TRCI-26-05153
Vulnerability Remediation / Application Security Engineer (SAST/DAST/SCA, CI/CD, OpenShift)
Contract role supporting a vulnerability remediation program for ~10 development teams. You will triage and prioritize vulnerabilities in third-party dependencies, analyze SAST/DAST/SCA findings (SonarQube, Checkmarx, OWASP ZAP, Dependabot), and drive remediation with engineering teams. The work includes automating dependency updates and security workflows in CI/CD and OpenShift, documenting evidence in Jira, reporting risk trends, and supporting incident response for critical CVEs/zero-days. Hybrid in Barcelona (70%+ remote; onsite day one and ideally weekly), English mandatory; Spanish/French a plus; duration through end of 2026 with possible extension.
Position summary
- Location
- Spain
- Workplace
- On-site
- Employment
- Contract
- Experience
- Minimum 3 years and Maximum 8 years
Role overview
Why This Role Matters.
Contract role supporting a vulnerability remediation program for ~10 development teams. You will triage and prioritize vulnerabilities in third-party dependencies, analyze SAST/DAST/SCA findings (SonarQube, Checkmarx, OWASP ZAP, Dependabot), and drive remediation with engineering teams. The work includes automating dependency updates and security workflows in CI/CD and OpenShift, documenting evidence in Jira, reporting risk trends, and supporting incident response for critical CVEs/zero-days. Hybrid in Barcelona (70%+ remote; onsite day one and ideally weekly), English mandatory; Spanish/French a plus; duration through end of 2026 with possible extension.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Automate dependency updates, detection and remediation in CI/CD pipelines and OpenShift
Report vulnerability status, remediation progress and risk trends to stakeholders
Support incident response on critical vulnerabilities (zero-days, high-severity CVEs)
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
Vulnerability remediation
Vulnerability management
Application Security
AppSec
SAST
DAST
SCA
CVE
CVSS
SonarQube
Checkmarx
OWASP ZAP
Dependabot
Red Hat Advanced Cluster Security
RHACS
OpenShift
CI/CD
Jira
npm
Maven
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
Vulnerability remediation and vulnerability management (3+ years)
Software security / application security fundamentals
Triage and prioritization of vulnerabilities (CVE/CVSS concepts)
SAST tooling: SonarQube
SAST tooling: Checkmarx
DAST tooling: OWASP ZAP
SCA/dependency scanning and updates: Dependabot
Dependency/package management across at least one of: npm, Maven, pip, NuGet, Go modules
Automation of security workflows in CI/CD pipelines
Container platform security workflow exposure (OpenShift mentioned)
Documentation and tracking in Jira
Fluent English
Preferred
Nice to Have
Cloud security (AWS, Azure, GCP)
Container security practices
Vulnerability management platforms: Tenable, Qualys, Rapid7
Compliance standards: ISO 27001, NIST, GDPR, SOC 2
Spanish (Barcelona)
French (Paris)
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Vulnerability Remediation / Application Security Engineer (SAST/DAST/SCA, CI/CD, OpenShift)
One page, about two minutes. We only ask for what we actually need to have a first conversation.