Vulnerability Management Engineer

Company
Description
### **Are You the Security Guardian Who Will Protect the Future of Elite Software?** **Location:** Valencia (On-site) **Working Hours:** 09:00 \- 18:00 We are not looking for someone who merely runs automated reports; we seek an engineer with deep technical curiosity, ready to take ownership of the security posture across our web, mobile, and cloud applications. At **Initium Software**, your mission will be to identify, manage, and remediate vulnerabilities throughout the entire software development lifecycle, collaborating side-by-side with high-performing teams. ### **Your Challenges and Responsibilities** * **Lead Security Assessments:** Execute and support vulnerability analyses in applications using SAST, DAST, SCA, and manual code reviews. * **Critical Analysis:** Validate scan results, analyze false positives, and rigorously track findings until effective remediation is confirmed via retesting. * **Strategic Prioritization:** Classify vulnerabilities based on business impact, severity, and exploitability probability, applying standard methodologies such as CVSS. * **Automation and Integration:** Drive the integration of security workflows and scanning directly into CI/CD pipelines. * **Metrics and KPI Management:** Develop and maintain dashboards to measure severity distribution, SLA compliance, and mean time to remediation (MTTR). * **Incident Response:** Actively participate in responses to high-severity or zero-day vulnerabilities, coordinating mitigation plans. ### **What We Look for in You? (Your Essential Arsenal)** * **Experience:** More than 5 years of solid experience in application security and/or vulnerability management. * **Education:** Graduate in Systems Engineering, Cybersecurity, Computer Science, or equivalent professional experience. * **Technical Proficiency:** Deep understanding of common vulnerability classes (e.g., OWASP Top 10\) and secure architecture principles. * **Manual Testing:** High proficiency in using **Burp Suite** for manual security testing of web applications and APIs (business logic validation, complex authentication and authorization). * **Industry Tools:** Practical experience with platforms such as Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and network discovery tools like Nmap. * **Frameworks:** Familiarity with NIST standards, MITRE ATT\&CK, and CIS benchmarks. * **Coding/Scripting:** Ability to program or automate using languages such as Python, Java, or .NET. * **Languages:** Advanced English (C1\), capable of interacting effectively with global teams and environments. * **Soft Skills:** Excellent documentation, communication, and stakeholder management skills. **We Especially Value If You Also Have (Desirable):** * Professional certifications in the field (e.g., Security\+, SSCP, GWAPT, or actively pursuing CISSP or OSCP). * Experience using ServiceNow for vulnerability or incident tracking. * Experience in Azure cloud environments and Azure DevOps ecosystems. * Proficiency in Power BI for visualizing security metrics to both technical and executive audiences. * Passion for learning, sharing ideas, and growing alongside the team. **How Will We Measure Your Impact?** * Monthly achievement of efficiency and mitigation goals within assigned Projects. * Effective alignment with and execution of the company’s strategic application security plan. ### **Benefits** **What Do We Offer You?** * **Compensation:** Competitive fixed salary commensurate with your elite experience. * **Work Modality:** Stable working hours from 09:00 to 18:00 at one of our clients’ offices in Valencia. * **Challenging Projects:** Work with cutting-edge technologies, protecting complex ecosystems — completely free from monotony. * **Initium Culture:** An environment built on autonomy, collaboration, and dynamism — where your initiative is valued, your impact recognized, and your growth and continuous mentorship strongly supported. "At Initium, we don’t just develop technology: we create an environment where people can evolve, deliver value, and leave a lasting mark." **Are You Ready for the Challenge?** If you seek a place where your expertise makes a real impact and your curiosity drives the protection of critical systems, let’s talk about the future you can build with us. **Apply now and let’s talk**
Posted by

David Muñoz
Indeed · HR