> Markdown version of [/jobs/ext/2267163-cyber-security-specialist-blue-team](https://www.wearedevelopers.com/jobs/ext/2267163-cyber-security-specialist-blue-team). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Specialist - Blue Team - **Company:** Hbx Group - **Location:** Valencia, Spain - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Static Program Analysis, Cyber Security, Information Leak Prevention, DevOps, Intrusion Detection and Prevention, Machine Learning, Cloud Services, Red Team (Cyber Security), Zero Trust Network Access, Secure Coding, Software Engineering, Software Vulnerability Management, Google Cloud, Cloud Platform System, Large Language Models, Software Security, Generative AI, Containerization, AI Platforms, Kubernetes, Cybercrime, Data Analytics, Machine Learning Operations, Devsecops, Blue Team (Cyber Security), Docker, Security Orchestration, Automation & Response, Vulnerability Analysis, Programming Languages - **Published:** August 27, 2026 - **Apply:** https://www.buscojobs.com.es/cyber-security-specialist-blue-team-en-valencia-ID-369091905 ## About the Role Previous experience in a cyber security role, technology delivery role or equivalent security-focused position. Strong understanding of threat modelling, cyber risk assessment and security analysis techniques. Up-to-date knowledge of current cyber security threats, best practices, technologies and defensive techniques. Experience with vulnerability management, including vulnerability assessment, prioritisation and remediation coordination. Knowledge of incident response processes, including investigation, analysis and timely response activities. Experience or working knowledge of secure software development practices and source code security analysis. Good understanding of DevOps and Agile principles, with the ability to support security practices in fast-moving delivery environments. Knowledge of cloud and container technologies, including Kubernetes, Docker and cloud environments such as AWS, GCP or Azure. Experience using programming languages and/or security automation tools to improve security operations and detection capabilities. Desired skills Ability to translate technical security findings into clear risk-based recommendations. Strong analytical mindset, with the ability to investigate complex issues and prioritise actions based on impact. Good collaboration skills, with the ability to work effectively with Security, Engineering, DevOps and infrastructure teams. Proactive approach to learning and staying current with emerging threats, attack techniques and security technologies. Ability to balance security requirements with delivery needs in agile and cloud-based environments. Personal attributes Ownership and accountability when managing security findings, incidents or remediation activities. Clear communication style, especially when explaining technical risks to non-security stakeholders. Continuous improvement mindset, with a focus on strengthening security processes and operational efficiency. xqziphu Team-oriented approach and willingness to collaborate across technical and business areas. ## Description La siguiente información ofrece un resumen de las habilidades, cualidades y cualificaciones necesarias para este puesto.About HBX GroupHBX Group is a leading independent B2B travel technology marketplace connecting travel businesses globally through advanced technology, data-driven solutions, and a network of interconnected products and services.Our Cyber Security team is responsible for protecting global platforms, cloud infrastructure, corporate environments, data assets, and emerging AI-enabled services.Role OverviewThe Blue Team Security Expert is responsible for the continuous protection, monitoring, assessment, and improvement of HBX Group's security posture across corporate, cloud, application, and AI-enabled environments.The role combines threat detection, incident response, threat hunting, vulnerability management, security automation, and proactive security engineering.The successful candidate will work closely with Red Team, Security Architecture, DevOps, Engineering, Data, and AI teams to identify, prevent, detect, and respond to cyber threats.Threat Detection & Threat HuntingIdentify, investigate and analyse cyber security threats affecting services, platforms and development environments.Assess the potential impact of detected threats and support the definition of effective remediation actions.Perform continuous technology watch to stay up to date with industry trends, emerging attack techniques, best practices and relevant security developments.Collaborate with Red Team activities to validate findings, improve detection capabilities and enhance the overall security posture.AI Security & Emerging ThreatsAssess risks related to Generative AI, Large Language Models (LLMs), AI agents, and machine learning systems.Identify and mitigate threats such as:Prompt injection attacksData poisoningModel manipulationAI supply chain attacksSensitive data leakage through AI platformsShadow AI usagePartner with AI and Data teams to implement secure-by-design AI solutions.Contribute to AI governance, monitoring, and security controls.Stay up to date on emerging AI security frameworks and industry best practices.Vulnerability & Exposure ManagementMonitor, assess and prioritise vulnerabilities across applications, infrastructure, cloud environments and containerised platforms.Evaluate the severity, exploitability and potential business impact of vulnerabilities to support risk-based remediation planning.Work with technology, infrastructure and development teams to coordinate remediation activities and track progress.Contribute to the continuous improvement of vulnerability management processes, reporting and prioritisation criteria.Cloud & Platform SecuritySupport and enhance security controls across AWS, Azure, and GCP environments.Monitor cloud-native security services and investigate cloud security incidents.Secure containerized environments, including Kubernetes and Docker platforms.Assess infrastructure-as-code and cloud deployments for security weaknesses.Contribute to Zero Trust and cloud security initiatives.Incident ResponseParticipate in security incident response activities, including investigation, analysis, containment support and timely response.Contribute to the identification of root causes and support the definition of corrective and preventive actions.Work with relevant teams to ensure lessons learned from incidents are translated into security improvements.DevSecOps Support and Code SecuritySupport agile delivery teams by embedding security practices into development and delivery processes.Provide guidance on secure development, code analysis and security testing across different platforms, environments and instances.Help improve the organisation's capability to identify and remediate vulnerabilities in source code.Promote the use of security automation tools to improve scalability, consistency and efficiency in security activities.What You Will BringPrevious experience in a cyber security role, technology delivery role or equivalent security-focused position.Strong understanding of threat modelling, cyber risk assessment and security analysis techniques.Up-to-date knowledge of current cyber security threats, best practices, technologies and defensive techniques.Experience with vulnerability management, including vulnerability assessment, prioritisation and remediation coordination.Knowledge of incident response processes, including investigation, analysis and timely response activities.Experience or working knowledge of secure software development practices and source code security analysis.Good understanding of DevOps and Agile principles, with the ability to support security practices in fast-moving delivery environments.Knowledge of cloud and container technologies, including Kubernetes, Docker and cloud environments such as AWS, GCP or Azure.Experience using programming languages and/or security automation tools to improve security operations and detection capabilities.Desired skillsAbility to translate technical security findings into clear risk-based recommendations.Strong analytical mindset, with the ability to investigate complex issues and prioritise actions based on impact.Good collaboration skills, with the ability to work effectively with Security, Engineering, DevOps and infrastructure teams.Proactive approach to learning and staying current with emerging threats, attack techniques and security technologies.Ability to balance security requirements with delivery needs in agile and cloud-based environments.Personal attributesOwnership and accountability when managing security findings, incidents or remediation activities.Clear communication style, especially when explaining technical risks to non-security stakeholders.Continuous improvement mindset, with a focus on strengthening security processes and operational efficiency.xqziphuTeam-oriented approach and willingness to collaborate across technical and business areas. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)