Offensive Security Engineer

Factorial HR

Barcelona

Híbrido

EUR 40.000 - 55.000

Jornada completa

14 días+
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Health insurance
Gym access
Cobee benefits
Language classes
Breakfast in the office
Food discounts
Pet friendly
Career growth

Descripción de la vacante

Factorial is seeking an Application Security Engineer in Barcelona to proactively hunt for vulnerabilities and strengthen defenses. You will test applications, APIs, and AI-powered features, reproduce external reports, and work with product teams to remediate issues.

The role requires 3+ years in application security and fluency in English. The team collaborates across Product and Engineering to ship with security baked in, while offering a flexible office-first, hybrid model.

Formación

  • 3+ years of professional experience in Application Security, Offensive Security, or Penetration Testing.
  • Web Application Penetration Testing experience is mandatory.
  • Fluency in English.
  • Degree in Engineering or Computer Science; strong knowledge of web apps, databases, networks, and OS.

Responsabilidades

  • Perform proactive penetration testing across Factorial’s applications, APIs, infrastructure, and AI-powered features.
  • Reproduce and validate vulnerability reports from third parties.
  • Collaborate with development teams to remediate security findings and enhance secure coding practices.
  • Improve validation, triage, and remediation of vulnerabilities from bug bounty reports, internal testing, automated controls, and external research.
  • Hunt for recurring or legacy vulnerability patterns based on root cause analysis and security findings.
  • Build and improve security automations, agents, skills, and CI/CD controls for early issue detection.
  • Help secure Factorial’s use of AI across product and internal workflows, including LLMs, agents, data access, tools, permissions, and abuse scenarios.
  • Contribute to development of security tools, automations, and infrastructure.
  • Stay up-to-date with latest security research and AI security risks.

Conocimientos

Web pentesting
Python
Bash
English fluency

Educación

Engineering or Computer Science degree

Herramientas

Ruby on Rails

Descripción del empleo

Application Security Engineer

Hey there, Cybersecurity Enthusiasts! At Factorial, we’re on the hunt for a skilled Application Security Engineer to join our Security Team. We need your expertise to proactively hunt for vulnerabilities and strengthen our defenses against cyber threats. If you have a passion for ethical hacking and want to make an impact in a dynamic tech environment, we’d love to hear from you!

Ready to be part of the challenge?

About the team

Security at Factorial works side by side with Product and Engineering to help a fast-moving, AI-native company ship without losing control of risk. Our mission is to protect Factorial and our customers while making security a practical part of how software is designed, built, tested, and operated.

The work goes far beyond finding vulnerabilities: we test real product surfaces, help teams fix issues properly, and turn repeated security needs into guardrails, automation, and CI/CD controls that developers can use every day. AI is part of Factorial’s culture, product, and way of working from day one, so Security also helps define how teams use agents, LLMs, tools, and company data safely at scale, while actively challenging those systems with an attacker mindset.

It’s a team for people who want to keep learning, move across different security problems, and build security that can keep up with the speed of the company.

What You’ll be doing?
  • Perform proactive penetration testing across Factorial’s applications, APIs, infrastructure, and AI-powered features.
  • Reproduce and validate vulnerability reports submitted by third parties, like our bug bounty program.
  • Collaborate with development teams to remediate security findings and enhance secure coding practices.
  • Improve how we validate, triage, and remediate vulnerabilities from bug bounty reports, internal testing, automated controls, and external research.
  • Hunt for recurring or legacy vulnerability patterns based on root cause analysis, previous incidents, and security findings.
  • Build and improve security automations, agents, skills, and CI/CD controls that help engineering teams catch and fix issues earlier.
  • Help secure Factorial’s use of AI across product and internal workflows, including LLMs, agents, data access, tools, permissions, and abuse scenarios.
  • Contribute to the development of our security tools, automations, and infrastructure.
  • Stay up-to-date with the latest security research, threats, attack techniques, and emerging AI security risks.
What are we looking for?
  • You have 3+ years of professional experience in Application Security, Offensive Security, or Penetration Testing. Web Application Penetration Testing experience is mandatory.
  • You hold a degree in Engineering or Computer Science and have strong knowledge of web applications, databases, network protocols, and operating systems.
  • You possess strong knowledge in cybersecurity fundamentals, CVSS, testing methodologies, and tooling.
  • You are fluent with scripting or programming languages used in security testing and automation, such as Python or Bash.
  • You are technical, curious, and comfortable moving across different security problems instead of specializing in one area.
  • You like to attack systems, but you also enjoy building tools, automations, guardrails, and practical solutions that make security scale.
  • You do not need to be an expert in every technology, but you should be able to reason critically, learn fast, use AI effectively, and design pragmatic solutions.
  • You have curiosity and willingness to learn about AI security topics such as LLM testing, prompt injection, agentic workflows, data exposure, tool permissions, RAG security, and secure AI adoption.
  • Certifications like BSCP or eWPTX are highly regarded but not mandatory.
  • Experience with Ruby / Ruby on Rails applications is highly regarded, but not mandatory.
  • Fluency in English is required.
Compensation

At Factorial we don't evaluate you by years of experience but by your knowledge and skills. We use our Career Path with a rubric framework where we define what is expected for each experience level and skill. This framework allows you to know your current level and what you need to keep growing. We love transparency, so our Career Path includes the salaries for each level, which we share during the first interview to ensure alignment. The salary range for this position is between 40.000 - 55.000€ base + 7-10% variable based on performance paid quarterly + ESOP plan.

