Application Security And Secure Development

Gmv
Madrid, Spain
3 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Shift work
Languages
English

Tech stack

Artificial Intelligence Software System Penetration Testing Burp Suite Cloud Computing Linux JSON Secure Coding Software Vulnerability Management Working Model 2D Scripting Software Security Cyber Threat Analysis
+4 more
Restful APIs Prisma Cloud Platform Qualys Vulnerability Analysis

Job description

If you want to take the next step in your cybersecurity career, becoming a technical reference in Vulnerability Management within a large-scale service for a financial sector organization, your place is with us.We’ll get to the point; we’ll tell you what’s not on the web.If you want to know more about de GMVWHAT CHALLENGE WILL YOU BE TAKING ON?You will act as the technical reference for a Vulnerability Management service, leading advanced analysis, risk-based prioritization and vulnerability treatment across infrastructure, applications, Cloud and container environments.Your main responsibilities will include:Acting as the technical reference for Vulnerability Management operations and resolving technical escalations.Performing advanced analysis and risk-based prioritization, considering factors such as CVSS, EPSS, CISA KEV, exposure, criticality and Threat Intelligence.Defining and monitoring remediation activities, mitigations and compensating controls.Coordinating with specialized Hacking, Cloud, Hardening/Compliance, Threat Intelligence and Automation teams.Supervising critical or actively exploited vulnerabilities, including technical verification and closure.Monitoring SLAs, KPIs and reporting, identifying opportunities for automation and service improvement.Contributing to the evolution of the service and the safe and supervised use of AI in Vulnerability Management.WHAT DO WE NEEDED IN OUR TEAM?We are looking for a professional with at least 5 years of experience in cybersecurity, with significant experience in Vulnerability Management, and a technical university degree or equivalent qualification.You should have:Strong knowledge of the vulnerability lifecycle and risk-based prioritization, including CVSS, EPSS, CISA KEV and Threat Intelligence.Experience with vulnerability scanning and management tools, preferably Qualys.Solid knowledge of Windows, Linux, networking, applications, Cloud and container environments.Experience in exploitation analysis, defining mitigations and compensating controls, as well as SLA, KPI and reporting management.Knowledge of scripting, REST APIs, JSON and automation.Strong technical leadership, autonomy and multidisciplinary coordination skills.Security, Hardening/Compliance, Pentesting and tools such as Prisma Cloud, Qualys WAAS or Burp Suite, will be valued.Knowledge of cybersecurity governance and risk.Technical English is required, with a B2 level being recommended.WHAT DO WE OFFER?Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.Flexible start and finish times, and intensive working hours Fridays and in summer.Personalized career plan development, training and language learning support.National and international mobility.Do you come from another country?We can offer you a relocation package.Competitive compensation with ongoing reviews, flexible compensation and discount on brands.Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!In our recruitment processes you will always have telephone and personal contact, face-to-face or online, with our talent acquisition team.In addition

Requirements

We are looking for a professional with at least 5 years of experience in cybersecurity, with significant experience in Vulnerability Management, and a technical university degree or equivalent qualification.You should have:Strong knowledge of the vulnerability lifecycle and risk-based prioritization, including CVSS, EPSS, CISA KEV and Threat Intelligence.Experience with vulnerability scanning and management tools, preferably Qualys.Solid knowledge of Windows, Linux, networking, applications, Cloud and container environments.Experience in exploitation analysis, defining mitigations and compensating controls, as well as SLA, KPI and reporting management.Knowledge of scripting, REST APIs, JSON and automation.Strong technical leadership, autonomy and multidisciplinary coordination skills.Security, Hardening/Compliance, Pentesting and tools such as Prisma Cloud, Qualys WAAS or Burp Suite, will be valued.Knowledge of cybersecurity governance and risk.Technical English is required, with a B2

Benefits & conditions

Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.Flexible start and finish times, and intensive working hours Fridays and in summer.Personalized career plan development, training and language learning support.National and international mobility. Do you come from another country? We can offer you a relocation package.Competitive compensation with ongoing reviews, flexible compensation and discount on brands.Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more! In our recruitment processes you will always have telephone and personal contact, face-to-face or online, with our talent acquisition team. In addition

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · World Congress 2025

1:17 min

Evaluating security vulnerabilities and user experience

Julian Richter Julian Richter · World Congress 2025

Videos

See all

Related articles

See all