> Markdown version of [/jobs/ext/2099291-security-engineer-ciso](https://www.wearedevelopers.com/jobs/ext/2099291-security-engineer-ciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer & Ciso - **Company:** Ledn - **Location:** Chantada, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Business Logic, Software System Penetration Testing, User Authentication, Bash Shell, Cloud Computing, Cyber Security, System Configuration, Continuous Integration, Domain Name System (DNS), Github, Identity and Access Management, Python (Programming Language), Security Information and Event Management, TypeScript, Software Vulnerability Management, Web Applications, Policy as Code, Data Logging, Software Security, Rate Limiting, Production Code, Cloudflare, Terraform, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** August 18, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role 5+ years in security engineering, application/product security, or software/platform engineering with a demonstrable security focus. Hands-on penetration testing across web applications, APIs, and cloud infrastructure, producing clear, reproducible findings and validating fixes. Production code review skills in JavaScript/TypeScript, Python, Go, or similar, with practical knowledge of authentication, authorization, injection, data exposure, and business-logic risks. Threat modeling and secure design experience that turns ambiguous risks into actionable engineering requirements and defensible architecture decisions. Strong AWS security expertise in multi-account environments, including IAM, networking, KMS, logging/detection services, and workload configuration. Cloudflare or similar edge-security experience covering WAF, rate limiting, bot management, DNS/TLS, and access controls. GitHub and CI/CD security experience with branch protection, review workflows, repository rules, workflow permissions, token hygiene, and secure automation. Secure SDLC tooling knowledge - SAST, DAST, software composition analysis, secret scanning, container scanning - and how to tune controls so engineers act on results. Software supply-chain and IaC security, including dependency/artifact risks and reviewing Terraform, Helm, or similar configuration for security gaps. Automation skills in Python, Bash, Go, or JavaScript to extend testing, analyze evidence, and build lightweight security tooling. Vulnerability lifecycle ownership, from risk-based triage and remediation targets through retesting, closure, and useful metrics. Experience in a fintech/regulated environment where audit trails, evidence quality, data protection, and cross-functional partnership matter. Fluent English and Spanish, able to explain a technical finding to an engineer and its business risk to senior stakeholders, given this role's CNMV and Board-facing responsibilities. DORA and regulatory governance experience in a European financial-services environment - ICT risk management frameworks, digital operational resilience testing. ICT third-party registers, and acting as a regulator/Board point of contact; CNMV experience is a strong plus. Must be willing to undergo applicable background checks, per local law, if selected. Preferred: Offensive security depth via OSCP, OSWE, comparable certification, research, responsible disclosures, or a strong portfolio. Digital-asset/fintech/payments security experience, especially with account-takeover, fraud-adjacent, custody, or transaction-integrity threat models. Detection and response engineering using cloud telemetry, SIEM tooling, or attack simulation to build actionable detections and playbooks. Vulnerability disclosure or bug bounty experience triaging researcher reports, managing communication, and coordinating fixes and retests. MiCA familiarity or other EU digital-asset regulatory frameworks, alongside core DORA expertise. Experience working in GDPR/SOC regulated environments. Culture Fit: Bring a builder's mindset, comfortable creating, adapting, and iterating as the business and the role evolve Be a collaborative partner, able to influence across functions and cultures with empathy and clarity Demonstrate integrity and accountability, especially in managing confidential information across multiple teams Be comfortable owning a complex area end to end and moving fast under pressure, especially when priorities shift or the path forward isn't fully mapped out yet ## Description Sr. Security Engineer Core Responsibilities: Secure Design & Threat Modeling : Lead security reviews for new designs and existing features, translating threats into concrete engineering requirements before production. Penetration Testing: Plan and execute hands-on testing of web apps, APIs, mobile-facing services, and infrastructure; document reproducible findings, validate remediation, and coordinate independent assessments. Adversarial Validation: Run red-team and purple-team exercises around realistic attack paths; work with defenders to improve preventive controls, telemetry, detections, and response playbooks. Secure Pull Requests: Define risk-based security standards for pull requests, including review requirements and tuned merge gates for secret scanning, SAST, dependency review, and sensitive-code ownership. Product & API Security : Review production code and architecture for vulnerabilities in authentication, authorization, session handling, data protection, and business logic; help teams fix root causes, not just symptoms. AWS Security: Assess and harden our multi-account AWS environment across IAM, network boundaries, encryption, logging, workload identity, and service configuration, using automation and policy-as-code where practical. Cloudflare Security: Review and harden WAF rules, rate limiting, bot controls, DNS/TLS configuration, edge access policies, and change governance without disrupting legitimate client traffic. GitHub & Software Supply Chain: Own security governance for repositories and CI workflows - branch protection, CODEOWNERS, least-privilege tokens, pinned actions, dependency controls, artifact integrity, and guardrails for AI-assisted code. Vulnerability Management: Triage findings from internal testing, scanners, third-party assessments, and disclosures; set risk-based remediation targets, track issues to closure, retest fixes, and report trends. Incident Readiness & Security Enablement: Support security investigations, tabletop exercises, and post-incident hardening while providing secure patterns, guidance, and security-champion support so engineering teams can move safely at scale. CISO, Ledn Spain Entity Core Responsibilities: Cybersecurity Framework & Board Reporting : Own the local Information Security Framework and ICT Risk Register; report periodically to the Board on information security and ICT risk; ensure immediate reporting of major incidents to Management and the Board. DORA Governance & Compliance : Direct the ICT Risk Management Framework and sign off its annual regulatory report; oversee the annual digital operational resilience testing programme (system/network testing plus BCP/DRP exercises); validate the ICT third-party register for CNMV submission. Regulatory & Audit Liaison : Serve as point of contact for the CNMV and external auditors on information security and DORA matters, in Spanish, including CNMV notification of significant incidents within DORA deadlines. Security Operations Oversight: Supervise vulnerability management and day-to-day technical security operations, escalating critical vulnerabilities and driving remediation with the ICT team. ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Empowering Developer Innovation - Balancing Speed, Security, and Scale](https://www.wearedevelopers.com/videos/1689-empowering-developer-innovation-balancing-speed-security-and-scale) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)