hirq
← All jobs

Pasiona

Vulnerability Management Expert

Barcelona · On-site · full-time · Comercial/Axa

Apply well, not just fast

Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.

About the role

AWSGCPAzureCI/CDCloud SecurityJiraPythonGoBashDockerGitSOC 2ISO 27001Incident Response
- Regularly monitor, triage, and prioritize vulnerabilities in third-party dependencies, libraries, and frameworks. - Analyze security findings from SAST, DAST, and SCA tools (such as SonarQube, Checkmarx, OWASP ZAP, and Dependabot). - Implement and automate processes for dependency updates, vulnerability detection, and remediation within CI/CD pipelines and container environments (like OpenShift). - Document vulnerability assessments, remediation activities, and compliance evidence using tools like Jira and vulnerability management platforms. - Develop and enforce secure coding guidelines, dependency management standards, and best practices. - Report on vulnerability status, remediation progress, and risk trends to stakeholders and security leadership. - Support incident response related to critical vulnerabilities, including zero-day exploits and high-severity CVEs. - Ensure adherence to internal policies and external regulations (such as ISO 27001, NIST, GDPR, and SOC 2). - Familiarity with cloud security principles (AWS, Azure, GCP) and container security practices. - Professional certifications such as CISSP, OSCP, CEH, or CCSP. - Experience with vulnerability management platforms (Tenable, Qualys, Rapid7) and compliance standards. - Experience: Minimum of 3 years of expertise in software security, vulnerability management, or related fields. - Tools & Technologies: - Vulnerability detection and management tools (SAST, DAST, SCA such as SonarQube, Checkmarx, OWASP ZAP, and Dependabot). - Dependency management across multiple ecosystems (npm, Maven, pip, NuGet, or Go modules). - Container orchestration and security (OpenShift and Docker). - Version control systems (Git, GitHub) and issue tracking tools (Jira). - Skills & Knowledge: - Proficiency in scripting and automation (Python, Bash) for integrating security processes into CI/CD workflows. - Deep understanding of vulnerabilities (OWASP Top 10, CWE) and CVSS scoring methodology. - Experience implementing security best practices within DevOps pipelines and cloud environments. - Strong analytical and problem-solving skills. - Familiarity with cloud security principles (AWS, Azure, GCP) and container security practices. - Professional certifications such as CISSP, OSCP, CEH, or CCSP. - Experience with vulnerability management platforms (Tenable, Qualys, Rapid7) and compliance standards. English is a must Barcelona