> Markdown version of [/jobs/ext/1683029-cyber-security-specialist-blue-team](https://www.wearedevelopers.com/jobs/ext/1683029-cyber-security-specialist-blue-team). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Specialist Blue Team - **Company:** Hbx Group - **Location:** Valencia, Spain - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Static Program Analysis, Cyber Security, Information Leak Prevention, DevOps, Intrusion Detection and Prevention, Cloud Services, Red Team (Cyber Security), Zero Trust Network Access, Secure Coding, Software Engineering, Software Vulnerability Management, Google Cloud, Cloud Platform System, Large Language Models, Software Security, Generative AI, Containerization, AI Platforms, Kubernetes, Cybercrime, Machine Learning Operations, Devsecops, Docker, Security Orchestration, Automation & Response, Vulnerability Analysis, Programming Languages - **Published:** July 14, 2026 - **Apply:** https://www.jobleads.com/es/job/ec8a84ca207a351c4ee5d6fad67b4a883 ## About the Role * Previous experience in a cyber security role, technology delivery role or equivalent security-focused position. * Strong understanding of threat modelling, cyber risk assessment and security analysis techniques. * Up-to-date knowledge of current cyber security threats, best practices, technologies and defensive techniques. * Experience with vulnerability management, including vulnerability assessment, prioritisation and remediation coordination. * Knowledge of incident response processes, including investigation, analysis and timely response activities. * Experience or working knowledge of secure software development practices and source code security analysis. * Good understanding of DevOps and Agile principles, with the ability to support security practices in fast-moving delivery environments. * Knowledge of cloud and container technologies, including Kubernetes, Docker and cloud environments such as AWS, GCP or Azure. * Experience using programming languages and/or security automation tools to improve security operations and detection capabilities., * Ability to translate technical security findings into clear risk-based recommendations. * Strong analytical mindset, with the ability to investigate complex issues and prioritise actions based on impact. * Good collaboration skills, with the ability to work effectively with Security, Engineering, DevOps and infrastructure teams. * Proactive approach to learning and staying current with emerging threats, attack techniques and security technologies. * Ability to balance security requirements with delivery needs in agile and cloud-based environments., * Ownership and accountability when managing security findings, incidents or remediation activities. * Clear communication style, especially when explaining technical risks to non-security stakeholders. * Continuous improvement mindset, with a focus on strengthening security processes and operational efficiency. * Team-oriented approach and willingness to collaborate across technical and business areas. ## Description The Blue Team Security Expert is responsible for the continuous protection, monitoring, assessment and improvement of HBX Group's security posture across corporate, cloud, application, and AI-enabled environments. The role combines threat detection, incident response, threat hunting, vulnerability management, security automation, and proactive security engineering. The successful candidate will work closely with Red Team, Security Architecture, DevOps, Engineering, Data, and AI teams to identify, prevent, detect and respond to cyber threats. * Identify, investigate and analyse cyber security threats affecting services, platforms and development environments. * Assess the potential impact of detected threats and support the definition of effective remediation actions. * Perform continuous technology watch to stay up to date with industry trends, emerging attack techniques, best practices and relevant security developments. * Collaborate with Red Team activities to validate findings, improve detection capabilities and enhance the overall security posture. AI Security & Emerging Threats * Assess risks related to Generative AI, Large Language Models (LLMs), AI agents, and machine learning systems. * Identify and mitigate threats such as: * AI supply chain attacks * Sensitive data leakage through AI platforms * Shadow AI usage * Partner with AI and Data teams to implement secure-by-design AI solutions. * Contribute to AI governance, monitoring, and security controls. * Stay up to date on emerging AI security frameworks and industry best practices., * Monitor, assess and prioritise vulnerabilities across applications, infrastructure, cloud environments and containerised platforms. * Evaluate the severity, exploitability and potential business impact of vulnerabilities to support risk-based remediation planning. * Work with technology, infrastructure and development teams to coordinate remediation activities and track progress. * Contribute to the continuous improvement of vulnerability management processes, reporting and prioritisation criteria. * Support and enhance security controls across AWS, Azure and GCP environments. * Monitor cloud-native security services and investigate cloud security incidents. * Secure containerised environments, including Kubernetes and Docker platforms. * Assess infrastructure-as-code and cloud deployments for security weaknesses. * Contribute to Zero Trust and cloud security initiatives. * Participate in security incident response activities, including investigation, analysis, containment support and timely response. * Contribute to the identification of root causes and support the definition of corrective and preventive actions. * Work with relevant teams to ensure lessons learned from incidents are translated into security improvements., * Support agile delivery teams by embedding security practices into development and delivery processes. * Provide guidance on secure development, code analysis and security testing across different platforms, environments and instances. * Help improve the organisation's capability to identify and remediate vulnerabilities in source code. * Promote the use of security automation tools to improve scalability, consistency and efficiency in security activities. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)