> Markdown version of [/jobs/ext/1678298-security-analyst](https://www.wearedevelopers.com/jobs/ext/1678298-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - **Company:** Jobgether - **Location:** Málaga, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Macintosh Computers, Software System Penetration Testing, Linux, Linux System Administration, Open Web Application Security, Web Applications, Working Model 2D, Vulnerability Analysis - **Published:** July 31, 2026 - **Apply:** https://www.buscojobs.com.es/security-analyst-en-malaga-ID-364160544 ## About the Role At least 2 years of experience in penetration testing, security testing, or vulnerability assessment roles Strong understanding of ethical hacking principles and familiarity with bug bounty ecosystems Solid knowledge of the OWASP Top 10 and common web application vulnerabilities Hands?on experience with Mac, Windows, and Linux environments Ability to independently research, troubleshoot, and solve complex technical problems Strong analytical mindset with excellent attention to detail and risk assessment skills Experience working in high?pressure or incident?driven environments with strong prioritization abilities Familiarity with CVSS scoring and vulnerability severity assessment Strong interpersonal and communication skills, with the ability to explain technical issues clearly Fluent in English; Dutch is a strong plus Nice to have: certifications such as CEH, OSCP, OSWE, or equivalent, and/or an active bug bounty profile Flexibility to work in a 24/7 operational support environment when required ## Description This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Analyst based in Spain.This role sits at the intersection of cybersecurity operations and global security research, where you will evaluate and manage incoming vulnerability reports from a large and active ethical hacker community. You will act as a trusted bridge between security researchers and client security teams, ensuring that findings are accurate, actionable, and properly prioritized. The position combines hands?on technical security analysis with incident response, communication, and community engagement. You will assess vulnerabilities, support remediation efforts, and help organizations strengthen their security posture. Working in a fast?paced, high?volume environment, you will continuously refine your offensive and defensive security skills. The role also involves mentoring junior analysts and contributing to the improvement of internal processes and workflows. It is ideal for someone who enjoys technical depth, structured problem?solving, and meaningful real?world security impact.AccountabilitiesReview, validate, and assess incoming vulnerability reports to ensure they are unique, actionable, and relevant for clientsPerform technical analysis, proof?of?concept validation, and severity assessment of reported security issuesCalculate and apply CVSS scoring to evaluate impact and prioritization of vulnerabilitiesAct as a key point of contact for escalation handling, incident triage, and researcher mediationProvide remediation guidance and clear technical feedback to customers and internal stakeholdersConduct security testing and validation across web, mobile, systems, and network environmentsStay up to date with emerging threats, malware trends, and evolving attack techniquesMentor and support junior team members while contributing to knowledge sharing within the teamCollaborate closely with customer success teams to ensure value is derived from security findingsProactively identify risks, prioritize workload, and ensure timely resolution of critical issuesRequirementsAt least 2 years of experience in penetration testing, security testing, or vulnerability assessment rolesStrong understanding of ethical hacking principles and familiarity with bug bounty ecosystemsSolid knowledge of the OWASP Top 10 and common web application vulnerabilitiesHands?on experience with Mac, Windows, and Linux environmentsAbility to independently research, troubleshoot, and solve complex technical problemsStrong analytical mindset with excellent attention to detail and risk assessment skillsExperience working in high?pressure or incident?driven environments with strong prioritization abilitiesFamiliarity with CVSS scoring and vulnerability severity assessmentStrong interpersonal and communication skills, with the ability to explain technical issues clearlyFluent in English; Dutch is a strong plusNice to have: certifications such as CEH, OSCP, OSWE, or equivalent, and/or an active bug bounty profileFlexibility to work in a 24/7 operational support environment when requiredBenefitsCompetitive salary packageHybrid working model with flexibility across Europe2?month work?from?anywhere policyInitial home office setup budget and access to high?quality equipmentAnnual learning and training budget to support continuous developmentStrong career growth path within cybersecurity and security operationsSocial events, team activities, and international collaboration opportunitiesReferral bonus programExposure to a global ethical hacking community and real?world security challengesOpportunity to work in a fast?growing cybersecurity environment with strong industry recognition#J-*****-Ljbffr ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Machine Learning for Software Developers (and Knitters)](https://www.wearedevelopers.com/videos/154-machine-learning-for-software-developers-and-knitters) - [Generate AI in the Browser with Chrome AI - Raymond Camden](https://www.wearedevelopers.com/videos/1770-generate-ai-in-the-browser-with-chrome-ai-raymond-camden) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [The Neuro-Architecture of Productivity: How Work Environments Impact Cognitive Performance](https://www.wearedevelopers.com/videos/1122-the-neuro-architecture-of-productivity-how-work-environments-impact-cognitive-performance) - [WebXR: Enabling Virtual and Augmented Reality on the Web](https://www.wearedevelopers.com/videos/965-webxr-enabling-virtual-and-augmented-reality-on-the-web) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam)