Cybersecurity Engineer

Kantar XTEL

España

A distancia

EUR 55.000 - 90.000

Jornada completa

14 días+
Generador de candidaturas

Transforma esta oferta en una entrevista: un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Remote or Hybrid working set-up
Flexible working hours
Competitive Salary Package and Bonus

Descripción de la vacante

XTEL is seeking a Cybersecurity Engineer to strengthen security posture across our platform, applications, and Microsoft environment. You’ll join a growing Security & Compliance team that already maintains a mature compliance foundation (ISO 27001:2022, SOC 2 Type 2, SOC 1 Type 2, ISAE 3402) and an established GRC function, alongside a managed SOC, an IT team, and a Cloud Operations team.

This is a very hands-on role where you’ll lead vulnerability management, work with Engineering and Product

Formación

  • 3+ years in cybersecurity engineering, security operations, DevSecOps, or security-focused IT (Azure preferred).
  • Vulnerability management: prioritizing and driving remediation across teams.
  • AppSec and SDLC controls (CI/CD security, SAST/DAST/IAST/SCA).
  • Microsoft environments security: Entra ID, Intune, CA, M365 controls.
  • Azure cloud security and CSPM knowledge.
  • Self-directed, able to work with limited guidance.
  • Strong communication and ownership across multiple teams.
  • English proficiency.

Responsabilidades

  • Own intake, triage, risk-based prioritization, remediation tracking, validation, SLAs, and reporting for Azure environments and the dev pipeline.
  • Improve secure SDLC with CI/CD security gates, SAST/DAST/IAST/SCA, and secure code review.
  • Hardening of Microsoft environment including identity, endpoint protections, and M365 controls.
  • Coordinate SOC-driven remediation and root-cause follow-up.
  • Coordinate external penetration tests and internal testing.
  • Support patch management with IT and Cloud Operations.
  • Partner with Cloud Operations on Azure security architecture and CSPM.
  • Support security audits and evidence collection for ISO 27001/SOC/ISAE.
  • Translate findings into actionable guidance for engineers and GRC inputs.
  • Identify opportunities to raise security across the organization.

Conocimientos

Cybersecurity engineering
Security operations
DevSecOps
Azure security
CI/CD security
AppSec
Threat modeling
Communication
Self-direction

Herramientas

SAST
DAST
IAST
SCA
Code scanning
Entra ID

Descripción del empleo

About XTEL

XTEL is a leader in advanced, AI-driven solutions for consumer goods companies, combining cutting- edge technology, industry expertise, and data management to accelerate profitable revenue growth and value realization.

Position Overview

XTEL is hiring a Cybersecurity Engineer to strengthen XTEL’s security posture across our platform, applications, and Microsoft environment. You’ll join a growing Security & Compliance team that already maintains a mature compliance foundation (ISO 27001:2022, SOC 2 Type 2, SOC 1 Type 2, ISAE 3402) and an established GRC function, alongside a managed SOC, an IT team, and a Cloud Operations team.

This is a very hands-on role where you’ll lead vulnerability management, work with Engineering and Product to embed security into the SDLC, partner with IT & Cloud Operations to continuously harden our Microsoft environments, and drive triage and remediation of issues surfaced by our SOC. Because you’ll work alongside existing IT, Cloud Operations, and GRC capabilities, success depends on collaboration and influence as much as technical depth.

The ideal candidate must be proactive and self-directed: actively seeking out opportunities to improve security across the organization and able to operate effectively with limited guidance and oversight.

Key Responsibilities
  • Vulnerability management. Own intake, triage, risk-based prioritization, remediation tracking, validation, SLAs, and reporting across our Azure environments (dev, test, prod, and customer-facing) and the development pipeline.

  • Secure SDLC & CI/CD. Partner with Engineering, Product, and QA to continually improve secure development practices:

    1. Pipeline security and security gates in CI/CD.
    2. SAST, DAST, IAST, dependency/software composition (SCA), and code scanning.
    3. Secure code review practices, threat modeling, and security requirements in design.
  • Microsoft environment hardening. Work continuously with IT to further secure infrastructure - identity and access management, endpoint protections, M365 controls, and configuration/hardening baselines.

  • SOC-driven remediation. Coordinate and drive triage and remediation for alerts, incidents, and vulnerabilities reported by XTEL’s SOC, including root cause follow up.

  • Penetration testing. Coordinate external penetration tests (scope, execution support, findings management, retesting and closure), and conduct internal testing.

  • Patch management. Support patch management processes and verification in partnership with IT and Cloud Operations.

  • Cloud security partnership. Partner with Cloud Operations on Azure security architecture, secure-by-design patterns, CSPM, secrets management, and network security.

  • Compliance & audit support. Support security audits and continuous compliance (ISO 27001, SOC 1, SOC 2 Type 2, ISAE 3402), including evidence collection and control improvement.

