> Markdown version of [/jobs/ext/3013303-security-engineer-in-saas](https://www.wearedevelopers.com/jobs/ext/3013303-security-engineer-in-saas). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer In Saas - **Company:** Enfint - **Location:** Barcelona, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Business Software, Software as a Service, Cyber Security, Databases, Continuous Integration, Data Security, Python (Programming Language), Microsoft Office, Network Protocols, Ruby on Rails, Ruby, Secure Coding, Strategies of Testing, Web Applications, Scripting, Large Language Models, Software Security, Build Tools, Programming Languages - **Published:** September 20, 2026 - **Apply:** https://www.buscojobs.com.es/security-engineer-in-saas-en-barcelona-ID-372023454 ## About the Role ??????Perform proactive penetration testing across applications, APIs, infrastructure, and AI-powered featuresReproduce and validate vulnerability reports submitted by third parties, including the bug bounty programCollaborate with development teams to remediate security findings and improve secure coding practicesImprove vulnerability validation, triage, and remediation processesHunt for recurring or legacy vulnerability patterns through root cause analysis, previous incidents, and security findingsBuild and improve security automations, agents, skills, and CI/CD controlsHelp secure the use of AI across product and internal workflows, including LLMs, agents, data access, tools, permissions, and abuse scenariosContribute to the development of security tools, automations, and infrastructureStay up to date with security research, threats, attack techniques, and emerging AI security risks??????????3+ Years of professional experience in Application Security, Offensive Security, or Penetration TestingMandatory experience in Web Application Penetration TestingDegree in Engineering or Computer ScienceStrong knowledge of web applications, databases, network protocols, operating systems, cybersecurity fundamentals, CVSS, testing methodologies, and toolingProficiency in scripting or programming languages used in security testing and automation, such as Python or BashAbility to work across different security problems and reason criticallyAbility to build tools, automations, guardrails, and scalable practical security solutionsCuriosity and willingness to learn AI security topics, including LLM testing, prompt injection, agentic workflows, data exposure, tool permissions, RAG security, and secure AI adoptionFluent EnglishNice to have: BSCP or eWPTX certifications, experience with Ruby / Ruby on Rails applications???????Base salary of ***************€ plus 7-10% variable performance pay paid quarterlyESOP planAlan private health insuranceWellhub gym, pool, and outdoor class ## Description ????????Factorial builds AI Business Management Software for companies of all sizes.Its platform centralizes workflows across HR, Finance, Talent, Operations, and IT, helping teams reduce manual processes.Factorial is a SaaS company headquartered in Barcelona.??????Perform proactive penetration testing across applications, APIs, infrastructure, and AI-powered featuresReproduce and validate vulnerability reports submitted by third parties, including the bug bounty programCollaborate with development teams to remediate security findings and improve secure coding practicesImprove vulnerability validation, triage, and remediation processesHunt for recurring or legacy vulnerability patterns through root cause analysis, previous incidents, and security findingsBuild and improve security automations, agents, skills, and CI/CD controlsHelp secure the use of AI across product and internal workflows, including LLMs, agents, data access, tools, permissions, and abuse scenariosContribute to the development of security tools, automations, and infrastructureStay up to date with security research, threats, attack techniques, and emerging AI security risks??????????3+ Years of professional experience in Application Security, Offensive Security, or Penetration TestingMandatory experience in Web Application Penetration TestingDegree in Engineering or Computer ScienceStrong knowledge of web applications, databases, network protocols, operating systems, cybersecurity fundamentals, CVSS, testing methodologies, and toolingProficiency in scripting or programming languages used in security testing and automation, such as Python or BashAbility to work across different security problems and reason criticallyAbility to build tools, automations, guardrails, and scalable practical security solutionsCuriosity and willingness to learn AI security topics, including LLM testing, prompt injection, agentic workflows, data exposure, tool permissions, RAG security, and secure AI adoptionFluent EnglishNice to have: BSCP or eWPTX certifications, experience with Ruby / Ruby on Rails applications???????Base salary of ***************€ plus 7-10% variable performance pay paid quarterlyESOP planAlan private health insuranceWellhub gym, pool, and outdoor class benefitsCobee expense savingsLanguage classesBreakfast at the office and organic fruitFood discounts with NoraPet-friendly workplaceOn-site work several days a week (80%) with remote work supported when it makes sense (20%)Office-first, flexible approach#J-*****-Ljbffr ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers)