It Cybersecurity Engineer

Werfen

Barcelona

Presencial

EUR 60.000 - 90.000

Jornada completa

hace 43 horas
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Werfen busca un Ingeniero de Seguridad de Producto para evaluar y mejorar la postura de seguridad de productos y entornos en la nube mediante pruebas de penetración y simulaciones avanzadas. Colaborarás con desarrollo, infraestructura y equipos de DevOps para remediar vulnerabilidades y fortalecer controles de seguridad en todo el ciclo de vida del producto.

Se requiere experiencia en seguridad ofensiva (4+ años), dominio de pruebas API/web, cloud (AWS/GCP/Azure), Docker/Kubernetes, AD y

Formación

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience.
  • 4+ years in Offensive Security, Penetration Testing or Red Teaming.
  • Experience in API and Web Application pentesting.
  • Cloud security (AWS, GCP and Azure).
  • Docker and Kubernetes security.
  • AI security assessments.
  • Active Directory knowledge.
  • Reverse Engineering and Binary Exploitation capabilities.
  • Certifications such as: eJPT, OSCP, CPTS, CRTO, CRTE, or equivalent.
  • Knowledge of OWASP and MITRE ATT&CK frameworks.

Responsabilidades

  • Plan and execute penetration tests of healthcare products and supporting infrastructure according to defined methodologies.
  • Perform security assessments of web apps, APIs, desktop apps, embedded systems, cloud environments and AI-enabled products.
  • Evaluate security of cloud-native architectures and containerized environments.
  • Assess AI features for security risks including prompt injection and data exposure.
  • Contribute to improving penetration testing methodologies and tooling.
  • Stay current with offensive security trends and healthcare cybersecurity threats.
  • Collaborate with product teams to communicate findings and guide remediation.
  • Verify fixes through remediation testing and follow-up assessments.
  • Produce detailed technical reports with findings and remediation recommendations.

Conocimientos

Analytical thinking
Problem solving
Communication skills
Team collaboration
Adaptability

Educación

Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent

Herramientas

Docker
Kubernetes
Cloud security tooling

Descripción del empleo

Descripción del trabajo


This position is part of the Product Security Department and is responsible for assessing and improving the security posture of the organization's products, applications, cloud environments, and enterprise infrastructure through offensive security activities.


The primary responsibility of this position is to identify, validate, and communicate security vulnerabilities before they can be exploited by attackers. The role involves performing penetration tests, security assessments, and adversary simulations across traditional IT environments, cloud platforms, modern applications, and Artificial Intelligence (AI) systems.


The engineer will collaborate with development, infrastructure, cloud, and engineering teams to improve the organization's overall security posture by providing actionable remediation guidance and security best practices.



  • Plan and execute penetration tests of healthcare products, applications, medical devices, and supporting infrastructure in accordance with defined testing methodologies and project timelines.

  • Perform security assessments of web applications, APIs, desktop applications, embedded systems, cloud environments, and AI-enabled products to identify exploitable vulnerabilities and security weaknesses.

  • Evaluate the security of cloud-native architectures, identity services, and containerized environments supporting healthcare solutions.

  • Assess Artificial Intelligence features and applications for security risks, including prompt injection, unauthorized access, sensitive data exposure, and misuse of AI models.

  • Contribute to the continuous improvement of penetration testing methodologies, tooling, automation, and testing procedures to address emerging technologies and evolving threats.

  • Stay current with the latest offensive security techniques, healthcare cybersecurity threats, cloud technologies, and AI security research to ensure testing methodologies remain effective and aligned with industry best practices.

  • Collaborate with product development and engineering teams to communicate security findings, provide technical guidance, and support secure product development throughout the product lifecycle.

  • Validate the effectiveness of implemented security fixes through remediation verification and follow-up security testing.

  • Produce high-quality technical reports that clearly describe findings, risk levels, exploitation evidence, and practical remediation recommendations for engineering teams.


