Vulnerability Management Engineer – Application Security (Mid-Level)

Stellenbeschreibung:

Vulnerability Management Engineer – Application Security (Mid-Level)

Location: Valencia, Spain or LATAM – 100% onsite in Valencia, 100% remote in LATAM.

Working Hours: U.S. Eastern Time (9:00AM – 5:00PM ET).

Role Overview

We are seeking a mid‑level engineer to identify, manage, and remediate application vulnerabilities throughout the software development lifecycle. This role plays a key part in maintaining our security posture across web, mobile, and cloud‑based applications.

Key Responsibilities

  • Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
  • Validate scanner results, perform false‑positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
  • Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
  • Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
  • Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
  • Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
  • Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
  • Support threat modeling and application risk assessments, focusing on discovering insecure design patterns.
  • Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
  • Provide input into policies and standards related to application and cloud security controls.

Required Qualifications

  • Bachelor’s Degree in Information Technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
  • 5–7 years of relevant experience in application security and/or vulnerability management.
  • Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
  • Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
  • Hands‑on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
  • Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
  • Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
  • Excellent documentation, communication, and stakeholder engagement skills.

Preferred Qualifications & Certifications

  • Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
  • Experience using the ServiceNow platform for vulnerability or incident tracking.
  • Proficiency in Azure cloud and Azure DevOps environments.
  • Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non‑technical stakeholders.

NTT Data is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action‑Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. NTT Data is an Equal Opportunity Employer Male/Female/Disabled/Veteran and a VEVRAA Federal Contractor.

#J-18808-Ljbffr
NOTE / HINWEIS:
EnglishEN: Please refer to Fuchsjobs for the source of your application
DeutschDE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung

Stelleninformationen

  • Veröffentlichungsdatum:

    24 Jul 2026
  • Standort:

    Remote
  • Typ:

    Vollzeit
  • Arbeitsmodell:

    Vor Ort
  • Kategorie:

  • Erfahrung:

    2+ years
  • Arbeitsverhältnis:

    Angestellt

KI Suchagent

AI job search

Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!

Diese Jobs passen zu Deiner Suche:

partner ad:Stepstone partner
Vollzeit Deggendorf
22 Jul 2026Development & IT
partner ad:Stepstone partner
Vollzeit Heidelberg
22 Jul 2026Development & IT
partner ad:Stepstone partner
Vollzeit Bundesweit
22 Jul 2026Development & IT
partner ad:Stepstone partner
Vollzeit Bremen
22 Jul 2026Development & IT
partner ad:Stepstone partner
Vollzeit Köln
22 Jul 2026Development & IT
partner ad:Stepstone partner
Vollzeit Deggendorf
22 Jul 2026Development & IT
partner ad:Stepstone partner
Vollzeit Putzbrunn
22 Jul 2026Development & IT
partner ad:Stepstone partner
Vollzeit Hannover
23 Jul 2026Development & IT