Security Engineer

Bynder's Security
Spain
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Software System Penetration Testing Cloud Computing Security Cloud Engineering DevOps Identity and Access Management Open Web Application Security Web Applications Cloud Platform System Software Security
+4 more
Amazon Virtual Private Cloud (VPC) Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

our CI/CD pipelines, from IaC scanning and SAST integration to secure deployment practices, working closely with DevOps and development teams. Support security incident response, investigation, containment guidance, and post-incident review and help mature our detection and response workflows over time. Translate compliance requirements (SOC2, ISO 42001, GDPR) into concrete technical controls and act as a technical point of contact for customer security discussions, questionnaires, and enterprise onboarding. Conduct vendor and third-party security risk assessments to protect our supply chain and advise on emerging AI/ML security risks as these technologies become more deeply embedded in our product. Share knowledge and raise the craft, you’ll naturally become a technical anchor for your teammate and a collaborative voice across engineering on what good security looks like in practice. What you bring 3-7 years of hands-on experience in application security, cloud security

Requirements

(AWS), or a broad security engineering role. Proven experience conducting penetration tests on web applications, APIs, and/or cloud environments, with a solid grip on OWASP Top 10 and common vulnerability classes. Solid understanding of AWS security: IAM, VPC design, cloud-native architecture and a clear intuition for what secure cloud infrastructure looks like. Familiarity with application security testing tools (SAST, DAST) and a practical understanding of DevSecOps: you know where to plug in and how to make it stick with developers. Strong communication skills, you can explain security risks clearly to both engineers and non-technical stakeholders, and you don’t default to “no” when there’s a smarter path forward. A growth mindset and genuine curiosity, you’re comfortable

Benefits & conditions

‘Byndies’ and help 4,000+ organizations work smarter with their content. Explore this opportunity and apply now to join our team. At Bynder, we believe security should never be an afterthought. We’re looking for a Security Engineer who thrives in a growth-oriented environment, someone who sees security as a starting point, not the finish line. If you’re hands-on by nature, energized by breadth, and serious about building security that actually scales in a cloud-native SaaS environment, you’ll feel right at home here. Meet the team We’re Bynder’s Security team: pragmatic, sharp, and relentlessly focused on enabling secure growth. We favor automation over repetition, integrations over point solutions, and smart security design over checkbox compliance. You’ll report directly to the VP Information Security and work alongside an Associate Security Engineer who brings strong application security and tooling chops. Together, you’ll cover the full security stack: AppSec, cloud, detection, and

About the company

At Bynder, we don’t just store creative assets; we enable brands to deliver exceptional content experiences that drive business impact. In an era of exploding content volume and complexity, the world’s most iconic brands, including Spotify, Campari, and Lacoste , trust Bynder as their single source of truth for creative content . Our industry-leading DAM platform serves as the strategic engine for brand governance and control. We are leading the shift from management to AI-powered content orchestration . By integrating human-led, customizable AI Agents directly into our enterprise-grade infrastructure, we enable brands to augment their workforce and intelligently automate high-effort workflows without sacrificing brand integrity. We turn creative content into intelligent assets that accelerate personalization and drive measurable business outcomes. Ready to grow your career by helping the world’s leading brands deliver exceptional content experiences? Join our global team of 600+, governance across a modern, cloud-native SaaS platform used by thousands of brands worldwide. Security at Bynder is a team sport. We work hand-in-hand with Platform teams, engineering, and business stakeholders to challenge assumptions, take calculated risks, and continuously raise the bar. It’s how we scale securely, and it’s part of how we win together. What you’ll do Plan and (help) execute penetration tests against web applications, APIs, and cloud infrastructure, and manage external pentest engagements including scoping, vendor coordination, and remediation tracking. Embed security across the full SDLC: leading threat modeling, security assessments, and vulnerability remediation in close collaboration with our engineering and product teams. Own and evolve our cloud security posture across our AWS environment, working with Wiz (CSPM, CNS, Code, AI Security) to drive risk prioritization, misconfiguration remediation, and shift-left security workflows. Champion security controls within

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on es.trabajo.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum ¡ WWC Europe 2026

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil ¡ LIVE

1:36 min

Running AI applications with PWAs and background web workers

Maxim Salnikov Maxim Salnikov ¡ WWC 2025

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia ¡ LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark ¡ LIVE

Videos

See all

Related articles

See all