> Markdown version of [/jobs/ext/2700096-security-engineer](https://www.wearedevelopers.com/jobs/ext/2700096-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Happyrobot Inc. - **Location:** Málaga, Spain - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Amazon Web Services, Bash Shell, Cloud Computing, Cyber Security, Document Management Systems, Identity and Access Management, Python (Programming Language), Network Segmentation, Security Information and Event Management, Software Vulnerability Management, Data Logging, Kubernetes, Terraform, SentinelOne Expertise, Blue Team (Cyber Security), Docker, Security Orchestration, Automation & Response - **Published:** September 4, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role 1-3 years of hands-on experience in Security Engineering, SOC, or a technical Blue Team role Proficiency in AWS or GCP (IAM, network segmentation, logging, and secret management). Experience with EDR/SIEM solutions (e.g., CrowdStrike, Wazuh, SentinelOne, or Elastic Security). Ability to read and write basic scripts ( Python or Bash ) to automate security workflows. Fluent in English and Spanish. You can explain a technical vulnerability to a developer and a compliance risk to a manager. Nice-to-Haves Experience with Infrastructure as Code (Terraform) Knowledge of container security ( Kubernetes/Docker ## Description We are looking for a Security Engineer to join our IT & Security team. As we scale, we need someone to take full ownership of our daily security operations-moving beyond basic IT tasks to focus on infrastructure hardening, vulnerability management, and incident detection . You will be the bridge between compliance requirements and technical execution, ensuring that our AWS/GCP environments are bulletproof while helping the senior team scale security through automation. What You'll Do Vulnerability Management: Triage CVEs based on exploitability and impact. Drive remediation efforts across engineering teams to meet our strict SLAs. Infrastructure Hardening: Own the security configuration (hardening) of our cloud infrastructure (AWS/GCP) and internal systems. Detection & Response: Monitor SIEM/EDR alerts, distinguish signal from noise, and execute escalation protocols for high-severity incidents. Security Automation: Write scripts in Python or Bash to automate repetitive security tasks and integrate tools via APIs. Technical Compliance: Document controls and gather evidence for SOC2 and ISO ***** audits, translating compliance needs into technical reality. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)