  • Cross-functional enablement. Translate security findings into clear, actionable guidance for engineers and into evidence and inputs for the GRC function.

  • Continuous improvement. Proactively identify and act on opportunities to raise the security bar across the organization.

Qualifications
  • Experience: 3+ years in cybersecurity engineering, security operations, DevSecOps, or security-focused IT (cloud-native SaaS experience strongly preferred, ideally on Azure).

  • Vulnerability management: Proven track record running vulnerability management beyond scanning - prioritizing and driving remediation to closure across teams.

  • Application & SDLC security: Working knowledge of AppSec and SDLC controls (CI/CD security, SAST/DAST/IAST/SCA, secure code review) and the ability to embed security without slowing delivery.

  • Microsoft environment: Hands‑on experience securing Microsoft environments (Entra ID, Intune, Conditional Access, endpoint protections, M365 controls).

  • Cloud security: Working knowledge of Azure security services and cloud security posture management.

  • Self-direction: Ability to work independently, set priorities, and build or mature programs in a lean environment with limited guidance.

  • Communication & ownership: Strong communicator who can drive work and build trust across Engineering, Product, Cloud Operations, IT, and Compliance.

  • English: English proficiency
Nice to have:
  • Familiarity operating within an ISO 27001 / SOC 2 environment and supporting audits.

  • Experience with infrastructure-as-code and securing CI/CD at scale.

  • Hands‑on penetration testing or offensive security experience (e.g., OSCP).

  • Experience with compliance automation tooling (e.g., Drata).

  • Relevant certifications (e.g., GIAC, CISSP, AZ-500, SC-200, SC-300).

Who You Are:
  • Proactive and self‑starting – you find work that needs doing and do it without waiting to be told.

  • Pragmatic and risk‑based – you focus effort where it reduces the most risk and balance security with delivery.

  • Collaborative – you achieve outcomes through influence across teams you don’t manage.

Geographical Location:
  • Belgium, Leuven.
  • Europe Remote
What We Offer
  • Remote or Hybrid working set‑up

  • Flexible working hours;

  • Competitive Salary Package and Bonus scheme;

  • A challenging role in a fast‑growing AI‑driven company;

  • A diverse and international team with strong ownership and a can‑do mentality.

  • Opportunities to contribute meaningfully to the organization’s growth and development.

Equal Opportunities Statement

If you have strengths to share, we’d love to hear from you. We value diverse backgrounds and experiences, so don’t hesitate to apply even if you don’t meet all criteria.

XTEL is an equal opportunity employer and values diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform crucial job functions, and to receive other benefits and privileges of employment.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Azure Security Engineer - Secure SDLC & Cloud Posture
Azure Security Engineer - Secure SDLC & Cloud Posture

Kantar XTEL • España

A distancia
EUR 55.000 - 90.000
Remote or Hybrid working set-up
Flexible working hours
Competitive Salary Package and Bonus
Head Of Cybersecurity Operations
Head Of Cybersecurity Operations

Mindmatch • Barcelona

Presencial
EUR 90.000 - 130.000
Hybrid work model (3 días onsite / 2?
Oficina moderna en Barcelona
Equipo internacional y cross-funcional
+2
Head of Cybersecurity Operations
Head of Cybersecurity Operations

Cellnex Telecom • Cataluña

Híbrido
EUR 110.000 - 140.000
Hybrid work model
Barcelona HQ
International team
+1
Cybersecurity Architect.
Cybersecurity Architect.

NAGRA • Madrid

Presencial
EUR 110.000 - 150.000
Generous time off
Tuition reimbursement
Competitive compensation
Cybersecurity Architect (Managed Risk And Exposure
Cybersecurity Architect (Managed Risk And Exposure

Kudelski Security • Crémenes

Presencial
EUR 90.000 - 125.000
Tuition reimbursement
Generous time off
Cybersecurity Architect (Managed Risk And Exposure
Cybersecurity Architect (Managed Risk And Exposure

Kudelski Security • Mos

Presencial
EUR 90.000 - 130.000
Cybersecurity Manager
Cybersecurity Manager

GMV Spain • Madrid

Híbrido
EUR 60.000 - 90.000
Hybrid work model
Relocation package
Flexible hours
Cybersecurity Architect (Managed Risk And Exposure
Cybersecurity Architect (Managed Risk And Exposure

Mindmatch • Valencia

Presencial
EUR 70.000 - 110.000
Telecom & DevOps Engineer (Junior)
Telecom & DevOps Engineer (Junior)

BICS • Madrid

Híbrido
EUR 42.000 - 66.000
Flexible Workstyle
IT Security Engineer
IT Security Engineer

Tensec • Madrid

Presencial
EUR 70.000 - 90.000
Work on cutting-edge aerospace projects
Collaborate globally with top engineers
Experience high-growth company environment
+1