Networking/Key relationships


A cybersecurity engineer interacts with different stakeholders including:



  • Software Development teams to coordinate security assessments, communicate technical findings, and support the remediation and validation of identified vulnerabilities.

  • Quality Assurance (QA) teams to integrate penetration testing activities into product release cycles and verify security fixes prior to deployment.

  • Cloud Engineering and DevOps teams to assess cloud infrastructure, containerized environments, CI/CD pipelines, and cloud-native services, providing recommendations to improve security posture.

  • Product Owners (PO) and Product Security Officers (PSO) to define assessment scope, prioritize security risks based on business impact, and support secure product releases.

  • Product Security Architects (PSA) to align penetration testing activities with organizational security strategies, threat models, and vulnerability management processes.


Minimum Knowledge & Experience required for the position:


The qualifications required for this position are:



  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience.


Minimum professional experience:



  • 4+ years in Offensive Security, Penetration Testing or Red Teaming.


Experience in several of the following areas:



  • API and Web Application pentesting.

  • Cloud security (AWS, GCP and Azure).

  • Docker and Kubernetes security

  • AI security assessments.

  • Active Directory

  • Reverse Engineering and Binary Exploitation capabilities.


The following work experience and qualifications are a plus:



  • Certifications such as: eJPT, OSCP, CPTS, CRTO, CRTE, or equivalent.

  • Knowledge of security frameworks such as OWASP and MITRE ATT&CK.


Additional valuable experience



  • Experience in Red Teaming Operations

  • Experience in CTFs in platforms such as Hack The Box

  • Knowledge of relevant standards such as ISO 27001.

  • Knowledge of medical device regulations (FDA, GDPR).

  • Solid knowledge on SW testing process and secure methodology (SSDLC).


Skills & Capabilities:


The skills and capabilities required by the position are:



  • Strong analytical and problem-solving skills to identify, validate, and assess security vulnerabilities and recommend effective remediation strategies.

  • Effective communication skills to convey complex cybersecurity concepts to both technical and non-technical stakeholders.

  • Willingness to stay updated on the latest cybersecurity trends, threats and technologies through continuous learning and professional development.

  • Ability to collaborate with cross-functional teams, share information, and work together to enhance overall cybersecurity posture.

  • Strong interpersonal skills with the ability to build trust, foster teamwork, and contribute positively to a collaborative working environment.


Travel requirements:


Less than 10% of the time

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cybersecurity Specialist
Cybersecurity Specialist

Randstad España • Madrid

Presencial
EUR 60.000 - 95.000
Cyber Security Specialist - Red Team
Cyber Security Specialist - Red Team

HBX Group • Valencia

Presencial
EUR 90.000 - 130.000
Security Engineer (Infrastructure)
Security Engineer (Infrastructure)

Hiring • Málaga

Presencial
EUR 45.000 - 65.000
Security Engineer (Infrastructure) - ESK Agency
Security Engineer (Infrastructure) - ESK Agency

hiring • Málaga

Presencial
EUR 50.000 - 80.000
Cybersecurity Engineer for Network Security
Cybersecurity Engineer for Network Security

Roche • Madrid

Presencial
EUR 50.000 - 70.000
Product Security Engineer
Product Security Engineer

Gomining • España

Híbrido
EUR 65.000 - 90.000
Professional development
Flexible work arrangement
Paid time off
+2
OT Cybersecurity Engineer
OT Cybersecurity Engineer

OW Ocean Winds • Madrid

Presencial
EUR 30.000 - 55.000
Cybersecurity Engineer for Network Security observability
Cybersecurity Engineer for Network Security observability

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 65.000 - 85.000
CYBERSECURITY SPECIALIST (F/M/X)
CYBERSECURITY SPECIALIST (F/M/X)

Michael Page • Bilbao

Presencial
EUR 45.000 - 65.000
Senior Cybersecurity Engineer for Secure Access Network
Senior Cybersecurity Engineer for Secure Access Network

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 60.000 - 80.000