> Markdown version of [/jobs/ext/2151849-security-engineer](https://www.wearedevelopers.com/jobs/ext/2151849-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Cataluña - **Location:** Barcelona, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Application Layers, Software System Penetration Testing, Microsoft Azure, Bash Shell, Software as a Service, Cloud Computing, Static Program Analysis, Code Review, Cyber Security, Data Centers, Python (Programming Language), Node.Js, Open Web Application Security, Secure Coding, Security Information and Event Management, Systems Integration, Datadog, Large Language Models, Software Security, Mitre Att&ck, Vue.js, Containerization, AngularJS, Kubernetes, NestJS, Software Coding, Terraform, Docker - **Published:** August 20, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role + 3+ years of professional experience in Application Security Operations within a high-growth SaaS or cloud-native environment. + Advanced proficiency in securing modern technical stacks, with specific expertise in NestJS, Vue.js, and Angular frameworks. + Hands-on experience with enterprise security tooling, including Snyk, Datadog ASM/AppSec (WAF), Google SecOps, and Crowdstrike. + Deep architectural understanding of AWS and Azure environments, including Kubernetes/Docker container security and Infrastructure as Code (Terraform). + Demonstrated ability to apply AI and LLM technologies to automate security tasks, such as automated vulnerability validation or code analysis at scale. + Expertise in scripting and development (Python, Node.js, Shell) to build custom security tooling and integrations. + Comprehensive knowledge of web protocols, OWASP Top 10, and advanced threat frameworks (MITRE ATT&CK, NIST CSF). + Proven track record in ethical hacking, CTF competitions, or bug bounty hunting, showcasing a high level of technical tenacity and analytical rigor. + Exceptional cross-functional collaboration skills, with the ability to articulate complex security risks to both technical and non-technical stakeholders. + Fluency in English is mandatory ## Description Contentsquare provides a globally leading SaaS service and commits to the highest security standards for its customers. We are ISO 27001 and ISO 27701 certified and maintain robust security initiatives (SOC 2 Type 2 report, private bug bounty program, SIEM, advanced security awareness, etc.). Working alongside other cybersecurity experts, your mission will be to ensure the security of Contentsquare's products and for keeping Contentsquare's users and customers safe. You will work out of our Barcelona office. What you'll do + Conduct continuous, automated security audits of our global SaaS applications to identify misconfigurations and ensure strict adherence to industry-standard security benchmarks and internal best practices. + Serve as a strategic security consultant to product and engineering teams, facilitating complex threat modeling sessions and AppSec reviews during the design phase to proactively mitigate risks. + Perform deep-dive, security-focused code reviews and mentor developers on secure coding patterns to minimize the introduction of high-impact vulnerabilities. + Architect and manage the end-to-end vulnerability lifecycle, developing sophisticated automation for the triage, reporting, and remediation tracking of security flaws across cloud infrastructure and application layers. + Orchestrate and optimize AI-driven security workflows, leveraging LLMs and autonomous agents to conduct scaleable, proactive vulnerability discovery and validation within our CI/CD pipelines. + Lead "Shift-Left" initiatives by integrating security checkpoints into the automation stack, developing custom security-as-code tools that empower developers to own security outcomes. + Oversee the strategic direction of our private and public bug-bounty programs, ensuring high-quality engagement with the researcher community and rapid internal response to critical findings. + Coordinate specialized external penetration testing engagements and customer-driven security assessments, acting as the primary technical point of contact for complex security inquiries. + Drive the technical response to application-level security incidents, conducting root-cause analysis to prevent recurrence and enhance our defensive posture. What you'll need, to connect, support one another, and passionately advocate for the issues close to their hearts - And more benefits tailored to each country Contentsquare is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to sex, gender identity or expression, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law. Your personal data is used by Contentsquare for recruitment purposes only. Read our Job Candidate Privacy Notice to find out more about data protection at Contentsquare and your rights. You can exercise your rights by using our dedicated Data Subject Rights Portal here. Your personal data will be securely stored in our hosting provider's data center in Oregon (US west). We have implemented appropriate transfer mechanisms under applicable data protection laws. Contentsquare may use AI-assisted tools to help review and screen applications. All decisions involving hiring are made by human reviewers, and your personal data will be processed in accordance with our Candidate Privacy Policy.We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.Inscribirse en esta oferta Recibir ofertas similares por correo electrónico Al crear una alerta, aceptas nuestros Términos y condiciones y Política de privacidad, y el uso de cookies. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [Lessons learned from building a thriving Vue.js SaaS application](https://www.wearedevelopers.com/videos/1666-lessons-learned-from-building-a-thriving-vue-js-saas-application) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)