Cloud Security Engineer

YGO

España

In loco

EUR 90.000 - 130.000

Tempo pieno

2 ore fa
Candidati tra i primi
Generatore di candidature

Distinguiti per questa posizione — genera un curriculum e una lettera di presentazione personalizzati in circa un minuto.

Supera i filtri ATS

Descrizione del lavoro

YGO.ai is hiring a Cloud Security Engineer to own the security of our cloud platform, the APIs our enterprise clients run on and the company itself.

You will build the security function while remaining hands-on as an engineer, reviewing code, testing, and improving security across the stack. You will lead the security roadmap and work closely with engineering to mitigate risks daily.

Competenze

  • 5+ years of hands-on security across multiple disciplines.
  • In-depth application security for modern web apps and APIs via code review or targeted tests.
  • Strong authentication/authorization skills (OAuth, OIDC, tokens, access control).
  • Cloud security fundamentals covering identity, network, workload and pipelines.
  • Defensive experience: investigated incidents and improved detection/alerting.
  • Threat modelling and secure architecture for cloud, container and API systems.
  • Engineering background; comfortable with a Go backend.
  • Resource-constrained mindset from startups/teams; prioritize risk and impact.
  • Interest in building and leading a security team.
  • Experience with Claude Code in real-world contexts.
  • Good pace judgement: guardrails over gates.
  • Experience with SOC 2, ISO 27001 or enterprise reviews.
  • Excellent spoken and written English.
  • Time zone alignment with CET ±3 hours.
  • Available for full-time (40h/week).

Mansioni

  • Own security engineering for our cloud platform, APIs and enterprise clients.
  • Hands-on code review, security design, and targeted penetration testing.
  • Implement cloud/platform hardening: access control, secrets management, containers, CI/CD security.
  • Lead detection and response: incidents, on-call, alerting and root-cause analysis.
  • Drive SOC 2 program management and security roadmap with Drata integration.
  • Collaborate with engineers to fix root causes and raise security standards.

Conoscenze

5+ years security experience
Application security
Authentication/Authorization
Cloud security fundamentals
Defensive security & incident response
Threat modelling & secure architecture
Engineering background
Go language familiarity
Resource-conscious mindset
Team build/leadership
Claude Code proficiency
Pace judgement & guardrails
SOC 2 / ISO 27001 experience
Excellent English
CET±3 time zones
Full-time availability

Descrizione del lavoro

YGO.ai is a VC-funded AI tourism platform. We are hiring a Cloud Security Engineer to own the security of our cloud platform, the APIs our enterprise clients run on and the company itself.

About this role

The role carries two things at once. You own security engineering directly and hands-on. You build the security function around it as we grow. At YGO a pod lead is a squad leader and a spokesperson, close to the work and close to the client, rather than a full-time manager. You will not stop being an engineer.

The work is broad. You might review source code in the morning, investigate an endpoint alert after lunch and help design a new authentication flow the next day. You identify the highest-risk problems, decide what happens first and execute.

We serve major travel enterprises and we have enterprise commitments going live from the start of 2027. Security is a condition of that business, not a layer added afterwards.

Application security. Hands-on code and architecture review across our APIs, backend services and internal tooling. Targeted penetration testing to validate issues yourself. Working with engineers on root causes and practical fixes rather than handing over reports. Vulnerability management and the external penetration tests we commission.

Detection and response. Knowing we are under attack while it is happening and what happens next. Alerting, intrusion detection, incident process and the on-call path.

Cloud and platform hardening. Access control, network boundaries, secrets management, containers and the deployment pipeline. Security through the SDLC: CI/CD, repositories and dependencies.

The security of our APIs. Authentication and authorization, tenant isolation, token scoping and lifecycle, abuse prevention, enterprise SSO and the audit trail our clients and our own accountability depend on.

The security of our AI systems. Prompt injection, tool and agent permissions, our MCP server, retrieval and data ingestion. The data-residency rules we are held to contractually.

Identity and company security. SSO, MFA and privileged access for employees, onboarding and offboarding, access reviews, MDM, endpoint security and SaaS access.

Secure design across the pods. Threat modelling and design review that enables engineers rather than gatekeeping them and raises the standard of what they ship.

The security function itself. Set the priorities and the roadmap from actual risk, not security theatre. Decide what we build, buy, automate or leave for later. Grow the team and hire into it, represent security to enterprise clients and carry our SOC 2 programme on Drata.

What you'll secure

An AI search and recommendation engine for major travel enterprises: enterprise integration, SSO, client security reviews, GDS integrations.

A content enrichment API sold as SaaS: high scale, public facing, data and AI heavy.

The platform underneath: a client console with organisations, projects and API tokens, supplier and business-client integrations, data ingestion, an MCP server, and several LLM providers behind a single internal library.

