> Markdown version of [/jobs/ext/1950857-senior-application-security-engineer-sast-dast-burp-suit-international-organization](https://www.wearedevelopers.com/jobs/ext/1950857-senior-application-security-engineer-sast-dast-burp-suit-international-organization). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - Sast / Dast / Burp Suit - International Organization - **Company:** NTT DATA - **Location:** Valencia, Spain - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Business Logic, Software System Penetration Testing, Microsoft Azure, Burp Suite, Cloud Computing, CompTIA Security+, Cyber Security, Data Validation, Cisco Nexus Switches, Open Web Application Security, Systems Development Life Cycle, Power BI, Fortify (Software), Secure Coding, Software Engineering, SonarQube, Software Vulnerability Management, Enterprise Software Applications, Software Security, Mitre Att&ck, Mttr, Sonatype Nexus, GWAPT, Information Technology, Virtual Agents, CIS Benchmarks, Appscan, Devsecops, Security Orchestration, Automation & Response, Servicenow, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 6, 2026 - **Apply:** https://www.buscojobs.com.es/senior-application-security-engineer-sast-dast-burp-suit-international-organization-en-valencia-ID-366191846 ## About the Role Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent experience. 10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related cybersecurity disciplines. Strong hands-on experience with: SAST DAST SCA Penetration Testing API Security Testing Manual Security Assessments Extensive experience using Burp Suite for web and API security testing. Hands-on experience with tools such as: Burp Suite HCL AppScan Sonatype Nexus IQ/Lifecycle Fortify SonarQube Black Duck (or similar SCA tools) Strong understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, vulnerability management, and risk-based prioritization. Experience collaborating with development teams to drive remediation and improve security maturity. Strong written, verbal, and stakeholder communication skills. Fluency in English (written and spoken). Desirable: Experience with Azure Cloud and Azure DevOps. Experience with ServiceNow for vulnerability or incident management workflows. Experience creating security dashboards and reports using Power BI. Knowledge of NIST, MITRE ATT&CK, CIS Benchmarks, threat modeling, and application security governance practices. Experience with AI-assisted security solutions, security automation, or agentic AI technologies. Certifications: CISSP, CSSLP, GWAPT, GWEB, OSCP / OSWE, Security+, SSCP, Microsoft Azure Security Certifications (AZ-500 or equivalent) ## Description NTT DATA is looking for a Senior Application Security Engineer for one of our international clients, with strong expertise in application security testing, vulnerability management, and DevSecOps advisory services.The successful candidate will lead security assessments, support vulnerability remediation efforts, advise development teams on secure software development practices, and contribute to application security governance, risk, and compliance initiatives.You will be responsible for:Perform and support application security assessments, including SAST, DAST, SCA, penetration testing, API security testing, and manual security reviews.Conduct security testing of web, API, cloud, and enterprise applications using industry-standard tools and techniques.Validate findings, perform false-positive analysis, and execute retesting to verify remediation effectiveness.Identify and assess security weaknesses related to authentication, authorization, input validation, business logic, insecure design, and vulnerable components.Lead vulnerability management activities, including identification, prioritization, remediation tracking, and reporting.Prioritize findings using business impact, exploitability, exposure, threat intelligence, and organizational risk criteria.Advise development teams on secure coding practices, remediation strategies, and secure SDLC implementation.Support integration of security testing and vulnerability management processes into CI/CD pipelines and DevSecOps practices.Support application security policies, standards, risk assessments, threat modeling, and secure design reviews.Assist with security compliance and audit-related activities.Develop security dashboards and metrics covering vulnerability trends, remediation SLAs, MTTR, and testing coverage.Communicate security risks and remediation priorities to technical and non-technical stakeholders.For this role you will need to have experience in:Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Technology, or related discipline, or equivalent experience.10+ years of experience in Application Security, Security Testing, Vulnerability Management, or related cybersecurity disciplines.Strong hands-on experience with:SASTDASTSCAPenetration TestingAPI Security TestingManual Security AssessmentsExtensive experience using Burp Suite for web and API security testing.Hands-on experience with tools such as:Burp SuiteHCL AppScanSonatype Nexus IQ/LifecycleFortifySonarQubeBlack Duck (or similar SCA tools)Strong understanding of OWASP Top 10, CWE, OWASP ASVS, Secure SDLC, vulnerability management, and risk-based prioritization.Experience collaborating with development teams to drive remediation and improve security maturity.Strong written, verbal, and stakeholder communication skills.Fluency in English (written and spoken).Desirable:Experience with Azure Cloud and Azure DevOps.Experience with ServiceNow for vulnerability or incident management workflows.Experience creating security dashboards and reports using Power BI.Knowledge of NIST, MITRE ATT&CK, CIS Benchmarks, threat modeling, and application security governance practices.Experience with AI-assisted security solutions, security automation, or agentic AI technologies.Certifications: CISSP, CSSLP, GWAPT, GWEB, OSCP / OSWE, Security+, SSCP, Microsoft Azure Security Certifications (AZ-500 or equivalent)NTT DATA is a global consultancy company, employing over ****** professionals world-wide.Within the International Institutions we have framework contracts with European Institutions like: European Commission; European Parliament; European Court of Auditors; Europol; NATO; Court of Justice; EPO; European Council, United Nations, etc.#J-*****-Ljbffr ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)