulnerabilities, high-severity CVEs, and zero-days.

  • Work with development teams to integrate security practices within the software lifecycle.

  • Contribute to compliance with standards and regulations such as ISO 27001, NIST, GDPR, and SOC 2.

  • Help to continuously improve and automate Vulnerability Management and DevSecOps processes.

Location

Barcelona

About Pasiona

Pasiona is a technology consulting firm specializing in cybersecurity, cloud infrastructure, and digital transformation. The company operates as a strategic partner for enterprises, offering services that range from vulnerability management and penetration testing to AI-driven platform engineering and data integration. With a global footprint, Pasiona combines deep technical expertise with a strong focus on innovation, helping organizations modernize their IT environments and secure their digital assets.

In Spain, Pasiona has established a significant presence in Barcelona, where it runs its Spanish operations and serves as a hub for international talent. The company is known for its collaborative, engineering-driven culture and actively recruits international professionals, offering opportunities for growth in areas like AI, cloud security, and platform engineering. For international hires, Pasiona provides a multicultural environment and the chance to work on cutting-edge projects, making it an attractive destination for those looking to build a career in Spain's thriving tech sector.

Industry
Tech Consulting
Founded
2010
Employees
100–500
Headquarters
Barcelona, Spain
In Spain
Barcelona

Good to know if you are moving

  • Pasiona is headquartered in Barcelona, so international hires would be joining the company at its global HQ.
  • The company's working language is English, making it accessible for non-Spanish speakers.
  • Pasiona offers visa sponsorship and relocation support for international candidates.
  • The company has a strong focus on professional development and certifications in cybersecurity and cloud technologies.
  • Barcelona offers a high quality of life, with a strong tech ecosystem and international community.

In their own words

Additional information

At Pasiona, we advocate for diversity and equal opportunities.

We encourage all individuals to apply, regardless of gender, age, disability, sexual orientation, gender identity, ethnic origin, religion, or other personal or social circumstances.

All open roles at Pasiona

Location

Pasiona · Barcelona

Loads Google Maps, which may set its own cookies.

WhatsApp