> Markdown version of [/jobs/ext/1909987-software-engineer-security](https://www.wearedevelopers.com/jobs/ext/1909987-software-engineer-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer (Security) - **Company:** Alan Sa. - **Location:** Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Continuous Integration, Github, Python (Programming Language), PostgreSQL, Redis, TypeScript, Software Vulnerability Management, Datadog, Okta, Large Language Models, Kubernetes, Cloudflare, Software Coding, Terraform - **Published:** August 4, 2026 - **Apply:** https://www.jobleads.com/es/job/ebe62f87719f930f260e2fbd5f50f73eb ## About the Role * 3+ years in full-stack software engineering roles * Experience designing systems, APIs, libraries, or frameworks used by other engineers * You've shipped, owned, and operated production systems (rollouts, on-call, incidents) * You've shipped secure features, fixed vulnerabilities, designed auth/crypto flows, or championed secure-by-default patterns in past teams * You love turning complex problems into elegant secure solutions * You care about creating secure-by-design products while keeping delightful experiences Mindset we value * You treat security engineering as product work: engineers and members are your customers, and security should feel effortless. * You're hands-on: writing code is the bulk of the job (Python, TypeScript, Terraform). You ship what you write to production yourself, then operate it: rollouts, alerting, on-call, incident response. * You design and communicate: you framing and diagrams, and align product crews on an auth migration as you code. You make complex security tradeoffs legible to non-security engineers. * You're an enabler: you measure your impact by how fast product crews ship secure features without ever consulting you. * You build reusable patterns: guardrails, libraries, and secure-by-default abstractions that prevent vulnerabilities at scale. * You're fluent in English (French is not required). ## Description Python/Flask, TypeScript, React, React Native, on the coding side. AWS, GCP, Kubernetes, Keycloak, PostgreSQL, Redis, Terraform/Terramate, Datadog, Cloudflare, GitHub Actions on the platform side, all in a monorepo. We deploy daily and believe in distributed ownership - you build it, you own it., 1. Authentication - design, build and operate the authentication stack on top of our self-hosted identity provider. Our goal is to go passwordless with great UX and unblock strategic initiatives relying on this stack. 2. Encryption - build, evolve and operate our end-to-end encryption component used by our Alan Clinic while keeping it delightful and frictionless for our members. 2. Security platforms 1. Secure file exchange - evolve and operate our secure file exchange platform to unblock product/ops teams while bringing support when relevant. 2. Secure enclave for medical secrecy - contribute to the foundations to isolate and protect highly sensitive medical data without sacrificing usability or delivery speed. 3. Contribute to engineering-wide security practices by building tools and patterns that help every engineer ship safely (secure CI/CD, vulnerability remediation tooling, AI/LLM safety, etc.). ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)