> Markdown version of [/jobs/ext/1605226-platform-security-engineer](https://www.wearedevelopers.com/jobs/ext/1605226-platform-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Platform Security Engineer - **Company:** Jobgether - **Location:** Huelva, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Application Firewall, Software System Penetration Testing, Cyber Security, Customer Data Management, DDoS Mitigation, Elasticsearch, Fraud Prevention and Detection, Network Security, Log Analysis, OAuth, OpenID, Open Web Application Security, Openid Connect, Akamai, Standard Sql, Secure Coding, Session Management, Software Vulnerability Management, Cloud Platform System, Software Security, Cloudflare, Api Gateway - **Published:** July 31, 2026 - **Apply:** https://www.buscojobs.com.es/platform-security-engineer-en-huelva-ID-364160331 ## About the Role At least 5 years of experience in information security, including a minimum of 3 years focused on product security. Hands?on expertise managing Web Application Firewalls such as Wallarm, Akamai, or Cloudflare. Strong understanding of API security principles, including the OWASP API Security Top 10 and API gateway technologies. Experience implementing anti?bot solutions using behavioral analysis and fingerprinting techniques. Practical knowledge of DDoS protection across Layers 3?7 and modern network defense strategies. Experience managing vulnerability management programs, including CVSS scoring, remediation prioritization, and service level tracking. Familiarity with coordinating penetration testing engagements and interpreting security assessment reports. Solid understanding of OAuth, OpenID Connect (OIDC), JWT, session management, and modern authentication frameworks. Working knowledge of SQL and Elasticsearch for security investigations, log analysis, monitoring, and reporting. Strong analytical, communication, collaboration, and problem?solving skills with the ability to work effectively across distributed engineering teams. ## Description This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Platform Security Engineer based in Spain.As a Platform Security Engineer, you will play a key role in protecting large-scale digital products used by a global audience. Working across engineering, infrastructure, and security teams, you will strengthen platform defenses, safeguard customer data, and proactively address emerging threats. This position offers the opportunity to lead critical security initiatives, influence secure development practices, and improve incident response capabilities. You will contribute to building resilient systems while supporting a collaborative, security?first engineering culture. Ideal for an experienced security professional, this role combines hands?on technical work with strategic leadership in a dynamic, fast?paced environment.AccountabilitiesStrengthen and maintain perimeter and network security controls, including web application firewalls (WAF), rate limiting, anti-bot protections, and DDoS mitigation strategies.Secure APIs against abuse, malicious traffic, and common vulnerabilities while improving authentication, authorization, and access control mechanisms.Lead the vulnerability management lifecycle by identifying, prioritizing, tracking, and validating remediation of security issues.Coordinate external penetration testing engagements and ensure timely resolution of identified findings.Drive incident response activities for product security events and collaborate with monitoring teams to improve detection and response capabilities.Partner with cross?functional teams on fraud prevention, trust and safety initiatives, and customer data protection through encryption, masking, and secure access controls.Promote secure development practices by managing Security Champions and Bug Bounty programs while increasing security awareness across engineering teams.RequirementsAt least 5 years of experience in information security, including a minimum of 3 years focused on product security.Hands?on expertise managing Web Application Firewalls such as Wallarm, Akamai, or Cloudflare.Strong understanding of API security principles, including the OWASP API Security Top 10 and API gateway technologies.Experience implementing anti?bot solutions using behavioral analysis and fingerprinting techniques.Practical knowledge of DDoS protection across Layers 3?7 and modern network defense strategies.Experience managing vulnerability management programs, including CVSS scoring, remediation prioritization, and service level tracking.Familiarity with coordinating penetration testing engagements and interpreting security assessment reports.Solid understanding of OAuth, OpenID Connect (OIDC), JWT, session management, and modern authentication frameworks.Working knowledge of SQL and Elasticsearch for security investigations, log analysis, monitoring, and reporting.Strong analytical, communication, collaboration, and problem?solving skills with the ability to work effectively across distributed engineering teams.BenefitsCompetitive compensation, with salary details shared during the recruitment process.Flexible full?time working arrangement.28 days of annual paid vacation.7 additional wellness days each year for personal wellbeing and recovery.Employee referral bonuses of up to $5,000 for successful hires.Reimbursement covering 50% of approved professional training, conferences, and industry events.Corporate discounts for English language courses.Health benefit reimbursement of up to $1,000 gross per year for eligible medical expenses or private health insurance.Home office and workspace support, including equipment or reimbursement of up to $1,000 gross every three years for remote workspace setup.Internal employee recognition program with redeemable rewards, merchandise, wellness experiences, and team?building activities.#J-*****-Ljbffr ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What the Heck is Edge Computing Anyway?](https://www.wearedevelopers.com/videos/593-what-the-heck-is-edge-computing-anyway) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)