Senior Security Engineer

Spendesk

Barcelona

Híbrido

EUR 70.000 - 120.000

Jornada completa

Hace 4 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca la empresa.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Flexible on-site and remote policy
Latest Apple equipment
Moka.care access
Office snacks
Positive team
Location-specific benefits

Descripción de la vacante

Spendesk is building a dedicated Security Engineering function and is hiring the first senior member in this space. You will shape how we protect our platform, respond to threats, and cultivate a security-aware engineering culture from within.

This is an individual contributor role with high influence, focusing on technical depth. You will mentor an Associate Security Engineer, guide practices across squads, and serve as the security knowledge hub for engineering teams.

Formación

  • Proven track record of owning security outcomes end to end across multiple domains.
  • Experience across code auditing, infrastructure security (AWS/Linux), and incident response.
  • Hands-on expertise with SIEM operations and security tooling.
  • Ability to translate security findings into engineering-ready tools and processes.

Responsabilidades

  • Own and manage vulnerability & incident management program.
  • Lead security incident response, forensics, remediation coordination, and post-mortems.
  • Operate and evolve our SIEM platform, including detection rules and IOC indicators.
  • Drive secure development practices: threat modelling, CI/CD hardening, and secure code patterns.
  • Conduct security reviews of code, IaC, and multi-tenant AWS environments.
  • Develop and maintain security runbooks and operational documentation.

Conocimientos

Security architecture
Threat modelling
Incident response
Penetration testing
Scripting (Python/Bash)

Herramientas

ElasticSearch
AWS
Terraform
Okta

Descripción del empleo

At Spendesk, we're building the leading spend management platform for modern businesses, processing billions of euros across Europe and beyond. Security is at the heart of what we do: our customers trust us to safeguard their financial data, and we're committed to raising the bar for security in fintech.

We're creating a dedicated Security Engineering function. You'll be the first senior hire in this space, shaping how we protect our platform, how we respond to threats, and how we build a security‑aware engineering culture from the inside.

Your Mission

You'll be the security conscience for engineering: building tooling, training developers, and partnering with Infrastructure on secure‑by‑default solutions. You own the technical security roadmap: partnering with the compliance team to identify risks, translating findings into actionable engineering‑native tools and processes, driving remediation, and raising the bar across the organisation.

This is a pure engineering role, not governance or compliance: a separate team owns policy and risk frameworks. It's an individual contributor track with high influence, focused on technical depth, not people management. You'll mentor an Associate Security Engineer, shape practices across squads, and be the go‑to person when engineering teams need security guidance.

You'll be hands‑on across the full security surface from day one. As the team grows, you'll move from day‑to‑day operations toward architecture, strategy, and mentoring, acting as the escalation point for the Associate Security Engineer.

Key Responsibilities
Vulnerability & incident management
  • Own and operate our bug bounty program: manage the platform, set escalation thresholds, and drive strategic improvements.
  • Act as escalation point for vulnerability triage, taking the lead on complex or high‑severity findings.
  • Lead security incident response: qualification, forensics (including fraud investigations), fix coordination, post‑mortem, and resolution tracking.
Detection & SIEM
  • Own our SIEM platform (ElasticSearch, multi‑node Linux): architecture, detection rules, and indicators of compromise.
  • Build and evolve detection coverage, focusing on signal quality over manual toil.
  • Build and maintain security runbooks and operational documentation.
Identity & access management
  • Own IAM implementation and operations for product and infrastructure systems, downstream of corporate IT: SSO/MFA configuration, role and access‑rights implementation, periodic permission reviews, and secrets rotation.
  • Work within the authentication standards set by the security governance team.
Secure development & audits
  • Embed security into the development lifecycle: threat modelling, secure code patterns, CI/CD hardening.
  • Conduct technical security reviews of code (TypeScript, Node.js, Python), infrastructure‑as‑code (Terraform), and multi‑tenant AWS environments.
  • Drive security tooling in CI/CD: design and own the automated gate suite (SAST, SCA, container scanning, AI‑generated code risk detection) and ensure pipeline coverage scales with engineering growth.
  • Assess and govern AI tooling adoption across engineering: define security standards for code assistants and LLM‑powered workflows, and conduct AI‑specific threat modelling.
  • Coordinate and execute penetration tests and security audits: prepare environments, manage auditor relationships, drive post‑audit action plans.
  • Drive remediation within the qualification rules and timeframes set by the security governance team.
Education & influence
  • Coach engineers on secure development through workshops, secure‑code guidance, and design reviews.
  • Surface security risks and recommendations to engineering leadership; own the security backlog and roadmap.
  • Partner with Infrastructure on secure‑by‑default solutions.
Must‑haves
What We're Looking For
  • A track record of owning security outcomes end to end, with hands‑on experience across at least three of: code auditing, infrastructure security (AWS/Linux), penetration testing, SIEM operations, incident response.
  • Ability to own a roadmap: identify priorities, build a plan, execute autonomously, and communicate progress to non‑specialists.
  • Deep understanding of modern web architectures (microservices, cloud‑native, PaaS/SaaS) and where they break.
  • Strong scripting and automation ability (Python, Bash, or similar).
  • Experience mentoring other engineers or security practitioners.
  • Excellent communication: you can explain a CVSS 9.8 to a PM and get them to prioritise it.
Nice‑to‑haves
  • Experience with ElasticSearch / ELK stack in production.
  • Familiarity with AWS, GCP, Snowflake, Datadog, Okta.
  • Knowledge of security standards and frameworks (ISO 27001, OWASP, SOC 2, PCI‑DSS).
  • Experience in a regulated fintech or payments environment.
  • Reverse engineering and analysis of minified/obfuscated code.

Not ticking every box? We’d still love to hear from you. At Spendesk, we value skills, potential and diverse experiences.

About Spendesk

Spendesk is the AI‑powered spend management and procurement platform that transforms company spending. By simplifying procurement, payment cards, expense management, invoice processing, and accounting automation, Spendesk sets the new standard for spending at work. Its single, intelligent solution makes efficient spending easy for employees and gives finance leaders the full visibility and control they need across all company spend, even in multi‑entity structures. Trusted by thousands of companies, Spendesk supports over 200,000 users across brands such as Payfit, Accor, Welcome to the Jungle, Swile, Big Mamma, Malt and Yousign. With offices in the United Kingdom, France, Spain and Germany, Spendesk also puts community at the heart of its mission.

About Our People & Culture

We believe that people do their best work when they're given the freedom to thrive and grow. That's why liberation is at the core of everything we do. We empower Spendeskers to take ownership of their work, to navigate ambiguity, and seize every opportunity. Spendeskers come from all over the world (35+ countries and counting!) but we have plenty in common: we're bold, ever‑curious, committed to kindness, and tackle every challenge with a positive mindset.

About Our Benefits
  • Flexible on‑site and remote policy
  • Latest Apple equipment — the tools you need to excel
  • Access to Moka.care — for emotional and mental health wellbeing
  • Great office snacks — to fuel your day
  • A positive team to work with daily!
  • We also offer location‑specific benefits tailored to each market, including health insurance, wellness allowances, commuter support, meal vouchers, and gym memberships — ensuring you're well supported wherever you're based.
Diversity & Inclusion

At Spendesk, we're committed to fostering an environment where all differences are encouraged, supported and celebrated. We're building our culture for everyone, with everyone. Our goal is to attract and build a diverse, equal and inclusive team, where everyone feels welcome and we truly embrace and encourage people from all backgrounds to apply.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Platform SRE: Automate & Scale Cloud Infra
Platform SRE: Automate & Scale Cloud Infra

Spendesk • Barcelona

Presencial
Confidential
Head of Engineering
Head of Engineering

Spendesk • Barcelona

Híbrido
EUR 180.000 - 240.000
Flexible on-site and remote policy
Apple equipment
Moka.care
+1
Head of Engineering
Head of Engineering

Spendesk • Bellprat

Híbrido
EUR 180.000 - 250.000
Flexible on-site and remote policy
Latest Apple equipment
Moka.care for wellbeing
+2
Account Manager - DACH market
Account Manager - DACH market

Spendesk, Inc. • Barcelona

Híbrido
EUR 42.000 - 64.000
Flexible on-site and remote policy
Alan health insurance
Meal vouchers (€6 per working day)
+5
Team Lead, Sales – Spain | Coach, Close & Grow Deals
Team Lead, Sales – Spain | Coach, Close & Grow Deals

Spendesk, Inc. • Barcelona

Híbrido
EUR 50.000 - 70.000
Flexible on-site and remote policy
Health insurance (fully covered)
Meal vouchers
+5
Backend Software Engineer (AI Squad)
Backend Software Engineer (AI Squad)

Spendesk • Barcelona

Híbrido
EUR 90.000 - 130.000
Flexible on-site and remote policy
Latest Apple equipment
Moka.care for wellbeing
+1
Account Executive Iberia
Account Executive Iberia

Spendesk • Barcelona

Presencial
EUR 50.000 - 80.000
Flexible on-site and remote policy
Alan health insurance
Meal vouchers through Edenred
+5
Account Executive DACH
Account Executive DACH

Spendesk • Bellprat

Híbrido
EUR 45.000 - 70.000
Flexible on-site and remote policy
Alan health insurance (fully covered)
Meal vouchers through Edenred
+6
Account Executive Iberia
Account Executive Iberia

Spendesk • Bellprat

Híbrido
EUR 45.000 - 65.000
Alan health insurance
Meal vouchers
Public transport subsidy
+3
Talent Acquisition Specialist – Go-To-Market
Talent Acquisition Specialist – Go-To-Market

Spendesk • Barcelona

Híbrido
EUR 55.000 - 75.000
Flexible on-site and remote policy
Health insurance
Meal vouchers
+6