Security Analyst

Jobgether
Málaga, Spain
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
2 years minimum
Working hours
Regular working hours
Languages
Dutch, English

Tech stack

Microsoft Windows Macintosh Computers Software System Penetration Testing Linux Linux System Administration Open Web Application Security Web Applications Working Model 2D Vulnerability Analysis

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Analyst based in Spain.This role sits at the intersection of cybersecurity operations and global security research, where you will evaluate and manage incoming vulnerability reports from a large and active ethical hacker community. You will act as a trusted bridge between security researchers and client security teams, ensuring that findings are accurate, actionable, and properly prioritized. The position combines hands?on technical security analysis with incident response, communication, and community engagement. You will assess vulnerabilities, support remediation efforts, and help organizations strengthen their security posture. Working in a fast?paced, high?volume environment, you will continuously refine your offensive and defensive security skills. The role also involves mentoring junior analysts and contributing to the improvement of internal processes and workflows. It is ideal for someone who enjoys technical depth, structured problem?solving, and meaningful real?world security impact.AccountabilitiesReview, validate, and assess incoming vulnerability reports to ensure they are unique, actionable, and relevant for clientsPerform technical analysis, proof?of?concept validation, and severity assessment of reported security issuesCalculate and apply CVSS scoring to evaluate impact and prioritization of vulnerabilitiesAct as a key point of contact for escalation handling, incident triage, and researcher mediationProvide remediation guidance and clear technical feedback to customers and internal stakeholdersConduct security testing and validation across web, mobile, systems, and network environmentsStay up to date with emerging threats, malware trends, and evolving attack techniquesMentor and support junior team members while contributing to knowledge sharing within the teamCollaborate closely with customer success teams to ensure value is derived from security findingsProactively identify risks, prioritize workload, and ensure timely resolution of critical issuesRequirementsAt least 2 years of experience in penetration testing, security testing, or vulnerability assessment rolesStrong understanding of ethical hacking principles and familiarity with bug bounty ecosystemsSolid knowledge of the OWASP Top 10 and common web application vulnerabilitiesHands?on experience with Mac, Windows, and Linux environmentsAbility to independently research, troubleshoot, and solve complex technical problemsStrong analytical mindset with excellent attention to detail and risk assessment skillsExperience working in high?pressure or incident?driven environments with strong prioritization abilitiesFamiliarity with CVSS scoring and vulnerability severity assessmentStrong interpersonal and communication skills, with the ability to explain technical issues clearlyFluent in English; Dutch is a strong plusNice to have: certifications such as CEH, OSCP, OSWE, or equivalent, and/or an active bug bounty profileFlexibility to work in a 24/7 operational support environment when requiredBenefitsCompetitive salary packageHybrid working model with flexibility across Europe2?month work?from?anywhere policyInitial home office setup budget and access to high?quality equipmentAnnual learning and training budget to support continuous developmentStrong career growth path within cybersecurity and security operationsSocial events, team activities, and international collaboration opportunitiesReferral bonus programExposure to a global ethical hacking community and real?world security challengesOpportunity to work in a fast?growing cybersecurity environment with strong industry recognition#J-*****-Ljbffr

Requirements

At least 2 years of experience in penetration testing, security testing, or vulnerability assessment roles Strong understanding of ethical hacking principles and familiarity with bug bounty ecosystems Solid knowledge of the OWASP Top 10 and common web application vulnerabilities Hands?on experience with Mac, Windows, and Linux environments Ability to independently research, troubleshoot, and solve complex technical problems Strong analytical mindset with excellent attention to detail and risk assessment skills Experience working in high?pressure or incident?driven environments with strong prioritization abilities Familiarity with CVSS scoring and vulnerability severity assessment Strong interpersonal and communication skills, with the ability to explain technical issues clearly Fluent in English; Dutch is a strong plus Nice to have: certifications such as CEH, OSCP, OSWE, or equivalent, and/or an active bug bounty profile Flexibility to work in a 24/7 operational support environment when required

Benefits & conditions

Competitive salary package Hybrid working model with flexibility across Europe 2?month work?from?anywhere policy Initial home office setup budget and access to high?quality equipment Annual learning and training budget to support continuous development Strong career growth path within cybersecurity and security operations Social events, team activities, and international collaboration opportunities Referral bonus program Exposure to a global ethical hacking community and real?world security challenges Opportunity to work in a fast?growing cybersecurity environment with strong industry recognition #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:13 min

Analyzing test coverage gaps in standard web applications

Jorge Gonzalez Pliego Jorge Gonzalez Pliego · Europe 2026 Virtual

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:36 min

Running AI applications with PWAs and background web workers

Maxim Salnikov Maxim Salnikov · WWC 2025

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

Videos

See all

Related articles

See all