IT Cybersecurity Engineer

Werfen

Barcelona

Presencial

EUR 70.000 - 100.000

Jornada completa

hace 38 horas
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Werfen, a leader in medical technology, is seeking a Product Security Engineer to assess and improve the security of products, applications, cloud environments and enterprise infrastructure through offensive security activities.

You will perform penetration tests, security assessments and adversary simulations across traditional IT, cloud platforms, modern applications and AI-enabled systems, collaborating with development, QA and DevOps to deliver actionable remediation and secure product

Formación

  • Bachelor's degree in CS/Cybersecurity or equivalent practical experience.
  • 4+ years in Offensive Security, Penetration Testing, or Red Teaming.
  • Experience in API/Web pentesting, cloud security, and AI security assessments.
  • Knowledge of security frameworks and best practices.

Responsabilidades

  • Plan and execute penetration tests of healthcare products, applications, medical devices, and supporting infrastructure.
  • Perform security assessments of web apps, APIs, desktop apps, embedded systems, cloud environments, and AI-enabled products.
  • Evaluate security of cloud-native architectures, identity services, and containerized environments.
  • Assess AI features for security risks including prompt injection and data exposure.
  • Produce high-quality technical reports with findings and remediation guidance.

Conocimientos

Penetration testing
Cloud security
AI security
Red Teaming
Reverse engineering
Threat modeling
Security reporting

Educación

Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent

Herramientas

Docker
Kubernetes
AWS
GCP
Azure
OWASP
MITRE ATT&CK

Descripción del empleo

This position is part of the Product Security Department and is responsible for assessing and improving the security posture of the organization's products, applications, cloud environments, and enterprise infrastructure through offensive security activities.

The primary responsibility of this position is to identify, validate, and communicate security vulnerabilities before they can be exploited by attackers. The role involves performing penetration tests, security assessments, and adversary simulations across traditional IT environments, cloud platforms, modern applications, and Artificial Intelligence (AI) systems.

The engineer will collaborate with development, infrastructure, cloud, and engineering teams to improve the organization's overall security posture by providing actionable remediation guidance and security best practices.

  • Plan and execute penetration tests of healthcare products, applications, medical devices, and supporting infrastructure in accordance with defined testing methodologies and project timelines.
  • Perform security assessments of web applications, APIs, desktop applications, embedded systems, cloud environments, and AI-enabled products to identify exploitable vulnerabilities and security weaknesses.
  • Evaluate the security of cloud-native architectures, identity services, and containerized environments supporting healthcare solutions.
  • Assess Artificial Intelligence features and applications for security risks, including prompt injection, unauthorized access, sensitive data exposure, and misuse of AI models.
  • Contribute to the continuous improvement of penetration testing methodologies, tooling, automation, and testing procedures to address emerging technologies and evolving threats.
  • Stay current with the latest offensive security techniques, healthcare cybersecurity threats, cloud technologies, and AI security research to ensure testing methodologies remain effective and aligned with industry best practices.
  • Collaborate with product development and engineering teams to communicate security findings, provide technical guidance, and support secure product development throughout the product lifecycle.
  • Validate the effectiveness of implemented security fixes through remediation verification and follow-up security testing.
  • Produce high-quality technical reports that clearly describe findings, risk levels, exploitation evidence, and practical remediation recommendations for engineering teams.
Networking/Key relationships

A cybersecurity engineer interacts with different stakeholders including:

  • Software Development teams to coordinate security assessments, communicate technical findings, and support the remediation and validation of identified vulnerabilities.
  • Quality Assurance (QA) teams to integrate penetration testing activities into product release cycles and verify security fixes prior to deployment.
  • Cloud Engineering and DevOps teams to assess cloud infrastructure, containerized environments, CI/CD pipelines, and cloud-native services, providing recommendations to improve security posture.
  • Product Owners (PO) and Product Security Officers (PSO) to define assessment scope, prioritize security risks based on business impact, and support secure product releases.
  • Product Security Architects (PSA) to align penetration testing activities with organizational security strategies, threat models, and vulnerability management processes.
Minimum Knowledge & Experience required for the position:

The qualifications required for this position are:

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience.

Minimum professional experience:

  • 4+ years in Offensive Security, Penetration Testing or Red Teaming.

Experience in several of the following areas:

  • API and Web Application pentesting.
  • Cloud security (AWS, GCP and Azure).
  • Docker and Kubernetes security
  • AI security assessments.
  • Active Directory
  • Reverse Engineering and Binary Exploitation capabilities.

The following work experience and qualifications are a plus:

  • Certifications such as: eJPT, OSCP, CPTS, CRTO, CRTE, or equivalent.
  • Knowledge of security frameworks such as OWASP and MITRE ATT&CK.
Additional valuable experience
  • Experience in Red Teaming Operations
  • Experience in CTFs in platforms such as Hack The Box
  • Knowledge of relevant standards such as ISO 27001.
  • Knowledge of medical device regulations (FDA, GDPR).
  • Solid knowledge on SW testing process and secure methodology (SSDLC).
Skills & Capabilities:

The skills and capabilities required by the position are:

  • Strong analytical and problem-solving skills to identify, validate, and assess security vulnerabilities and recommend effective remediation strategies.
  • Effective communication skills to convey complex cybersecurity concepts to both technical and non-technical stakeholders.
  • Willingness to stay updated on the latest cybersecurity trends, threats and technologies through continuous learning and professional development.
  • Ability to collaborate with cross-functional teams, share information, and work together to enhance overall cybersecurity posture.
  • Strong interpersonal skills with the ability to build trust, foster teamwork, and contribute positively to a collaborative working environment.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cybersecurity Specialist
Cybersecurity Specialist

Randstad España • Madrid

Presencial
EUR 60.000 - 95.000
Security Engineer (Infrastructure)
Security Engineer (Infrastructure)

Hiring • Málaga

Presencial
EUR 45.000 - 65.000
Security Engineer (Infrastructure) - ESK Agency
Security Engineer (Infrastructure) - ESK Agency

hiring • Málaga

Presencial
EUR 50.000 - 80.000
Information Security Engineer
Information Security Engineer

Jobtailor • Madrid

Presencial
EUR 70.000 - 90.000
Product Security Engineer
Product Security Engineer

Gomining • España

Híbrido
EUR 65.000 - 90.000
Professional development
Flexible work arrangement
Paid time off
+2
Cyber Security Analyst
Cyber Security Analyst

Graphic Packaging International • Cataluña

Presencial
EUR 42.000 - 62.000
Senior Cybersecurity Engineer for Secure Access Network
Senior Cybersecurity Engineer for Secure Access Network

Roche • Madrid

Presencial
EUR 60.000 - 80.000
Information Security Engineer
Information Security Engineer

Comoro Ltd • Barcelona

Presencial
EUR 70.000 - 90.000
Senior Cybersecurity Engineer for Secure Access Network
Senior Cybersecurity Engineer for Secure Access Network

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 60.000 - 80.000
Cyber Security Specialist - Red Team
Cyber Security Specialist - Red Team

HBX Group • Comunidad Valenciana

Presencial
EUR 70.000 - 100.000