> Markdown version of [/jobs/ext/1618520-security-engineer](https://www.wearedevelopers.com/jobs/ext/1618520-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Joppy - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Computer Programming, Django Web Framework, Identity and Access Management, Python (Programming Language), PostgreSQL, Open Web Application Security, Phishing, Secure Coding, Security Software, Software Engineering, TypeScript, Software Vulnerability Management, Working Model 2D, Google Cloud, ReactJS, Grafana, Software Security, Kubernetes, Gsuite, Front End Software Development, Terraform, Elk Stack, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** July 27, 2026 - **Apply:** https://www.jobleads.com/es/job/eae69153f2237a3c475ccca17089778b0 ## About the Role * 5+ years of experience in security engineering, infrastructure security, or security software engineering * Hands-on expertise with AWS or GCP security (IAM, security groups, WAF, etc.) * Deep understanding of application security (OWASP Top 10, secure coding, API security) * Experience building security programs from the ground up in high-growth environments * Track record in incident response and handling data breach scenarios * Programming skills in at least one language: Python, TypeScript, or Golang * Experience training employees on security best practices, * Experience with GDPR compliance and data protection regulations * Background in penetration testing or offensive security * Familiarity with Django, React, PostgreSQL, Terraform * Experience responding to security questionnaires for enterprise sales * Knowledge of SOC2 or ISO27001 implementation * Vibrant office environment with complimentary drinks and snacks ## Description * Enable the sales team to effectively answer security questionnaires for enterprise clients * Work collaboratively within the SRE team, partnering with software engineering and other department leaders * Reduce business risk by proactively preventing and responding to security incidents in a fast-scaling environment What you'll do * Security Engineering (60%)Harden AWS infrastructure, Kubernetes clusters, and application security * Implement automated scanning (SAST/DAST) and dependency checks * Strengthen authentication and identity management (SSO, MFA, Google Workspace) * Set up vulnerability management and alerting, integrated with engineering sprints * Respond to security incidents, create runbooks, and support customer security requests * Security Culture & Training (40%)Develop and deliver engaging, role-specific training; run phishing simulations * Define and enforce hardware and endpoint security standards * Build a network of security champions and create self-service security guides * Create pragmatic policies and governance that balance security with business needs * AWS * Infrastructure as Code: Terraform, Helm * Monitoring: Grafana, ELK stack * Frontend: React, TypeScript ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [5 steps for running a Kubernetes environment at scale](https://www.wearedevelopers.com/videos/88-5-steps-for-running-a-kubernetes-environment-at-scale) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Super scaling for the Super Bowl: How to survive 30 million users hitting your backend in 30 minutes](https://www.wearedevelopers.com/videos/100356-super-scaling-for-the-super-bowl-how-to-survive-30-million-users-hitting-your-backend-in-30-minutes) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [All your telemetry data from any source in one place](https://www.wearedevelopers.com/videos/57-all-your-telemetry-data-from-any-source-in-one-place) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)