Hosting: PaaS-managed containers, Cloudflare in front

Observability: Jaeger tracing, BetterStack for logging, alerting and on-call

Compliance: Drata, SOC 2 in progress

AI tooling: Claude Code, used across the whole team

You must have
  • 5+ years of hands-on security work spanning more than one discipline. Not five years of engineering with some security in it.
  • Application security depth. You know how modern web applications and APIs are attacked and can validate an issue yourself through code review or a targeted penetration test.
  • A strong grasp of authentication and authorization. OAuth and OIDC, sessions, token handling, access control and the failure modes behind most API breaches.
  • Cloud security fundamentals, properly. Identity, network, workload and pipeline security on a modern cloud platform.
  • Defensive experience alongside the offensive. You have investigated real incidents and built or improved the detection and alerting that catches them.
  • Threat modelling and secure architecture for cloud, container and API systems.
  • An engineering background. You are comfortable in a codebase. Our backend is Go. Prior Go experience is a plus and not a requirement.
  • Comfort in resource-constrained environments. Startups, small security teams or consultancies taught you to prioritize on risk, business impact and available resources.
  • The appetite to build a team. Prior leadership experience is a plus and not a requirement.
  • Working proficiency with Claude Code. Share specific examples.
  • Judgement about pace. You secure a company that ships daily without becoming the reason it stops. Guardrails over gates.
  • Experience of SOC 2, ISO 27001 or demanding enterprise security reviews.
  • Excellent spoken and written English.
  • European or African time zones (±3 hours from CET).
  • Available full-time (40 hours per week).
Nice to have
  • AI and LLM security: prompt injection, agent and tool permissions, model security, retrieval pipelines.
  • Early security hire experience.
  • Experience leading or mentoring security engineers.
  • Go.
  • Security tooling or automation you built yourself.
  • MDM, endpoint protection and identity provider administration (Google Workspace or similar).
  • Compliance automation tooling (Drata, Vanta, Secureframe or similar).
  • Security certifications. Valued as a signal, never required.
  • GDPR depth. Travel or GDS exposure.
  • German.
You are a great fit if you
  • See security as an engineering discipline. You ship fixes and guardrails, not slide decks.
  • Can explain a vulnerability to an engineer and its business risk to a client's security lead in the same afternoon.
  • Have done offensive work as a penetration tester or consultant and wanted broader ownership than producing reports.
  • Want to build something and own it, rather than advise on someone else's.
  • Are comfortable challenging unnecessary security bureaucracy and genuinely risky engineering decisions alike.
  • Get frustrated when a security fix takes weeks instead of days.
Ottieni la revisione del curriculum gratis e riservata.

o trascina qui il file.

Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Senior Security Engineer
Senior Security Engineer

The Mill Adventure Limited • Barcelona

Ibrido
EUR 70.000 - 90.000
Private health insurance
Learning budget
Work equipment of your choice
+2
Engineering Manager (Grafana Application Security)
Engineering Manager (Grafana Application Security)

Grafana • Spagna

Remoto
EUR 120.000 - 180.000
30 days vacation
Health stipend
Retirement plan
+6
Cloud Security Engineer
Cloud Security Engineer

Happyrobot Inc. • Bellprat

In loco
EUR 90.000 - 130.000
Healthcare coverage
Dental coverage
Vision coverage
+1
Arquitecto de Seguridad de Aplicaciones
Arquitecto de Seguridad de Aplicaciones

Itequia • Barcelona

In loco
EUR 90.000 - 120.000
Flexible hybrid model
Continuous learning opportunities
Low bureaucracy culture
Cloud Security Engineer
Cloud Security Engineer

Happyrobot • Madrid, Barcelona

In loco
EUR 70.000 - 110.000
Healthcare
Dental coverage
Vision coverage
+1
Information Security Architect - AI & Strategic Initiatives
Information Security Architect - AI & Strategic Initiatives

Ryanair Group Holdings • Madrid

Ibrido
EUR 120.000 - 150.000
Hybrid working model
Travel discounts
Health insurance discounts
Senior Platform Software Engineer
Senior Platform Software Engineer

Cello • Spagna

Remoto
EUR 70.000 - 120.000
AI Architect (AI for Security)
AI Architect (AI for Security)

Neurons Lab • Spagna

In loco
EUR 90.000 - 130.000
Offensive Security Engineer
Offensive Security Engineer

Jobgether SRL • Spagna

Remoto
EUR 90.000 - 130.000
Equity options
Remote-first
Career growth
+2
Head of Infrastructure & Security
Head of Infrastructure & Security

Deliverect • Madrid

In loco
USD 120.000 - 160.000