> Markdown version of [/jobs/ext/1597812-security-engineer](https://www.wearedevelopers.com/jobs/ext/1597812-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Vivid - **Location:** Barcelona, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Information Leak Prevention, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Multi-Factor Authentication, Github, Intrusion Detection and Prevention, Virtual Private Networks (VPN), OpenID, Phishing, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Okta, Spoofing, Sumo Logic (Software), Gsuite, Splunk - **Published:** July 16, 2026 - **Apply:** https://www.jobleads.com/es/job/eda385caa426bff38980211c5b6ebe663 ## About the Role * 5+ years in security operations, corporate/IT security, or endpoint engineering. * Strong with a SIEM (Splunk, Elastic, Panther, Sumo Logic) - detection engineering and incident response - plus an identity provider (Okta, Entra ID, Google Workspace), access recertification, and least-privilege / PAM. * Working knowledge of endpoint security (MDM, XDR/EDR/AV) and email / phishing defense. * Practical experience securing how a company uses AI internally: shadow AI discovery, DLP for AI tools, controls for AI assistants and agents, and a working risk framework for adopting new ones. You've done this for real, not from a vendor pitch deck. * Strong scripting and automation skills - you build tooling against APIs, not just configure consoles. * Track record of driving improvements end-to-end and leading initiatives with little oversight. * Сlear written and spoken English for engineers and leadership. ## Description We're looking for a Security Engineer to own and improve the security of our internal environment - the identities, SaaS apps, endpoints, AI tooling, and networks our employees use every day. This is a hands-on senior role: we expect you to design controls, find the gaps, and drive the changes that close them - and to build the automation that makes it scale. We're an EMI-licensed fintech in a fully cloud-native AWS environment, we use AI heavily, and we're growing fast. We need someone who can lead technical initiatives independently, influence our security architecture, challenge approaches that no longer fit, and explain it clearly to engineers and leadership. Your Mission Detection & Response (SIEM) - our top priority * Own SIEM alerting end-to-end: ship logs from endpoints, IdP, VPN, SaaS, and cloud; write and tune detection rules; cut false positives. * Act as first responder for security incidents - investigate, contain, drive to closure with clear runbooks - and feed recurring issues back into preventive controls. Identity, Access & SaaS * Administer the IdP (SSO via SAML/OIDC, MFA, conditional access) and run access recertification end-to-end across IdP, SaaS, AWS, and internal tools - scope, evidence, follow-through on revocations. * Hunt down over-permissive and stale access, enforce least privilege and PAM, catch SoD gaps, and make JML and third-party access work in practice. * Improve SaaS security posture (Google/Microsoft, Slack, GitHub, others) and apply DLP controls to limit data leakage. Endpoint, Email & Phishing Defense * Keep the endpoint stack healthy and well-tuned - MDM, XDR/AV, device-compliance checks for VPN/ZTNA - and define posture requirements (disk encryption, EDR present, OS version) with automated remediation. * Defend against phishing and spoofing - secure email gateway rules, DMARC/SPF/DKIM - and run phishing simulations and security awareness, acting on the results. Automation & Ownership * Build internal tooling and automate repetitive operations - reduce manual work, don't just operate it. * Own the roadmap for your areas: identify gaps, lead initiatives independently, and raise the bar rather than just maintain it. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)