Security Engineer

Bynder
Spain
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Java (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Software System Penetration Testing Software as a Service Cloud Computing Security Cloud Engineering DevOps Github Identity and Access Management Python (Programming Language)
+11 more
Open Web Application Security Scala (Programming Language) Web Applications Cloud Platform System Software Security Amazon Virtual Private Cloud (VPC) Kubernetes Terraform Devsecops Static Application Security Testing Dynamic Application Security Testing

Requirements

tracking. Own and evolve our cloud security posture across our AWS environment, working with Wiz (CSPM, CNS, Code, AI Security) to drive risk prioritization, misconfiguration remediation, and shift-left security workflows. Champion security controls within our CI/CD pipelines, from IaC scanning and SAST integration to secure deployment practices, working closely with DevOps and development teams. Translate compliance requirements (SOC2, ISO 42001, GDPR) into concrete technical controls and act as a technical point of contact for customer security discussions, questionnaires, and enterprise onboarding. 3-7 years of hands-on experience in application security, cloud security (AWS), or a broad security engineering role. ~ Proven experience conducting penetration tests on web applications, APIs, and/or cloud environments, with a solid grip on OWASP Top 10 and common vulnerability classes. ~ Solid understanding of AWS security: IAM, VPC design, cloud-native architecture and a clear intuition for what secure cloud infrastructure looks like. ~ Familiarity with application security testing tools (SAST, DAST) and a practical understanding of DevSecOps: you know where to plug in and how to make it stick with developers. ~ Write security scripts, tinker with tools, or keep a personal GitHub with automation or research projects. Have experience with Terraform or IaC security scanning. Have hands-on experience with Kubernetes and container security. Python, Java, Scala) and can read and reason about code to support security reviews What’s in it for you? Real breadth and ownership across a modern, cloud-native security stack across a high-growth SaaS platform. Flexibility to work from home, with weekly office time in Rotterdam and Amsterdam. LI-Hybrid #LI-MF1

About the company

At Bynder, we don’t just store creative assets; we enable brands to deliver exceptional content experiences that drive business impact. In an era of exploding content volume and complexity, the world’s most iconic brands, including ā€œSpotify, Campari, and Lacosteā€ , trust Bynder as their single source of truth for creative content . Our industry-leading DAM platform serves as the strategic engine for brand governance and control. We are leading the shift from management to AI-powered content orchestration . By integrating human-led, customizable AI Agents directly into our enterprise-grade infrastructure, we enable brands to augment their workforce and intelligently automate high-effort workflows without sacrificing brand integrity. We turn creative content into intelligent assets that accelerate personalization and drive measurable business outcomes. Ready to grow your career by helping the world’s leading brands deliver exceptional content experiences? Join our global team of 600+

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on es.trabajo.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira Ā· Coffee With Developers

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum Ā· WWC Europe 2026

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters Ā· WWC 2023

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil Ā· LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia Ā· LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes Ā· WWC 2025

Videos

See all

Related articles

See all