> Markdown version of [/jobs/ext/1939884-app-security-vulnerability-engineer-hybrid-valencia](https://www.wearedevelopers.com/jobs/ext/1939884-app-security-vulnerability-engineer-hybrid-valencia). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # App Security & Vulnerability Engineer - Hybrid Valencia - **Company:** Gramian Consulting - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** DevOps, Open Web Application Security, Software Engineering, Software Vulnerability Management, Software Security - **Published:** August 5, 2026 - **Apply:** https://www.buscojobs.com.es/app-security-vulnerability-engineer-hybrid-valencia-en-madrid-ID-365592564 ## About the Role The ideal candidate will have at least 3 years of experience in Application Security and Vulnerability Management, with a strong understanding of OWASP Top 10. ## Description Gramian Consulting is seeking a mid-level Vulnerability Management Engineer based in Valencia, Spain.In this role, you will work closely with development, DevOps, and security teams to enhance the organization's security posture by coordinating the remediation of security vulnerabilities throughout the software development lifecycle.The ideal candidate will have at least 3 years of experience in Application Security and Vulnerability Management, with a strong understanding of OWASP Top 10.This position offers a hybrid work model in a primarily on-site environment.#J-*****-Ljbffr ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Avengers Initiative (Practical Ethics for Software Engineers)](https://www.wearedevelopers.com/videos/2070-the-avengers-initiative-practical-ethics-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)