Associate Security Engineer

Spendesk
Barcelona, Spain
13 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Bash Shell Static Program Analysis Continuous Integration DevOps Elasticsearch Identity and Access Management Python (Programming Language) Log Analysis Open Web Application Security Web Application Security Security Information and Event Management Software Vulnerability Management
+4 more
Scripting Okta Gsuite Vulnerability Analysis

Job description

Experteer Overview As a Security Engineer at Spendesk, you will help build the security backbone of a fintech platform used across Europe.You will work hands-on across vulnerability management, identity controls, monitoring, and secure development support, collaborating closely with a Senior Security Engineer and cross-functional teams.The role focuses on translating compliance guidance into practical security improvements within product and infrastructure.You’ll fix and improve systems from week one, avoiding purely governance tasks and driving real risk reduction.This position offers growth in a fast-paced, security-first environment that values practical impact and collaboration.Compensaciones / Beneficios * Triage vulnerabilities from bug bounty, scanners, and dependency checks; support incident response with fixes and post-mortems; monitor security alerts from SIEM.* Implement and maintain SSO/MFA configurations using Okta and Google Workspace; manage roles, access rights, and periodic audits; manage production secrets and credential rotation.* Run pre-deployment security checks (static analysis, dependency scanning, container image scanning); enforce security reviews and help engineers remediate findings.* Monitor and tune SIEM/monitoring rules; operate SIEM infrastructure (ElasticSearch, log pipelines); escalate and respond to suspicious activity.* Coordinate pentest activities: prepare test environments and track remediation; maintain security runbooks and procedures.Responsabilidades * Foundational experience in security engineering, SOC, or DevOps/SRE with a security focus.* Solid understanding of web application security (OWASP Top 10).* Hands-on with at least two: vulnerability scanning tools, SIEM/log analysis, IAM systems (Okta, Google Workspace), or CI/CD security tooling.* Scripting competence (Python, Bash, or similar) for automation.* Collaborative mindset with clear, constructive security communication and risk articulation.Requisitos principales * Flexible on-site and remote policy * Latest Apple equipment * Moka.care for wellbeing * Great office snacks * Location-specific benefits (health insurance, wellness allowances, commuter support, meal vouchers, gym memberships)

Requirements

Responsabilidades * Foundational experience in security engineering, SOC, or DevOps/SRE with a security focus.

  • Solid understanding of web application security (OWASP Top 10).
  • Hands-on with at least two: vulnerability scanning tools, SIEM/log analysis, IAM systems (Okta, Google Workspace), or CI/CD security tooling.
  • Scripting competence (Python, Bash, or similar) for automation.
  • Collaborative mindset with clear, constructive security communication and risk articulation. Requisitos principales * Flexible on-site and remote policy * Latest Apple equipment * Moka.care for wellbeing * Great office snacks * Location-specific benefits (health insurance, wellness allowances, commuter support, meal vouchers, gym memberships)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

Videos

See all

Related articles

See all