> Markdown version of [/jobs/ext/2025126-application-security-specialist](https://www.wearedevelopers.com/jobs/ext/2025126-application-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Specialist - **Company:** Zone3000 Technologies - **Location:** Barcelona, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Server Applications, Software Applications, C++ (Programming Language), Static Program Analysis, Software Debugging, Dynamic Program Analysis, Python (Programming Language), Reverse Engineering, Software Engineering, Software Security, Information Technology, Vulnerability Analysis - **Published:** August 11, 2026 - **Apply:** https://www.tecnoempleo.com/application-security-specialist-zone3000-technolog/reverse-engineering-mem/rf-86a410092221533a604d ## About the Role BSc / MS in computer science or a related field Previous CVEs in desktop applications Proficiency with reverse engineering tools Significant experience in memory exploitation techniques (e.g. gaining code execution from memory vulnerabilities in modern operating systems) Familiarity with cloud security best practices 3+ years of industry experience OSCP / OSWE / OSED / RET2 certification Will definitely be a plus: An attacker mindset: engineers will often want proof before fixes are implemented Eagerness to learn - you are not expected to know everything coming in, but you should continuously learn new techniques on the job The ability to communicate clearly, acknowledge mistakes, and disagree when necessary Demonstrable passion for offensive security Experience reading, writing and debugging C++ and Python code Basic experience with memory exploitation techniques Demonstrable experience with web exploitation techniques and tools (e.g. PortSwigger lab scoreboards) Excellent written and oral communication skills, In this role, you will help make security decisions that impact millions of users while gaining hands-on experience in exploit development, vulnerability research, and CVE discovery. The ideal candidate combines an attacker mindset with strong attention to detail and enjoys collaborating with engineering teams to build secure, scalable solutions. ## Description Reproduce and triage incoming vulnerabilities from security automation/bug bounty programs, then propose granular fixes to engineers Discover vulnerabilities and construct exploits for core Parallels applications such as Parallels Remote Application Server Assist in the CVE disclosure process Provide threat models and design reviews for teams throughout the company Assist in tuning existing static analysis, dynamic analysis, and dependency management tools About the company and project: ZONE3000 is a 2400+ people family that forms a new cultural code in the software development business. For 25 years we have been focusing on the highest quality of projects and empowering people to think big and make a difference. We are looking for talents who want to create and improve technological solutions for tomorrow and make things as best possible. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Using AI Without Losing Your Skills](https://www.wearedevelopers.com/videos/2045-using-ai-without-losing-your-skills) - [2021: Familiar APIs on Kickass Runtimes #slideless](https://www.wearedevelopers.com/videos/102-2021-familiar-apis-on-kickass-runtimes-slideless) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Stranger Danger: Your Java Attack Surface Just Got Bigger](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)