Associate Security Engineer

Spendesk

Barcelona

Presencial

EUR 40.000 - 70.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care
Great office snacks
Location-specific benefits

Descripción de la vacante

Spendesk is looking for a Security Engineer in Barcelona to join its dedicated Security Engineering function. You will work closely with a Senior Security Engineer, focusing on vulnerability management, access controls, and secure development support.

This role demands hands-on management of vulnerabilities and security incidents, requiring a foundational experience in security engineering and strong collaboration skills. The position offers a flexible on-site and remote policy alongside various benefits tailored to ensure employee well-being.

Formación

  • Foundational experience in security engineering, SOC, or DevOps/SRE with strong security focus.
  • Understanding of web application security and common attack vectors.
  • Hands-on experience with vulnerability scanning tools and SIEM/log analysis.

Responsabilidades

  • Monitor and process security alerts from SIEM and other tools.
  • Implement and maintain SSO/MFA configurations.
  • Run pre-deployment security checks.

Conocimientos

Security engineering experience
Web application security
Scripting (Python, Bash)
Collaboration skills
Vulnerability scanning tools

Herramientas

Okta
Google Workspace
ElasticSearch

Descripción del empleo

We're building a dedicated Security Engineering function. You'll join alongside a Senior Security Engineer and together form the operational security backbone of the engineering organisation.

Your Mission

You'll be hands‑on across vulnerability management, access controls, monitoring, and secure development support. You'll work closely with a Senior Security Engineer who'll mentor you and help you grow, while partnering day‑to‑day with Infrastructure and product engineering teams.

This is a hands‑on engineering role, not a dashboard‑watching SOC seat or a governance one: you'll build, fix, and improve, while a separate team owns policy and risk frameworks. You'll learn fast and ship real security improvements from week one. If you like fixing things, digging into alerts, and making systems harder to break, you'll thrive here.

You will sit at the intersection of two domains: as a security engineer, your impact will be directly measured by how effectively you translate second‑line‑of‑defence guidance (from the Compliance and Regulatory team) into practice, while ensuring technical alignment and buy‑in from the Product and Engineering organisation you are part of.

Key Responsibilities

Vulnerability & incident management

  • Triage vulnerabilities from our bug bounty program, scanners, and dependency checks.
  • Support incident response: develop fixes, track resolution, update tickets, and contribute to post‑mortems.
  • Monitor and process security alerts from our SIEM and other monitoring tools.

Identity & access management

  • Implement and maintain SSO/MFA configurations for product and infrastructure systems, leveraging Okta and Google Workspace to manage downstream access rights.
  • Implement roles and access rights per tool and system.
  • Run periodic permission reviews and access audits.
  • Manage production secrets and credential rotation.

Secure development support and tooling

  • Run pre‑deployment security checks: static analysis, dependency scanning, container image scanning.
  • Flag issues in code reviews when security patterns are violated.
  • Help engineers understand and fix security findings.

Monitoring & detection

  • Monitor SIEM alerts, investigate suspicious activity, and elevate when needed.
  • Maintain and tune detection rules under guidance from the Senior Security Engineer.
  • Help operate and maintain SIEM infrastructure (ElasticSearch, log collection pipelines).

Security operations

  • Support pentest coordination: prepare test environments, track remediation items.
  • Maintain documentation on security procedures and runbooks.
What We’re Looking For

Must‑haves:

  • Foundational experience in security engineering, SOC, or a DevOps/SRE role with a strong security focus, eager to deepen across the security stack.
  • Solid understanding of web application security (OWASP Top 10, common attack vectors).
  • Hands‑on experience with at least two of: vulnerability scanning tools, SIEM/log analysis, IAM systems (Okta, Google Workspace), or CI/CD security tooling.
  • Comfortable scripting (Python, Bash, or similar) to automate repetitive security tasks.
  • Collaborative mindset: you work across many teams and communicate security issues clearly and constructively. Rather than binary allowed/forbidden calls, you assess and articulate risk through a severity and likelihood lens, bringing teams along instead of acting as a blocker.

Nice‑to‑haves:

  • Experience with AWS security (IAM policies, Security Hub, GuardDuty).
  • Familiarity with ElasticSearch / ELK stack.
  • Exposure to infrastructure‑as‑code (Terraform) and container security.
  • Knowledge of compliance frameworks (ISO 27001, SOC 2, PCI‑DSS): not as an auditor, but enough to understand why controls exist.
  • Experience in fintech or a regulated environment.
About Our Benefits
  • Flexible on‑site and remote policy
  • Latest Apple equipment — the tools you need to excel
  • Access to Moka.care — for emotional and mental health wellbeing
  • Great office snacks — to fuel your day
  • A positive team to work with daily!
  • We also offer location‑specific benefits tailored to each market, including health insurance, wellness allowances, commuter support, meal vouchers, and gym memberships — ensuring you're well supported wherever you're based.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Product Security Engineer
Product Security Engineer

Gomining • España

Híbrido
EUR 65.000 - 90.000
Professional development
Flexible work arrangement
Paid time off
+2
Senior Application Security Engineer
Senior Application Security Engineer

LeoVegas Group • Málaga

Híbrido
EUR 70.000 - 100.000
Hybrid work policy
Workation benefits
Wellness contribution
+7
Engineering
Engineering

Nexthink SA • Madrid

Híbrido
EUR 90.000 - 120.000
Hybrid work model
Private Health Insurance (Sanitas)
Daily meal vouchers 11 EUR
+1
Security Engineer (Infrastructure)
Security Engineer (Infrastructure)

Hiring • Málaga

Presencial
EUR 45.000 - 65.000
Security Engineer
Security Engineer

airapps • Barcelona

Presencial
EUR 60.000 - 80.000
Annual Bonus
Top-tier Health and Life Insurance
Transportation Budget
+4
Security Engineer (Infrastructure) - ESK Agency
Security Engineer (Infrastructure) - ESK Agency

hiring • Málaga

Presencial
EUR 50.000 - 80.000
Senior Security Engineer
Senior Security Engineer

Auctane • Barcelona

Presencial
EUR 75.000 - 83.000
Private health insurance
Annual salary review
Training budget up to €2000/year
+2
Security Engineer
Security Engineer

Doist • Barcelona

Híbrido
EUR 90.000 - 130.000
Security Engineer
Security Engineer

Wizeline • Barcelona

Presencial
EUR 90.000 - 130.000
High-Impact Environment
Professional Development
Flexible Culture
+3
Senior Security Engineer
Senior Security Engineer

Socium - Teams Done Differently • Madrid

Híbrido
EUR 70.000 - 110.000
Private health insurance
Unlimited vacation
Relocation package