Security Analyst (Vulnerability & Exposure)

Q Tech
Barcelona, Spain
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
€51,000.0 - €56,000.0
Working hours
Regular working hours
Languages
English

Tech stack

Microsoft Windows Active Directory Amazon Web Services JIRA Microsoft Azure Cyber Security Linux Identity and Access Management Issue Tracking Systems Python (Programming Language) Neo4j Open Web Application Security
+9 more
Windows PowerShell Software Vulnerability Management Web Applications Scripting Google Cloud Cloud Platform System CIS Benchmarks Cyber Warfare Servicenow

Job description

We are looking for a Vulnerability & Exposure Management Analyst to join a mature Cyber Defense Center within a global enterprise environment.Aumente sus posibilidades de llegar a la fase de entrevista leyendo la descripción completa del puesto y enviando su solicitud sin demora.This role sits at the core of the vulnerability lifecycle, acting as a bridge between security, infrastructure, and development teams, ensuring that identified vulnerabilities are properly prioritised, communicated, and remediated.Rather than focusing on scanning or hands?on remediation, this position plays a key orchestration and advisory role, working closely with internal stakeholders across multiple countries.Your responsibilitiesManage the lifecycle of vulnerabilities and exposures: triage, prioritisation, assignment and follow?upinfrastructure, web applications, and (in the future) APIsApply risk?based prioritisation using frameworks such as CVSSProvide clear and actionable remediation guidance to internal teamsCollaborate with infrastructure, cloud and development teams to support remediationAct as a first point of contact for internal stakeholders, handling: support requeststroubleshootingclarification of findingsDevelop and maintain remediation guidelines for: security misconfigurations (Non?CVE)Contribute to process improvements, automation and new initiativesMonitor and track remediation progress through dashboards and reportsHelp improve the overall vulnerability management operating modelWhat we’re looking forMust?have5+ years of experience in Cybersecurity OperationsHands?on experience in Vulnerability Management / Exposure ManagementStrong understanding of: CVEs and security misconfigurationsrisk prioritisation (CVSS or similar)Experience across: web applications (OWASP mindset)Solid understanding of: networking, OS (Windows/Linux)Active Directory or IAM environmentsStrong communication skills and stakeholder managementExperience working with ticketing systems (Jira, ServiceNow, etc.)Nice to haveExposure to cloud environments (AWS, Azure, GCP)Knowledge of CIS benchmarks or hardening standardsBasic scripting (Python / PowerShell)Familiarity xqbhyrx with graph?based data (e.g., Neo4j)What makes this role differentYou will not just detect vulnerabilities - you will drive their resolutionHighly collaborative role with strong exposure to international teamsOpportunity to influence processes and shape how vulnerability management is donePotential to grow into leadership responsibilities over timeWorking environmentInternational and English?speaking environmentFlexible schedule with high autonomyOccasional travel within EuropeSalary: 51k-56k€ (depending on experience)Flexible compensation package (~3.7k net/year)Private health insuranceRemote work allowance (1?2 days/week office) and flexible hours#J-*****-Ljbffr

Requirements

internal teamsCollaborate with infrastructure, cloud and development teams to support remediationAct as a first point of contact for internal stakeholders, handling: support requeststroubleshootingclarification of findingsDevelop and maintain remediation guidelines for: security misconfigurations (Non?CVE)Contribute to process improvements, automation and new initiativesMonitor and track remediation progress through dashboards and reportsHelp improve the overall vulnerability management operating modelWhat we’re looking forMust?have5+ years of experience in Cybersecurity OperationsHands?on experience in Vulnerability Management / Exposure ManagementStrong understanding of: CVEs and security misconfigurationsrisk prioritisation (CVSS or similar)Experience across: web applications (OWASP mindset)Solid understanding of: networking, OS (Windows/Linux)Active Directory or IAM environmentsStrong communication skills and stakeholder managementExperience working with ticketing systems (Jira, ServiceNow, etc.)Nice to haveExposure to cloud environments (AWS, Azure, GCP)Knowledge of CIS benchmarks or hardening standardsBasic scripting (Python / PowerShell)Familiarity xqbhyrx with graph?based data (e.g., Neo4j)What makes this role differentYou will not just detect vulnerabilities - you will drive their resolutionHighly collaborative role with strong exposure to international teamsOpportunity to influence processes and shape how vulnerability management is donePotential to grow into leadership responsibilities over timeWorking environmentInternational and English?speaking environmentFlexible schedule with high autonomyOccasional travel within EuropeSalary: 51k-56k€ (depending on experience)Flexible compensation package (~3.7k net/year)Private health insuranceRemote work allowance (1?2 days/week office) and flexible hours#J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

2:24 min

Comparing Neo4j and GraphQL conceptual models

William Lyon · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:55 min

Prioritizing system vulnerabilities and enhancing automated security posture

Raz Cohen · LIVE

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all