> Markdown version of [/jobs/ext/1307690-application-security-analyst](https://www.wearedevelopers.com/jobs/ext/1307690-application-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Analyst - **Company:** OneTrust, LLC. - **Location:** Madrid, Spain - **Contract:** Temporary contract - **Skills:** Agile Methodology, Artificial Intelligence, Software System Penetration Testing, Burp Suite, Software as a Service, Cyber Security, Network Security, Secure Coding, Software Vulnerability Management, Software Security, GWAPT, Infrastructure Automation Frameworks, Information Technology, Metasploit - **Published:** July 17, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role Bachelor's degree in Computer Science, Information Security, or a related field - or equivalent hands-on experience. Fluent in English; proficiency in Spanish is a plus. Proven experience in application security, penetration testing, and secure coding principles. Solid understanding of security protocols, network security, cryptography, and vulnerability management. Skilled at translating complex security issues into clear business risks and remediation plans. A strong collaborator, capable of partnering with cross-functional teams and external stakeholders. Experience with scripting and automation tools is a plus. Extra Awesome Security certifications such as OSCP, GWAPT, CEH, or similar. Experience managing bug bounty programs or working with platforms like HackerOne or Bugcrowd. Familiarity with Burp Suite, OWASP ZAP, Metasploit, or similar tools. Experience working in SaaS, Agile environments, or CI/CD pipelines. Knowledge of secure development lifecycle (SDLC) practices. ## Description OneTrust's mission is to enable organizations to use data and AI responsibly. Our platform simplifies the collection of data with consent and preferences, automates the governance of data with integrated risk management across privacy, security, IT/tech, third-party, and AI risk, and activates the responsible use of data by applying and enforcing data policies across the entire data estate and lifecycle. OneTrust supports seamless collaboration between data teams and risk teams to drive rapid and trusted innovation. Recognized as a market pioneer and leader, OneTrust boasts over 300 patents and serves more than 14,000 customers globally, ranging from industry giants to small businesses. The Challenge As a Senior Application Security Analyst at OneTrust, you'll play a pivotal role in safeguarding the security of our products. You'll lead end-to-end efforts in identifying vulnerabilities, working closely with engineering teams, customers, and external researchers to drive proactive remediation and elevate our overall security posture. From coordinating customer penetration tests to managing our bug bounty program, this is a hands-on role that combines technical depth with strong collaboration skills. Your Mission Conduct application-level penetration tests to identify and assess vulnerabilities across OneTrust products. Coordinate and support customer penetration testing efforts, ensuring seamless communication and delivering clear, actionable insights. Guide internal development teams through secure remediation strategies to resolve vulnerabilities effectively. Manage and evolve OneTrust's bug bounty program, engaging with researchers and tracking issues to closure. Oversee relationships with third-party product security vendors to ensure testing quality and compliance. Contribute to continuously improving security testing practices, documentation, and internal education. Your Experience Includes ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)