> Markdown version of [/jobs/ext/1463656-app-cloud-vulnerability-lead](https://www.wearedevelopers.com/jobs/ext/1463656-app-cloud-vulnerability-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # App & Cloud Vulnerability Lead - **Company:** Gramian Consultancy - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Microsoft Azure, Cloud Computing, Continuous Integration, DevOps, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, Software Vulnerability Management, Cloud Platform System, Software Security, Information Technology, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 28, 2026 - **Apply:** https://www.buscojobs.com.es/app-cloud-vulnerability-lead-en-madrid-ID-364767685 ## About the Role With a strong background in software engineering and leadership, we help companies build high-performing teams by matching them with professionals who truly fit their needs.Role OverviewOur client is a global technology and digital transformation consultancy delivering enterprise IT operations and cloud management solutions for large international organizations. Their teams help modernize IT infrastructure through automation, observability, and Service Management platforms.We are looking for a mid-level Vulnerability Management Engineer with experience in Application Security, vulnerability assessment, and security remediation. In this role, you will help identify, prioritize, and coordinate the remediation of security vulnerabilities throughout the software development lifecycle, working closely with development, DevOps, and security teams to improve the organization's overall security posture.Contract : ContractorCommitment : Full-timeLocation : Valencia, Spain (Hybrid / Primarily On-site)Process : 2 Client Interview ProcessNote : English-speaking environment. Spanish is not needed.ResponsibilitiesPerform application vulnerability assessments across web, mobile, and cloud applicationsAnalyze and prioritize security findings based on risk and business impactCoordinate remediation activities with development and engineering teamsSupport vulnerability management throughout the Software Development Lifecycle (SDLC)Conduct security reviews and validate remediation effortsWork with automated vulnerability scanning and security assessment toolsTrack vulnerability metrics and report on remediation progressCollaborate with DevOps and infrastructure teams to improve security practicesContribute to application security processes, standards, and documentationPromote secure development practices across engineering teamsRequirements3+ years of experience in Application Security, Vulnerability Management, or CybersecurityHands-on experience with vulnerability scanning and security assessment toolsStrong understanding of OWASP Top 10 and common application security vulnerabilitiesExperience assessing web, mobile, and/or cloud-based applicationsKnowledge of secure software development practices and the SDLCExperience prioritizing and coordinating vulnerability remediationFamiliarity with cloud environments (AWS, Azure, or GCP)Experience working in Agile development environmentsPreferred QualificationsSecurity certifications such as Security+, CEH, OSCP, CSSLP, or similarExperience with SAST, DAST, SCA, or container security toolsKnowledge of CI/CD security practices and DevSecOpsExperience performing threat modeling or secure code reviewsExperience working with enterprise vulnerability management platforms#J-*****-Ljbffr ## Description About UsGramian Consultancy is a boutique consultancy specializing in IT professional services and engineering talent solutions.With a strong background in software engineering and leadership, we help companies build high-performing teams by matching them with professionals who truly fit their needs.Role OverviewOur client is a global technology and digital transformation consultancy delivering enterprise IT operations and cloud management solutions for large international organizations.Their teams help modernize IT infrastructure through automation, observability, and Service Management platforms.We are looking for a mid-level Vulnerability Management Engineer with experience in Application Security, vulnerability assessment, and security remediation.In this role, you will help identify, prioritize, and coordinate the remediation of security vulnerabilities throughout the software development lifecycle, working closely with development, DevOps, and security teams to improve the organization's overall security posture.Contract : ContractorCommitment : Full-timeLocation : Valencia, Spain (Hybrid / Primarily On-site)Process : 2 Client Interview ProcessNote : English-speaking environment.Spanish is not needed.ResponsibilitiesPerform application vulnerability assessments across web, mobile, and cloud applicationsAnalyze and prioritize security findings based on risk and business impactCoordinate remediation activities with development and engineering teamsSupport vulnerability management throughout the Software Development Lifecycle (SDLC)Conduct security reviews and validate remediation effortsWork with automated vulnerability scanning and security assessment toolsTrack vulnerability metrics and report on remediation progressCollaborate with DevOps and infrastructure teams to improve security practicesContribute to application security processes, standards, and documentationPromote secure development practices across engineering teamsRequirements3+ years of experience in Application Security, Vulnerability Management, or CybersecurityHands-on experience with vulnerability scanning and security assessment toolsStrong understanding of OWASP Top 10 and common application security vulnerabilitiesExperience assessing web, mobile, and/or cloud-based applicationsKnowledge of secure software development practices and the SDLCExperience prioritizing and coordinating vulnerability remediationFamiliarity with cloud environments (AWS, Azure, or GCP)Experience working in Agile development environmentsPreferred QualificationsSecurity certifications such as Security+, CEH, OSCP, CSSLP, or similarExperience with SAST, DAST, SCA, or container security toolsKnowledge of CI/CD security practices and DevSecOpsExperience performing threat modeling or secure code reviewsExperience working with enterprise vulnerability management platforms#J-*****-Ljbffr ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)