About this role
Descripción del puesto / Funciones <ul><li><p>Regularly monitor, triage, and prioritize vulnerabilities in third-party dependencies, libraries, and frameworks.</p></li><li><p>Analyze security findings from SAST, DAST, and SCA tools (such as SonarQube, Checkmarx, OWASP ZAP, and Dependabot).</p></li><li><p>Implement and automate processes for dependency updates, vulnerability detection, and remediation within CI/CD pipelines and container environments (like OpenShift).</p></li><li><p>Document vulnerability assessments, remediation activities, and compliance evidence using tools like Jira and vulnerability management platforms.</p></li><li><p>Develop and enforce secure coding guidelines, dependency management standards, and best practices.</p></li><li><p>Report on vulnerability status, remediation progress, and risk trends to stakeholders and security leadership.</p></li><li><p>Support incident response related to critical vulnerabilities, including zero-day exploits and high-severity CVEs.</p></li><li><p>Ensure adherence to internal policies and external regulations (such as ISO 27001, NIST, GDPR, and SOC 2).</p></li></ul> Requisitos mínimos <ul><li><p>Familiarity with cloud security principles (AWS, Azure, GCP) and container security practices.</p></li><li><p>Professional certifications such as CISSP, OSCP, CEH, or CCSP.</p></li><li><p>Experience with vulnerability management platforms (Tenable, Qualys, Rapid7) and compliance standards.</p></li><li><p><b>Experience:</b> Minimum of 3 years of expertise in software security, vulnerability management, or related fields.</p></li><li><p><b>Tools & Technologies:</b></p><ul><li><p>Vulnerability detection and management tools (SAST, DAST, SCA such as SonarQube, Checkmarx, OWASP ZAP, and Dependabot).</p></li><li><p>Dependency management across multiple ecosystems (npm, Maven, pip, NuGet, or Go modules).</p></li><li><p>Container orchestration and security (OpenShift and Docker).</p></li><li><p>Version control systems (Git, GitHub) and issue tracking tools (Jira).</p></li></ul></li><li><p><b>Skills & Knowledge:</b></p><ul><li><p>Proficiency in scripting and automation (Python, Bash) for integrating security processes into CI/CD workflows.</p></li><li><p>Deep understanding of vulnerabilities (OWASP Top 10, CWE) and CVSS scoring methodology.</p></li><li><p>Experience implementing security best practices within DevOps pipelines and cloud environments.</p></li><li><p>Strong analytical and problem-solving skills.</p></li></ul></li></ul> Requisitos valorables <ul><li><p>Familiarity with cloud security principles (AWS, Azure, GCP) and container security practices.</p></li><li><p>Professional certifications such as CISSP, OSCP, CEH, or CCSP.</p></li><li><p>Experience with vulnerability management platforms (Tenable, Qualys, Rapid7) and compliance standards.</p></li></ul> Idiomas English is a must Ubicación Barcelona