Senior Application Security Engineer - Sast / Dast / Burp Suit - International Organization

NTT DATA
Valencia, Spain
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
10 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Business Logic Software System Penetration Testing Microsoft Azure Burp Suite Cloud Computing CompTIA Security+ Cyber Security Data Validation Cisco Nexus Switches Open Web Application Security
+22 more
Systems Development Life Cycle Power BI Fortify (Software) Secure Coding Software Engineering SonarQube Software Vulnerability Management Enterprise Software Applications Software Security Mitre Att&ck Mttr Sonatype Nexus GWAPT Information Technology Virtual Agents CIS Benchmarks Appscan Devsecops Security Orchestration, Automation & Response Servicenow Static Application Security Testing Dynamic Application Security Testing

Job description

NTT DATA is looking for a Senior Application Security Engineer for one of our international clients, with strong expertise in application security testing, vulnerability management, and DevSecOps advisory services.The successful candidate will lead security assessments, support vulnerability remediation efforts, advise development teams on secure software development practices, and contribute to application security governance, risk, and compliance initiatives.You will be responsible for:Perform and support application security assessments, including SAST, DAST, SCA, penetration testing, API security testing, and manual security reviews.Conduct security testing of web, API, cloud, and enterprise applications using industry-standard tools and techniques.Validate findings, perform false-positive analysis, and execute retesting to verify remediation effectiveness.Identify and assess security weaknesses related to authentication, authorization, input validation, business logic, insecure design, and vulnerable components.Lead vulnerability management activities, including identification, prioritization, remediation tracking, and reporting.Prioritize findings using business impact, exploitability, exposure, threat intelligence, and organizational risk criteria.Advise development teams on secure coding practices, remediation strategies, and secure SDLC implementation.Support integration of security testing and vulnerability management processes into CI/CD pipelines and DevSecOps practices.Support application security policies, standards, risk assessments, threat modeling, and secure design reviews.Assist with security compliance and audit-related activities.Develop security dashboards and metrics covering vulnerability trends, remediation SLAs, MTTR, and testing coverage.Communicate security risks and remediation priorities to technical and non-technical stakeholders.For this role you will need to have experience in:Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent experience.10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related cybersecurity disciplines.Strong hands-on experience with:SASTDASTSCAPenetration TestingAPI Security TestingManual Security AssessmentsExtensive experience using Burp Suite for web and API security testing.Hands-on experience with tools such as:Burp SuiteHCL AppScanSonatype Nexus IQ/LifecycleFortifySonarQubeBlack Duck (or similar SCA tools)Strong understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, vulnerability management, and risk-based prioritization.Experience collaborating with development teams to drive remediation and improve security maturity.Strong written, verbal, and stakeholder communication skills.Fluency in English (written and spoken).Desirable:Experience with Azure Cloud and Azure DevOps.Experience with ServiceNow for vulnerability or incident management workflows.Experience creating security dashboards and reports using Power BI.Knowledge of NIST, MITRE ATT&CK, CIS Benchmarks, threat modeling, and application security governance practices.Experience with AI-assisted security solutions, security automation, or agentic AI technologies.Certifications: CISSP, CSSLP, GWAPT, GWEB, OSCP / OSWE, Security+, SSCP, Microsoft Azure Security Certifications (AZ-500 or equivalent)NTT DATA is a global consultancy company, employing over ** professionals world-wide.Within the International Institutions we have framework contracts with European Institutions like: European Commission; European Parliament; European Court of Auditors; Europol; NATO; Court of Justice; EPO; European Council, United Nations, etc.#J-*****-Ljbffr

Requirements

Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent experience. 10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related cybersecurity disciplines. Strong hands-on experience with: SAST DAST SCA Penetration Testing API Security Testing Manual Security Assessments Extensive experience using Burp Suite for web and API security testing. Hands-on experience with tools such as: Burp Suite HCL AppScan Sonatype Nexus IQ/Lifecycle Fortify SonarQube Black Duck (or similar SCA tools) Strong understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, vulnerability management, and risk-based prioritization. Experience collaborating with development teams to drive remediation and improve security maturity. Strong written, verbal, and stakeholder communication skills. Fluency in English (written and spoken). Desirable: Experience with Azure Cloud and Azure DevOps. Experience with ServiceNow for vulnerability or incident management workflows. Experience creating security dashboards and reports using Power BI. Knowledge of NIST, MITRE ATT&CK, CIS Benchmarks, threat modeling, and application security governance practices. Experience with AI-assisted security solutions, security automation, or agentic AI technologies. Certifications: CISSP, CSSLP, GWAPT, GWEB, OSCP / OSWE, Security+, SSCP, Microsoft Azure Security Certifications (AZ-500 or equivalent)

About the company

NTT DATA is a global consultancy company, employing over ** professionals world-wide. Within the International Institutions we have framework contracts with European Institutions like: European Commission; European Parliament; European Court of Auditors; Europol; NATO; Court of Justice; EPO; European Council, United Nations, etc. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · World Congress 2021

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

4:01 min

Implementing the barbell strategy and focusing on recovery time

Jan de Vries Jan de Vries · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all