> Markdown version of [/jobs/ext/2837876-offensive-security-engineer](https://www.wearedevelopers.com/jobs/ext/2837876-offensive-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Offensive Security Engineer - **Company:** Factorial - **Location:** Barcelona, Spain (Remote available) - **Salary:** €42,800.0 - €60,500.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Bash Shell, Cyber Security, Databases, Continuous Integration, Data Security, Python (Programming Language), Network Protocols, Ruby, Secure Coding, Strategies of Testing, Web Applications, Scripting, Large Language Models, Software Security, Information Technology, Cybercrime, Programming Languages - **Published:** September 11, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role + You have 3+ years of professional experience in Application Security, Offensive Security, or Penetration Testing. Web Application Penetration Testing experience is mandatory. + You hold a degree in Engineering or Computer Science and have strong knowledge of web applications, databases, network protocols, and operating systems. + You possess strong knowledge in cybersecurity fundamentals, CVSS, testing methodologies, and tooling. + You are fluent with scripting or programming languages used in security testing and automation, such as Python or Bash. + You are technical, curious, and comfortable moving across different security problems instead of specializing in only one area. + You like to attack systems, but you also enjoy building tools, automations, guardrails, and practical solutions that make security scale. + You do not need to be an expert in every technology, but you should be able to reason critically, learn fast, use AI effectively, and design pragmatic solutions. + You have curiosity and willingness to learn about AI security topics such as LLM testing, prompt injection, agentic workflows, data exposure, tool permissions, RAG security, and secure AI adoption. + Certifications like BSCP or eWPTX are highly regarded but not mandatory. + Experience with Ruby / Ruby on Rails applications is highly regarded, but not mandatory. + Fluency in English is required. ## Description At Factorial, we're on the hunt for a skilled Application Security Engineer to join our Security Team. We need your expertise to proactively hunt for vulnerabilities and strengthen our defenses against cyber threats. If you have a passion for ethical hacking and want to make an impact in a dynamic tech environment, we'd love to hear from you! Ready to be part of the challenge? About the team Security at Factorial works side by side with Product and Engineering to help a fast-moving, AI-native company ship without losing control of risk. Our mission is to protect Factorial and our customers while making security a practical part of how software is designed, built, tested, and operated. The work goes far beyond finding vulnerabilities: we test real product surfaces, help teams fix issues properly, and turn repeated security needs into guardrails, automation, and CI/CD controls that developers can use every day. AI is part of Factorial's culture, product, and way of working from day one, so Security also helps define how teams use agents, LLMs, tools, and company data safely at scale, while actively challenging those systems with an attacker mindset. It's a team for people who want to keep learning, move across different security problems, and build security that can keep up with the speed of the company. What You'll be doing? + Perform proactive penetration testing across Factorial's applications, APIs, infrastructure, and AI-powered features. + Reproduce and validate vulnerability reports submitted by third parties, like our bug bounty program. + Collaborate with development teams to remediate security findings and enhance secure coding practices. + Improve how we validate, triage, and remediate vulnerabilities from bug bounty reports, internal testing, automated controls, and external research. + Hunt for recurring or legacy vulnerability patterns based on root cause analysis, previous incidents, and security findings. + Build and improve security automations, agents, skills, and CI/CD controls that help engineering teams catch and fix issues earlier. + Help secure Factorial's use of AI across product and internal workflows, including LLMs, agents, data access, tools, permissions, and abuse scenarios. + Contribute to the development of our security tools, automations, and infrastructure. + Stay up-to-date with the latest security research, threats, attack techniques, and emerging AI security risks. ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)