Senior Vulnerability Engineer - Barcelona - Hybrid work model

Michael Page España·Barcelona

Qué ofrecen

  • Contrato de duración determinada

    Según la oferta.

  • Híbrido

    Días de oficina y de casa — el reparto está en la oferta.

Qué piden

  • Trabajo en inglés

    Se requiere inglés, según la oferta.

  • Estés cerca de Barcelona para los días híbridos

    No se menciona ninguna ayuda para la mudanza.

  • Tengas 5+ años de experiencia

    Puesto de nivel Senior.

Extraído automáticamente de la oferta — lo que cuenta es el anuncio completo.

Añadida hace 9 días
Leer la oferta completa

Requisitos

We are looking someone with at least 5-8 years of experience, with a solid foundation in vulnerability management, recent pentesting, automation (Python, Go, or others), and strong communication skills. Working in a small, highly horizontal senior InfoSec team in an international environment (English required) and a hybrid model (1-2 days in the office). The role is highly hands-on and autonomous, focused on managing end-to-end vulnerabilities (identification, analysis, prioritization, and monitoring), executing full internal penetration testing, and automating security processes (scripts, integrations, use of AI) in cloud environments (primarily AWS) and CI/CD (GitHub), collaborating closely with other teams to explain risks and coordinate remediation (incident management is handled by others).

Beneficios

Hybrid and flexible work model

Chances to extend the partnership

Attractive salary conditions

Oferta original

Resumen

We are seeking a Senior Security Engineer specializing in Vulnerability Management for a 12-month project (with potential extension) in Barcelona.
  • Attractive salary package
  • Really power team in a top company

¿Dónde vas a trabajar?

Multinational Tech company

Descripción

Reporting to the Manager of this division, your main responsibilities will be:

Operate the vulnerability management platform and associated processes, including maintaining asset inventories, coordinating validations and retests, supporting detection tuning, delivering metrics and runbooks that empower engineering teams to remediate efficiently, and engaging with product and platform stakeholders to facilitate triage, clarify ownership and coordinate remediation activities;Design and engineer scalable, secure integration patterns and automation for the vulnerability management ecosystem, including APIs, service-account patterns, CI/CD pipelines, data schemas, observability and SLAs; you will build reusable integration components, document interfaces and hand off stable integration artifacts for others to consume;Operate offensive and assessment capabilities, perform vulnerability scanning and testing workflows, and run the bug-bounty / vulnerability disclosure life-cycle (triage, closure and retests);Conduct and evaluate internal penetration tests and red team exercises to validate controls, test detection and response, and produce actionable remediation guidance;Conduct deep technical vulnerability investigations, run threat-modelling sessions, coordinate countermeasure testing to validate mitigation's, and triage and prioritise findings with product and infrastructure teams;Ensure assets forward appropriate telemetry to central detection systems, help define detection rules, and convert intelligence and scan output into meaningful alerts and triage workflows;Act as a cross-team subject matter expert supporting other Security and engineering/product teams with remediation guidance, run-books and best practices.

¿A quién buscamos (H/M/D)?

We are looking someone with at least 5-8 years of experience, with a solid foundation in vulnerability management, recent pentesting, automation (Python, Go, or others), and strong communication skills. Working in a small, highly horizontal senior InfoSec team in an international environment (English required) and a hybrid model (1-2 days in the office). The role is highly hands-on and autonomous, focused on managing end-to-end vulnerabilities (identification, analysis, prioritization, and monitoring), executing full internal penetration testing, and automating security processes (scripts, integrations, use of AI) in cloud environments (primarily AWS) and CI/CD (GitHub), collaborating closely with other teams to explain risks and coordinate remediation (incident management is handled by others).

¿Cuáles son tus beneficios?

Hybrid and flexible work model

Chances to extend the partnership

Attractive salary conditions

Sobre la empresa

Michael Page España

Michael Page España

Staffing

Ver el perfil de la empresa
Empresa internacional

Michael Page España es una agencia de selección de personal.Seleccionan personal para empresas clientes, así que la empresa para la que trabajarías no aparece en esta oferta.