Cyber Security Engineer

Smadex SLU
Laza, Spain
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Remote
Laza, Spain

Tech stack

API
Agile Methodologies
Amazon Web Services (AWS)
Software System Penetration Testing
Bash
Cloud Computing
Cloud Computing Security
Computer Security
Linux
DevOps
Python
Linux System Administration
Security Information and Event Management
Scripting (Bash/Python/Go/Ruby)
Cloud Platform System
Software Security
Deep Learning
Containerization
Information Technology
Nessus
Integration Frameworks
Data Pipelines
Devsecops
Qualys
Vulnerability Analysis

Job description

Smadex is a leading advertising technology company founded in Barcelona in **** and sold to American-based and stock-listed Entravision in **** (NYSE::EVC). We power campaigns for Apps, Games and Brands across Mobile and CTV using advanced machine learning and optimized creative strategies to deliver results. Smadex is one of the fastest growing DSPs globally and we are adding talent to fuel our ambitious plans.We are looking for a proactiveCyber Security Engineerto join our team and safeguard the integrity of our high-traffic programmatic infrastructure. In this role, you will be the guardian of our digital ecosystem, bridging the gap between cutting-edge security engineering and agile DevOps practices.The RoleArchitectand deploy scalable, cloud-native security protocols (e.g., WAF, Security Groups, GuardDuty, CSPM) to safeguard our high-traffic, API driven infrastructure.Designand maintain automated threat detection rules and response mechanisms for our cloud and container environments.Managecontinuous vulnerability assessments programs and coordinate third-party penetration testing to identify and remediate risks within our cloud-native and Linux environments.Secureour software supply chain and third-party dependencies, with a strong focus on SDK security and data partner integrations critical to ad-tech.Partnerwith engineering and DevOps teams to integrate secure system design, threat modeling and robust API security into the product lifecycle.Leadincident response efforts and forensic investigations to mitigate the impact of security breaches and prevent future occurrences.Ensuredata privacy is a core component of our product architecture and data processing workflows, maintaining strict adherence toGDPRrequirements.Developand maintain comprehensive security documentation, including policies, standards, and incident handling procedures.Drivea "security-first" culture by creating awareness training, providing technical guidance to cross-functional teams, and offering a security perspective on ad fraud and invalid traffic (IVT).RequirementsExperience:4-5+ years of professional experience in Cybersecurity/ Security EngineeringCloud & Systems:Proven expertise in securing cloud environments (AWS/GCP), Linux deployments, and containerized workloads.API & Application Security:Deep understanding of API security principles and experience securing APIs in high-throughput environments.Technical Tools:Hands-on proficiency with cloud-native security tools, SIEM platforms, and vulnerability scanners (e.g., Nessus, Qualys)..Privacy & Compliance:Strong working knowledge ofGDPRand its practical application in data-heavy, European-based environments.Supply Chain Security:Experience managing vendor risk, third-party integrations, and dependency security.Scripting:Strong ability to automate security workflows using Python, Bash, or similar languages.Education:BA/BS degree in Computer Science, Information Security, or a related technical field.Bonus points:Ad-Tech Context:Familiarity with the programmatic advertising ecosystem (DSP, SSP, Ad Exchanges), SDK security, or invalid traffic (IVT) mitigation.Advanced Principles:Deep understanding of threat modeling, and secure SDLC/DevSecOps practices.Compliance Knowledge:Familiarity with planning or maintaining industry standards and certifications such as ISO *****, NIST, SOC2 or CCPA.Mindset:A pragmatic, problem-solving mindset-finding the right balance between rapid velocity and strict security standards.Please note that we do NOT provide VISA sponsorship. Candidates without a legal permit to work in Spain won't be considered.What is in it for you:Integrate a highly motivated, young and dynamic teamGreat compensation packageTop location at the heart of Barcelonawith a rooftop terrace, Barbecue, and a fully stocked fridgeGreat work-life balance: work from home (2 days per week), flexible hoursMeal vouchers -Ticket Restaurantmonthly allowanceMonthly gym allowance: Choose between DiR and WellhubLinkedIn Learning and training opportunitiesMonthly TGIF eventsRegular team-building eventsFun and friendly work environment with talented marketers and engineers from over 40 countriesAnd more!If you want to know more about us visit our websiteSmadex.com, and for a sneak peek of the cool stuff we build check thisvideoout!

Requirements

4-5+ years of professional experience in Cybersecurity / Security Engineering Cloud & Systems: Proven expertise in securing cloud environments (AWS/GCP), Linux deployments, and containerized workloads. API & Application Security: Deep understanding of API security principles and experience securing APIs in high-throughput environments. Technical Tools: Hands-on proficiency with cloud-native security tools, SIEM platforms, and vulnerability scanners (e.g., Nessus, Qualys).. Privacy & Compliance: Strong working knowledge of GDPR and its practical application in data-heavy, European-based environments. Supply Chain Security: Experience managing vendor risk, third-party integrations, and dependency security. Scripting: Strong ability to automate security workflows using Python, Bash, or similar languages. Education: BA/BS degree in Computer Science, Information Security, or a related technical field. Bonus points: Ad-Tech Context: Familiarity with the programmatic advertising ecosystem (DSP, SSP, Ad Exchanges), SDK security, or invalid traffic (IVT) mitigation. Advanced Principles: Deep understanding of threat modeling, and secure SDLC/DevSecOps practices. Compliance Knowledge: Familiarity with planning or maintaining industry standards and certifications such as ISO *****, NIST, SOC2 or CCPA. Mindset: A pragmatic, problem-solving mindset-finding the right balance between rapid velocity and strict security standards. Please note that we do NOT provide VISA sponsorship. Candidates without a legal permit to work in Spain won't be considered.

Benefits & conditions

Great compensation package Top location at the heart of Barcelona with a rooftop terrace, Barbecue, and a fully stocked fridge Great work-life balance: work from home (2 days per week), flexible hours Meal vouchers - Ticket Restaurant monthly allowance Monthly gym allowance: Choose between DiR and Wellhub LinkedIn Learning and training opportunities Monthly TGIF events Regular team-building events Fun and friendly work environment with talented marketers and engineers from over 40 countries And more! If you want to know more about us visit our website Smadex.com , and for a sneak peek of the cool stuff we build check this video out!

About the company

Smadex is a leading advertising technology company founded in Barcelona in **** and sold to American-based and stock-listed Entravision in **** (NYSE::EVC). We power campaigns for Apps, Games and Brands across Mobile and CTV using advanced machine learning and optimized creative strategies to deliver results. Smadex is one of the fastest growing DSPs globally and we are adding talent to fuel our ambitious plans.

Apply for this position