Ubique Systems

TRCI-26-05153

Vulnerability Remediation / Application Security Engineer (SAST/DAST/SCA, CI/CD, OpenShift)

Contract role supporting a vulnerability remediation program for ~10 development teams. You will triage and prioritize vulnerabilities in third-party dependencies, analyze SAST/DAST/SCA findings (SonarQube, Checkmarx, OWASP ZAP, Dependabot), and drive remediation with engineering teams. The work includes automating dependency updates and security workflows in CI/CD and OpenShift, documenting evidence in Jira, reporting risk trends, and supporting incident response for critical CVEs/zero-days. Hybrid in Barcelona (70%+ remote; onsite day one and ideally weekly), English mandatory; Spanish/French a plus; duration through end of 2026 with possible extension.

Position summary

Location
Spain
Workplace
On-site
Employment
Contract
Experience
Minimum 3 years and Maximum 8 years
Apply now

Role overview

Why This Role Matters.

Contract role supporting a vulnerability remediation program for ~10 development teams. You will triage and prioritize vulnerabilities in third-party dependencies, analyze SAST/DAST/SCA findings (SonarQube, Checkmarx, OWASP ZAP, Dependabot), and drive remediation with engineering teams. The work includes automating dependency updates and security workflows in CI/CD and OpenShift, documenting evidence in Jira, reporting risk trends, and supporting incident response for critical CVEs/zero-days. Hybrid in Barcelona (70%+ remote; onsite day one and ideally weekly), English mandatory; Spanish/French a plus; duration through end of 2026 with possible extension.

Your Impact

Deliver Enterprise Value

Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.

Collaboration

Work Across Teams

Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.

Growth

Learn Continuously

Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.

Career Path

Grow With Ubique

Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.

Responsibilities

What You'll Be Doing.

Every role at Ubique contributes directly to solving meaningful business challenges for our clients.

01

Triage and prioritize vulnerabilities in third-party dependencies, libraries and frameworks

02

Automate dependency updates, detection and remediation in CI/CD pipelines and OpenShift

03

Report vulnerability status, remediation progress and risk trends to stakeholders

04

Support incident response on critical vulnerabilities (zero-days, high-severity CVEs)

Technology stack

Tools & Technologies.

The platforms and technologies you'll use to build modern, enterprise-grade solutions.

01

Vulnerability remediation

02

Vulnerability management

03

Application Security

04

AppSec

05

SAST

06

DAST

07

SCA

08

CVE

09

CVSS

10

SonarQube

11

Checkmarx

12

OWASP ZAP

13

Dependabot

14

Red Hat Advanced Cluster Security

15

RHACS

16

OpenShift

17

CI/CD

18

Jira

19

npm

20

Maven

Requirements

Skills & Experience.

We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.

Essential

Required Qualifications

Vulnerability remediation and vulnerability management (3+ years)

Software security / application security fundamentals

Triage and prioritization of vulnerabilities (CVE/CVSS concepts)

SAST tooling: SonarQube

SAST tooling: Checkmarx

DAST tooling: OWASP ZAP

SCA/dependency scanning and updates: Dependabot

Dependency/package management across at least one of: npm, Maven, pip, NuGet, Go modules

Automation of security workflows in CI/CD pipelines

Container platform security workflow exposure (OpenShift mentioned)

Documentation and tracking in Jira

Fluent English

Preferred

Nice to Have

Cloud security (AWS, Azure, GCP)

Container security practices

Vulnerability management platforms: Tenable, Qualys, Rapid7

Compliance standards: ISO 27001, NIST, GDPR, SOC 2

Spanish (Barcelona)

French (Paris)

What you'll gain

More Than Just A Job.

We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.

Global Exposure

Collaborate with international clients and multicultural teams on enterprise programmes.

Continuous Learning

Expand your expertise through mentoring, certifications and hands-on project experience.

Career Growth

Take ownership, develop leadership skills and grow your consulting career over time.

Flexible Working

Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.

People First

Join a supportive culture where collaboration, respect and long-term relationships come first.

Enterprise Projects

Work on meaningful technology initiatives for leading organisations across industries.

Apply

Apply for Vulnerability Remediation / Application Security Engineer (SAST/DAST/SCA, CI/CD, OpenShift)

One page, about two minutes. We only ask for what we actually need to have a first conversation.

Your CV

Optional. A line or two is plenty.