Security Engineer

ProntoPro
Barcelona, Spain
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Amazon Web Services Software System Penetration Testing Computer Programming Continuous Integration Django Web Framework Identity and Access Management Python (Programming Language) PostgreSQL Open Web Application Security RabbitMQ
+26 more
Redis Phishing Runbook Secure Coding Security Software Software Engineering TypeScript Software Vulnerability Management Working Model 2D Google Cloud ReactJS Grafana Software Security Fastapi Gitlab-ci Kubernetes Apache Kafka Celery Gsuite Front End Software Development Terraform Docker Elk Stack Static Application Security Testing Golang Dynamic Application Security Testing

Job description

A fitness and wellness management software company that we partner with at Joppy is looking to hire a Senior Security Engineer to lead the security transformation and build security foundations from scratch. Responsibilities - Protect the personal data of approximately 10 million users - Enable the sales team to effectively answer security questionnaires for enterprise clients - Work collaboratively within the SRE team, partnering with software engineering and other department leaders - Reduce business risk by proactively preventing and responding to security incidents in a fast-scaling environment ️ What you’ll do - Security Engineering (60%) Harden AWS infrastructure, Kubernetes clusters, and application security - Implement automated scanning (SAST/DAST) and dependency checks - Strengthen authentication and identity management (SSO, MFA, Google Workspace) - Set up vulnerability management and alerting, integrated with engineering sprints - Respond to security incidents

Requirements

create runbooks, and support customer security requests - Security Culture & Training (40%) Develop and deliver engaging, role-specific training; run phishing simulations - Define and enforce hardware and endpoint security standards - Build a network of security champions and create self-service security guides - Create pragmatic policies and governance that balance security with business needs Tech Stack - AWS - Infrastructure as Code: Terraform, Helm - Container orchestration: Kubernetes, Docker - Monitoring: Grafana, ELK stack - Backend: Python Django, FastAPI, Celery - Frontend: React, TypeScript - Databases: PostgreSQL, Redis, RabbitMQ, Kafka - CI/CD: GitLab CI, ArgoCD ️ Requirements - 5+ years of experience in security engineering, infrastructure security, or security software engineering - Hands-on expertise with AWS or GCP security (IAM, security groups, WAF, etc.) - Deep understanding of application security (OWASP Top 10, secure coding, API security) - Experience building security programs from the ground up in high-growth environments - Track record in incident response and handling data breach scenarios - Programming skills in at least one language: Python, TypeScript, or Golang - Experience securing infrastructure (Kubernetes, containers, IaC security) - Experience training employees on security best practices Nice to have - Experience with GDPR compliance and data protection regulations - Background in penetration testing or offensive security - Familiarity with Django, React, PostgreSQL, Terraform - Experience responding to security questionnaires for enterprise sales - Knowledge of SOC2 or ISO27001 implementation We offer - Vibrant office environment with complimentary drinks and snacks - Flexible hybrid working model with two remote days per week, plus 15 additional remote days per year - Health insurance fully covered - Discounted gym membership via Wellhub, with access to various gyms and wellbeing apps - Collaborative, international team - Paid sick leave to support your health About Joppy Joppy es una plataforma de reclutamiento tecnológico construida para developers por developers. No se requiere CV. Solo di lo que sabes y lo que quieres. Perfil anónimo por defecto. Tú eliges quién puede hablar contigo. Las empresas no pueden escribirte hasta que aceptes su oferta. Sólo ofertas relevantes que coincidan con tus preferencias. No más ofertas de Javascript para desarrolladores Java. Obtén una recompensa si te contratan. Echa un ojo a las oportunidades de empleo tecnológico de forma anónima y encuentra el trabajo que te haga feliz.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on es.trabajo.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

3:55 min

Demonstrating semantic routing thresholds with the Redis vector library

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

3:42 min

Comparing in-memory and Redis storage for cache scalability

Simone Sanfratello · WWC 2022

Videos

See all

Related articles

See all