> Markdown version of [/jobs/ext/2798824-associate-security-engineer](https://www.wearedevelopers.com/jobs/ext/2798824-associate-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Associate Security Engineer - **Company:** Spendesk - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Bash Shell, Static Program Analysis, Continuous Integration, DevOps, Elasticsearch, Identity and Access Management, Python (Programming Language), Log Analysis, Open Web Application Security, Web Application Security, Security Information and Event Management, Software Vulnerability Management, Scripting, Okta, Gsuite, Vulnerability Analysis - **Published:** September 8, 2026 - **Apply:** https://www.buscojobs.com.es/associate-security-engineer-en-barcelona-ID-370265600 ## About the Role Responsabilidades * Foundational experience in security engineering, SOC, or DevOps/SRE with a security focus. * Solid understanding of web application security (OWASP Top 10). * Hands-on with at least two: vulnerability scanning tools, SIEM/log analysis, IAM systems (Okta, Google Workspace), or CI/CD security tooling. * Scripting competence (Python, Bash, or similar) for automation. * Collaborative mindset with clear, constructive security communication and risk articulation. Requisitos principales * Flexible on-site and remote policy * Latest Apple equipment * Moka.care for wellbeing * Great office snacks * Location-specific benefits (health insurance, wellness allowances, commuter support, meal vouchers, gym memberships) ## Description Experteer Overview As a Security Engineer at Spendesk, you will help build the security backbone of a fintech platform used across Europe.You will work hands-on across vulnerability management, identity controls, monitoring, and secure development support, collaborating closely with a Senior Security Engineer and cross-functional teams.The role focuses on translating compliance guidance into practical security improvements within product and infrastructure.You'll fix and improve systems from week one, avoiding purely governance tasks and driving real risk reduction.This position offers growth in a fast-paced, security-first environment that values practical impact and collaboration.Compensaciones / Beneficios * Triage vulnerabilities from bug bounty, scanners, and dependency checks; support incident response with fixes and post-mortems; monitor security alerts from SIEM.* Implement and maintain SSO/MFA configurations using Okta and Google Workspace; manage roles, access rights, and periodic audits; manage production secrets and credential rotation.* Run pre-deployment security checks (static analysis, dependency scanning, container image scanning); enforce security reviews and help engineers remediate findings.* Monitor and tune SIEM/monitoring rules; operate SIEM infrastructure (ElasticSearch, log pipelines); escalate and respond to suspicious activity.* Coordinate pentest activities: prepare test environments and track remediation; maintain security runbooks and procedures.Responsabilidades * Foundational experience in security engineering, SOC, or DevOps/SRE with a security focus.* Solid understanding of web application security (OWASP Top 10).* Hands-on with at least two: vulnerability scanning tools, SIEM/log analysis, IAM systems (Okta, Google Workspace), or CI/CD security tooling.* Scripting competence (Python, Bash, or similar) for automation.* Collaborative mindset with clear, constructive security communication and risk articulation.Requisitos principales * Flexible on-site and remote policy * Latest Apple equipment * Moka.care for wellbeing * Great office snacks * Location-specific benefits (health insurance, wellness allowances, commuter support, meal vouchers, gym memberships) ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)