> Markdown version of [/jobs/ext/2018376-security-analyst-vulnerability-exposure](https://www.wearedevelopers.com/jobs/ext/2018376-security-analyst-vulnerability-exposure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst (Vulnerability & Exposure) - **Company:** Q Tech - **Location:** Barcelona, Spain (Remote available) - **Salary:** €51,000.0 - €56,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, JIRA, Microsoft Azure, Cyber Security, Linux, Identity and Access Management, Issue Tracking Systems, Python (Programming Language), Neo4j, Open Web Application Security, Windows PowerShell, Software Vulnerability Management, Web Applications, Scripting, Google Cloud, Cloud Platform System, CIS Benchmarks, Cyber Warfare, Servicenow - **Published:** August 11, 2026 - **Apply:** https://www.buscojobs.com.es/security-analyst-vulnerability-exposure-en-barcelona-ID-366516459 ## About the Role internal teamsCollaborate with infrastructure, cloud and development teams to support remediationAct as a first point of contact for internal stakeholders, handling: support requeststroubleshootingclarification of findingsDevelop and maintain remediation guidelines for: security misconfigurations (Non?CVE)Contribute to process improvements, automation and new initiativesMonitor and track remediation progress through dashboards and reportsHelp improve the overall vulnerability management operating modelWhat we're looking forMust?have5+ years of experience in Cybersecurity OperationsHands?on experience in Vulnerability Management / Exposure ManagementStrong understanding of: CVEs and security misconfigurationsrisk prioritisation (CVSS or similar)Experience across: web applications (OWASP mindset)Solid understanding of: networking, OS (Windows/Linux)Active Directory or IAM environmentsStrong communication skills and stakeholder managementExperience working with ticketing systems (Jira, ServiceNow, etc.)Nice to haveExposure to cloud environments (AWS, Azure, GCP)Knowledge of CIS benchmarks or hardening standardsBasic scripting (Python / PowerShell)Familiarity xqbhyrx with graph?based data (e.g., Neo4j)What makes this role differentYou will not just detect vulnerabilities - you will drive their resolutionHighly collaborative role with strong exposure to international teamsOpportunity to influence processes and shape how vulnerability management is donePotential to grow into leadership responsibilities over timeWorking environmentInternational and English?speaking environmentFlexible schedule with high autonomyOccasional travel within EuropeSalary: 51k-56k€ (depending on experience)Flexible compensation package (~3.7k net/year)Private health insuranceRemote work allowance (1?2 days/week office) and flexible hours#J-*****-Ljbffr ## Description We are looking for a Vulnerability & Exposure Management Analyst to join a mature Cyber Defense Center within a global enterprise environment.Aumente sus posibilidades de llegar a la fase de entrevista leyendo la descripción completa del puesto y enviando su solicitud sin demora.This role sits at the core of the vulnerability lifecycle, acting as a bridge between security, infrastructure, and development teams, ensuring that identified vulnerabilities are properly prioritised, communicated, and remediated.Rather than focusing on scanning or hands?on remediation, this position plays a key orchestration and advisory role, working closely with internal stakeholders across multiple countries.Your responsibilitiesManage the lifecycle of vulnerabilities and exposures: triage, prioritisation, assignment and follow?upinfrastructure, web applications, and (in the future) APIsApply risk?based prioritisation using frameworks such as CVSSProvide clear and actionable remediation guidance to internal teamsCollaborate with infrastructure, cloud and development teams to support remediationAct as a first point of contact for internal stakeholders, handling: support requeststroubleshootingclarification of findingsDevelop and maintain remediation guidelines for: security misconfigurations (Non?CVE)Contribute to process improvements, automation and new initiativesMonitor and track remediation progress through dashboards and reportsHelp improve the overall vulnerability management operating modelWhat we're looking forMust?have5+ years of experience in Cybersecurity OperationsHands?on experience in Vulnerability Management / Exposure ManagementStrong understanding of: CVEs and security misconfigurationsrisk prioritisation (CVSS or similar)Experience across: web applications (OWASP mindset)Solid understanding of: networking, OS (Windows/Linux)Active Directory or IAM environmentsStrong communication skills and stakeholder managementExperience working with ticketing systems (Jira, ServiceNow, etc.)Nice to haveExposure to cloud environments (AWS, Azure, GCP)Knowledge of CIS benchmarks or hardening standardsBasic scripting (Python / PowerShell)Familiarity xqbhyrx with graph?based data (e.g., Neo4j)What makes this role differentYou will not just detect vulnerabilities - you will drive their resolutionHighly collaborative role with strong exposure to international teamsOpportunity to influence processes and shape how vulnerability management is donePotential to grow into leadership responsibilities over timeWorking environmentInternational and English?speaking environmentFlexible schedule with high autonomyOccasional travel within EuropeSalary: 51k-56k€ (depending on experience)Flexible compensation package (~3.7k net/year)Private health insuranceRemote work allowance (1?2 days/week office) and flexible hours#J-*****-Ljbffr ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)