Description
### **Are You the Security Guardian Who Will Protect the Future of Elite Software?**
**Location:** Valencia (On-site) **Working Hours:** 09:00 \- 18:00
We are not looking for someone who merely runs automated reports; we seek an engineer with deep technical curiosity, ready to take ownership of the security posture across our web, mobile, and cloud applications. At **Initium Software**, your mission will be to identify, manage, and remediate vulnerabilities throughout the entire software development lifecycle, collaborating side-by-side with high-performing teams.
### **Your Challenges and Responsibilities**
* **Lead Security Assessments:** Execute and support vulnerability analyses in applications using SAST, DAST, SCA, and manual code reviews.
* **Critical Analysis:** Validate scan results, analyze false positives, and rigorously track findings until effective remediation is confirmed via retesting.
* **Strategic Prioritization:** Classify vulnerabilities based on business impact, severity, and exploitability probability, applying standard methodologies such as CVSS.
* **Automation and Integration:** Drive the integration of security workflows and scanning directly into CI/CD pipelines.
* **Metrics and KPI Management:** Develop and maintain dashboards to measure severity distribution, SLA compliance, and mean time to remediation (MTTR).
* **Incident Response:** Actively participate in responses to high-severity or zero-day vulnerabilities, coordinating mitigation plans.
### **What We Look for in You? (Your Essential Arsenal)**
* **Experience:** More than 5 years of solid experience in application security and/or vulnerability management.
* **Education:** Graduate in Systems Engineering, Cybersecurity, Computer Science, or equivalent professional experience.
* **Technical Proficiency:** Deep understanding of common vulnerability classes (e.g., OWASP Top 10\) and secure architecture principles.
* **Manual Testing:** High proficiency in using **Burp Suite** for manual security testing of web applications and APIs (business logic validation, complex authentication and authorization).
* **Industry Tools:** Practical experience with platforms such as Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and network discovery tools like Nmap.
* **Frameworks:** Familiarity with NIST standards, MITRE ATT\&CK, and CIS benchmarks.
* **Coding/Scripting:** Ability to program or automate using languages such as Python, Java, or .NET.
* **Languages:** Advanced English (C1\), capable of interacting effectively with global teams and environments.
* **Soft Skills:** Excellent documentation, communication, and stakeholder management skills.
**We Especially Value If You Also Have (Desirable):**
* Professional certifications in the field (e.g., Security\+, SSCP, GWAPT, or actively pursuing CISSP or OSCP).
* Experience using ServiceNow for vulnerability or incident tracking.
* Experience in Azure cloud environments and Azure DevOps ecosystems.
* Proficiency in Power BI for visualizing security metrics to both technical and executive audiences.
* Passion for learning, sharing ideas, and growing alongside the team.
**How Will We Measure Your Impact?**
* Monthly achievement of efficiency and mitigation goals within assigned Projects.
* Effective alignment with and execution of the company’s strategic application security plan.
### **Benefits**
**What Do We Offer You?**
* **Compensation:** Competitive fixed salary commensurate with your elite experience.
* **Work Modality:** Stable working hours from 09:00 to 18:00 at one of our clients’ offices in Valencia.
* **Challenging Projects:** Work with cutting-edge technologies, protecting complex ecosystems — completely free from monotony.
* **Initium Culture:** An environment built on autonomy, collaboration, and dynamism — where your initiative is valued, your impact recognized, and your growth and continuous mentorship strongly supported.
"At Initium, we don’t just develop technology: we create an environment where people can evolve, deliver value, and leave a lasting mark."
**Are You Ready for the Challenge?** If you seek a place where your expertise makes a real impact and your curiosity drives the protection of critical systems, let’s talk about the future you can build with us.
**Apply now and let’s talk**