> Markdown version of [/jobs/ext/2267383-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/2267383-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** Xtel - **Location:** Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Adobe InDesign, Software System Penetration Testing, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, Software Design Patterns, Identity and Access Management, Key Management, Network Security, Microsoft Servers, Systems Development Life Cycle, Secure Coding, Software Vulnerability Management, Software Security, Microsoft InTune, Patch Management, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 27, 2026 - **Apply:** https://www.jobleads.com/es/job/e06cd8cb82ff217d8580741d5e1d4c266 ## About the Role The ideal candidate must be proactive and self-directed: actively seeking out opportunities to improve security across the organization and able to operate effectively with limited guidance and oversight., * Experience: 3+ years in cybersecurity engineering, security operations, DevSecOps, or security-focused IT (cloud-native SaaS experience strongly preferred, ideally on Azure). * Vulnerability management: Proven track record running vulnerability management beyond scanning - prioritizing and driving remediation to closure across teams. * Application & SDLC security: Working knowledge of AppSec and SDLC controls (CI/CD security, SAST/DAST/IAST/SCA, secure code review) and the ability to embed security without slowing delivery. * Microsoft environment: Hands-on experience securing Microsoft environments (Entra ID, Intune, Conditional Access, endpoint protections, M365 controls). * Cloud security: Working knowledge of Azure security services and cloud security posture management. * Self-direction: Ability to work independently, set priorities, and build or mature programs in a lean environment with limited guidance. * Communication & ownership: Strong communicator who can drive work and build trust across Engineering, Product, Cloud Operations, IT, and Compliance., * Familiarity operating within an ISO 27001 / SOC 2 environment and supporting audits. * Experience with infrastructure-as-code and securing CI/CD at scale. * Hands-on penetration testing or offensive security experience (e.g., OSCP). * Experience with compliance automation tooling (e.g., Drata)., * Proactive and self-starting - you find work that needs doing and do it without waiting to be told. * Pragmatic and risk-based - you focus effort where it reduces the most risk and balance security with delivery. * Collaborative - you achieve outcomes through influence across teams you don't manage. ## Description XTEL is hiring a Cybersecurity Engineer to strengthen XTEL's security posture across our platform, applications, and Microsoft environment. You'll join a growing Security & Compliance team that already maintains a mature compliance foundation (ISO 27001:2022, SOC 2 Type 2, SOC 1 Type 2, ISAE 3402) and an established GRC function, alongside a managed SOC, an IT team, and a Cloud Operations team. This is a very hands-on role where you'll lead vulnerability management, work with Engineering and Product to embed security into the SDLC, partner with IT & Cloud Operations to continuously harden our Microsoft environments, and drive triage and remediation of issues surfaced by our SOC. Because you'll work alongside existing IT, Cloud Operations, and GRC capabilities, success depends on collaboration and influence as much as technical depth., * Vulnerability management. Own intake, triage, risk-based prioritization, remediation tracking, validation, SLAs, and reporting across our Azure environments (dev, test, prod, and customer-facing) and the development pipeline. * Secure SDLC & CI/CD. Partner with Engineering, Product, and QA to continually improve secure development practices: * Pipeline security and security gates in CI/CD. * SAST, DAST, IAST, dependency/software composition (SCA), and code scanning. * Secure code review practices, threat modeling, and security requirements in design. * Microsoft environment hardening. Work continuously with IT to further secure infrastructure - identity and access management, endpoint protections, M365 controls, and configuration/hardening baselines. * SOC-driven remediation. Coordinate and drive triage and remediation for alerts, incidents, and vulnerabilities reported by XTEL's SOC, including root cause follow up. * Penetration testing. Coordinate external penetration tests (scope, execution support, findings management, retesting and closure), and conduct internal testing. * Patch management. Support patch management processes and verification in partnership with IT and Cloud Operations. * Cloud security partnership. Partner with Cloud Operations on Azure security architecture, secure-by-design patterns, CSPM, secrets management, and network security. * Compliance & audit support. Support security audits and continuous compliance (ISO 27001, SOC 1, SOC 2 Type 2, ISAE 3402), including evidence collection and control improvement. * Cross-functional enablement. Translate security findings into clear, actionable guidance for engineers and into evidence and inputs for the GRC function. * Continuous improvement. Proactively identify and act on opportunities to raise the security bar across the organization. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [This Machine Ends Data Breaches](https://www.wearedevelopers.com/videos/574-this-machine-ends-data-breaches) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)