How We Work

At Factorial, we believe the best products are built when people come together—in person—to collaborate, challenge ideas, and move fast. That’s why our Engineering Team follows an office-first, flexible approach.

We work on-site several days a week (80%), using that time to connect, align, and innovate as a team. However, we also understand the importance of focus and flexibility, so we support remote work when it makes sense (20%), whether for deep work, personal needs, or just a change of scenery.

This balance helps us stay agile, creative, and closely connected, while giving everyone the space to do their best work.

Hiring Process
  • Intro Call – Chat with our Talent Partner about your journey and goals.
  • Hiring Manager Interview – Deep dive into your product mindset, teamwork, and problem-solving.
  • Technical Interview – A collaborative technical discussion based on real‑life problems.
  • Final Coffee Chat – A relaxed conversation with our CTO & VP of Engineering to explore our vision, culture, and your growth.

The whole process is remote, using videoconferencing tools!

About Factorial

At Factorial, we’re building the leading AI Business Management Software for companies of all sizes. Our platform centralizes key workflows across HR, Finance, Talent, Operations, and IT, freeing teams from manual processes so they can focus on what really matters: leading, growing, and taking care of their people. With over 1,500 employees across Europe, Asia, Africa, and America, we are one of Europe’s fastest-growing SaaS companies, proudly headquartered in Barcelona. If you're excited to shape the future of business management technology, we’d love to meet you.

We believe in diverse talent: we welcome applicants from all backgrounds and strongly encourage people of diverse experiences and identities to apply.

We believe in inclusion: we are committed to equal opportunities and actively promote workplace inclusion of people with disabilities. If you would like to learn more about our inclusive recruitment processes, you are welcome to indicate so optionally and we will share additional information with you.

Our Values
  • We own it: We take responsibility for every project. We make decisions, not excuses.
  • We learn and teach: We're dedicated to learning something new every day and, above all, share it.
  • We partner: Every decision is a team decision. We trust each other.
  • We grow fast: We act fast. We think that the worst mistake is not learning from them.
Perks
  • High growth, multicultural and friendly environment
  • Alan as private health insurance
  • Healthy life with Wellhub (Gyms, pools, outdoor classes)
  • Save expenses with Cobee
  • Language classes
  • Breakfast in the office and organic fruit
  • Food discounts with Nora
  • Pet Friendly
  • Much more that we’ll spill during the interview process!

Wanna learn more about us? Check our website!

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Offensive Security Engineer
Offensive Security Engineer

Factorial • Barcelona

Híbrido
EUR 40.000 - 55.000
Private health insurance
Wellhub gym access
Office breakfast
Senior Product Software Engineer - Operations Domain
Senior Product Software Engineer - Operations Domain

Factorial HR • Barcelona

Híbrido
EUR 90.000 - 120.000
Alan as private health insurance
Wellhub gym membership
Cobee benefits platform
+4
AI Software Developer - Founding role
AI Software Developer - Founding role

Factorial HR • Barcelona

Híbrido
EUR 90.000 - 120.000
Private health insurance
WellHub gym access
Cobee benefits
+4
Technical Support & Data Operations Engineer
Technical Support & Data Operations Engineer

Factorial • Barcelona

Presencial
EUR 42.000 - 64.000
High growth, multicultural andfriendly
Alan as private health insurance
Healthy life with Wellhub (Gyms, pools
+6
Senior Product Engineer - Operations Domain
Senior Product Engineer - Operations Domain

Factorial • Barcelona

Presencial
EUR 70.000 - 110.000
Alan private health insurance
Cobee benefits platform
Language classes
+2
Engineering Manager
Engineering Manager

Factorial • Oleiros

Híbrido
EUR 90.000 - 135.000
High growth environment
Private health insurance
Wellhub gym benefits
+3
Staff Engineer — Performance, Reliability & AI Automation
Staff Engineer — Performance, Reliability & AI Automation

Factorial HR • Madrid

Presencial
EUR 90.000 - 130.000
Staff Engineer — Performance, Reliability & AI Automation
Staff Engineer — Performance, Reliability & AI Automation

Factorial HR • Oleiros

Híbrido
EUR 100.000 - 140.000
Private health insurance
Wellhub gym
Cobee benefits
+5
Infrastructure Security Engineer
Infrastructure Security Engineer

Factorial HR • Barcelona

Híbrido
EUR 70.000 - 100.000
Alan private health insurance
Cobee
Payflow
+4
Staff AI Engineer - API & Integrations Team (Madrid)
Staff AI Engineer - API & Integrations Team (Madrid)

Factorial • Madrid

Híbrido
EUR 42.000 - 65.000
High growth environment
Private health insurance
Wellhub gym membership
+5