> Markdown version of [/jobs/ext/1938484-associate-security-engineer](https://www.wearedevelopers.com/jobs/ext/1938484-associate-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Associate Security Engineer - **Company:** Spendesk - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Bash Shell, Static Program Analysis, Code Review, Cyber Security, Continuous Integration, DevOps, Elasticsearch, Identity and Access Management, Python (Programming Language), Log Analysis, Open Web Application Security, Secure Coding, Web Application Security, Security Information and Event Management, Software Vulnerability Management, Scripting, Okta, Gsuite, Terraform, Elk Stack, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://www.buscojobs.com.es/associate-security-engineer-en-madrid-ID-365561089 ## About the Role Must?haves: Foundational experience in security engineering, SOC, or a DevOps/SRE role with a strong security focus, eager to deepen across the security stack. Solid understanding of web application security (OWASP Top 10, common attack vectors). Hands?on experience with at least two of: vulnerability scanning tools, SIEM/log analysis, IAM systems (Okta, Google Workspace), or CI/CD security tooling. Comfortable scripting (Python, Bash, or similar) to automate repetitive security tasks. Collaborative mindset: you work across many teams and communicate security issues clearly and constructively. Rather than binary allowed/forbidden calls, you assess and articulate risk through a severity and likelihood lens, bringing teams along instead of acting as a blocker. Nice?to?haves: Experience with AWS security (IAM policies, Security Hub, GuardDuty). Familiarity with ElasticSearch / ELK stack. Exposure to infrastructure?as?code (Terraform) and container security. Knowledge of compliance frameworks (ISO *****, SOC 2, PCI?DSS): not as an auditor, but enough to understand why controls exist. Experience in fintech or a regulated environment. ## Description We're building a dedicated Security Engineering function.You'll join alongside a Senior Security Engineer and together form the operational security backbone of the engineering organisation.Your MissionYou'll be hands?on across vulnerability management, access controls, monitoring, and secure development support.You'll work closely with a Senior Security Engineer who'll mentor you and help you grow, while partnering day?to?day with Infrastructure and product engineering teams.This is a hands?on engineering role, not a dashboard?watching SOC seat or a governance one: you'll build, fix, and improve, while a separate team owns policy and risk frameworks.You'll learn fast and ship real security improvements from week one.If you like fixing things, digging into alerts, and making systems harder to break, you'll thrive here.You will sit at the intersection of two domains: as a security engineer, your impact will be directly measured by how effectively you translate second?line?of?defence guidance (from the Compliance and Regulatory team) into practice, while ensuring technical alignment and buy?in from the Product and Engineering organisation you are part of.Key ResponsibilitiesVulnerability & incident managementTriage vulnerabilities from our bug bounty program, scanners, and dependency checks.Support incident response: develop fixes, track resolution, update tickets, and contribute to post?mortems.Monitor and process security alerts from our SIEM and other monitoring tools.Identity & access managementImplement and maintain SSO/MFA configurations for product and infrastructure systems, leveraging Okta and Google Workspace to manage downstream access rights.Implement roles and access rights per tool and system.Run periodic permission reviews and access audits.Manage production secrets and credential rotation.Secure development support and toolingRun pre?deployment security checks: static analysis, dependency scanning, container image scanning.Flag issues in code reviews when security patterns are violated.Help engineers understand and fix security findings.Monitoring & detectionMonitor SIEM alerts, investigate suspicious activity, and elevate when needed.Maintain and tune detection rules under guidance from the Senior Security Engineer.Help operate and maintain SIEM infrastructure (ElasticSearch, log collection pipelines).Security operationsSupport pentest coordination: prepare test environments, track remediation items.Maintain documentation on security procedures and runbooks.What We're Looking ForMust?haves:Foundational experience in security engineering, SOC, or a DevOps/SRE role with a strong security focus, eager to deepen across the security stack.Solid understanding of web application security (OWASP Top 10, common attack vectors).Hands?on experience with at least two of: vulnerability scanning tools, SIEM/log analysis, IAM systems (Okta, Google Workspace), or CI/CD security tooling.Comfortable scripting (Python, Bash, or similar) to automate repetitive security tasks.Collaborative mindset: you work across many teams and communicate security issues clearly and constructively.Rather than binary allowed/forbidden calls, you assess and articulate risk through a severity and likelihood lens, bringing teams along instead of acting as a blocker.Nice?to?haves:Experience with AWS security (IAM policies, Security Hub, GuardDuty).Familiarity with ElasticSearch / ELK stack.Exposure to infrastructure?as?code (Terraform) and container security.Knowledge of compliance frameworks (ISO *****, SOC 2, PCI?DSS): not as an auditor, but enough to understand why controls exist.Experience in fintech or a regulated environment.About Our BenefitsFlexible on?site and remote policyLatest Apple equipment - the tools you need to excelAccess to Moka.care - for emotional and mental health wellbeingGreat office snacks - to fuel your dayA positive team to work with daily!We also offer location?specific benefits tailored to each market, including health insurance, wellness allowances, commuter support, meal vouchers, and gym memberships - ensuring you're well supported wherever you're based.#J-*****-Ljbffr ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)