Senior Security Engineer & Ciso (Spain) - Islas Baleares

Ledn

Islas Baleares

Presencial

EUR 110.000 - 170.000

Jornada completa

Hace 6 días
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Remote work up to 180 days/year
Generous PTO

Descripción de la vacante

Ledn busca un(a) Sr. Security Engineer & CISO para fortalecer la seguridad de producto, nube y entrega de software en España. Liderarás revisiones, pruebas y controles para impedir vulnerabilidades, trabajando con equipos de desarrollo, DevOps y cumplimiento.

Como CISO local, dirigirás el marco de seguridad y la gestión de riesgos ICT, reportando al consejo y colaborando con CNMV y auditores. Se requiere fluidez en inglés y español, y experiencia en fintech regulado.

Formación

  • 5+ años de experiencia en ingeniería de seguridad o campo relacionado.
  • Práctica en pruebas de penetración en aplicaciones web, APIs y infraestructuras en la nube.
  • Revisión de código en JavaScript/TypeScript, Python o Go, con conocimiento de autenticación/autorización y seguridad de datos.
  • Modelado de amenazas y diseño seguro para requerimientos de ingeniería.
  • Fuerte experiencia en seguridad AWS en entornos multi-cuenta.
  • Experiencia con seguridad en borde (Cloudflare) para WAF y control de tráfico.
  • Seguridad de GitHub/CI-CD con protecciones de repositorio y flujos de revisión.
  • Conocimientos de SAST/DAST, SBOM, y escaneo de secretos.
  • Automatización con Python/Bash/Go/JS para herramientas de seguridad.
  • Gestión del ciclo de vida de vulnerabilidades y métricas de seguridad.
  • Experiencia en entornos fintech/regulados y cumplimiento de normas.
  • Inglés y español fluidos; capacidad de comunicar hallazgos técnicos y riesgos de negocio.
  • Experiencia en gobernanza DORA y CNMV en entorno europeo.

Responsabilidades

  • Conducir revisiones de seguridad para nuevos diseños y características, transformando amenazas en requisitos de ingeniería.
  • Realizar pruebas de penetración en apps web, APIs e infraestructura y documentar hallazgos reproducibles.
  • Ejecutar ejercicios de red team y purple team para mejorar controles preventivos y telemetría.
  • Definir estándares de seguridad para pull requests, incluyendo escaneos de secretos y revisiones de dependencias.
  • Revisar código de producción y arquitectura para vulnerabilidades de autenticación, autorización y lógica de negocio.
  • Evaluar y endurecer entornos AWS multi-cuenta y políticas de seguridad (IAM, KMS, logs).
  • Revisar configuraciones y políticas de Cloudflare para seguridad de borde.
  • Gestión de seguridad de repositorios y CI/CD (CODEOWNERS, protecciones de rama).
  • Gestión de vulnerabilidades desde triage hasta cierre y reporte de tendencias.

Conocimientos

Security engineering
Penetration testing
AWS security
Cloudflare security
GitHub security
Threat modeling
Secure SDLC
Automation scripting
Vulnerability management
Regulatory compliance

Herramientas

Terraform
Helm
CI/CD security
SCA/DAST tooling

Descripción del empleo

Descripción del trabajo

Sr. Security Engineers & CISOs (Spain), we want to hear from you!

Ledn is the leading bitcoin-backed lender dedicated to providing secure, transparent, and efficient digital asset solutions. Our mission is to help clients build long-term wealth in hard assets through interest-earning accounts, loans, and trading services. Serving 100+ markets with $11B in loans issued since 2018, Ledn continues to expand its reach, giving clients access to reliable financial products worldwide.

Our team is a passionate group from diverse backgrounds. What we all have in common is an unshakeable conviction that digital assets can democratize access to the global economy and Ledn’s suite of products & services can play a critical role in doing so. The core values that guide us are: act with integrity always, own it, have a passion for progress, and lead with empathy. Combining these values with our conviction make Ledn an unstoppable force in changing the world for the better.

The Opportunity:

As a full-time Sr. Security Engineer & CISO, you'll be a hands-on, high-ownership individual contributor strengthening our product, cloud, and software delivery security. You'll find vulnerabilities before attackers do, build controls that prevent entire classes of issues from reaching production, and help engineers ship securely. A builder-and-breaker role: you'll assess our applications, APIs, AWS environment, Cloudflare edge, and GitHub workflows from an adversary's perspective, then partner with owners to remediate findings and validate fixes. You'll turn lessons learned into standards, automation, and measurable improvements, while collaborating with Software Engineering, DevOps, Risk, and Compliance to deliver technical controls, audit evidence, and incident readiness.

This dual-mandate role is based in Spain. Beyond hands-on security engineering, you'll serve as the Spain entity's CISO within the second line of defense — owning the local Information Security Framework and ICT Risk Register, reporting periodically to the Board, and acting as primary contact for the CNMV and external auditors on cybersecurity and DORA compliance.

About The Role:

Sr. Security Engineer Core Responsibilities:

  • Secure Design & Threat Modeling: Lead security reviews for new designs and existing features, translating threats into concrete engineering requirements before production.
  • Penetration Testing: Plan and execute hands-on testing of web apps, APIs, mobile-facing services, and infrastructure; document reproducible findings, validate remediation, and coordinate independent assessments.
  • Adversarial Validation: Run red-team and purple-team exercises around realistic attack paths; work with defenders to improve preventive controls, telemetry, detections, and response playbooks.
  • Secure Pull Requests: Define risk-based security standards for pull requests, including review requirements and tuned merge gates for secret scanning, SAST, dependency review, and sensitive-code ownership.
  • Product & API Security: Review production code and architecture for vulnerabilities in authentication, authorization, session handling, data protection, and business logic; help teams fix root causes, not just symptoms.
  • AWS Security: Assess and harden our multi-account AWS environment across IAM, network boundaries, encryption, logging, workload identity, and service configuration, using automation and policy-as-code where practical.
  • Cloudflare Security: Review and harden WAF rules, rate limiting, bot controls, DNS/TLS configuration, edge access policies, and change governance without disrupting legitimate client traffic.
  • GitHub & Software Supply Chain: Own security governance for repositories and CI workflows — branch protection, CODEOWNERS, least-privilege tokens, pinned actions, dependency controls, artifact integrity, and guardrails for AI-assisted code.
  • Vulnerability Management: Triage findings from internal testing, scanners, third-party assessments, and disclosures; set risk-based remediation targets, track issues to closure, retest fixes, and report trends.
  • Incident Readiness & Security Enablement: Support security investigations, tabletop exercises, and post-incident hardening while providing secure patterns, guidance, and security-champion support so engineering teams can move safely at scale.

CISO, Ledn Spain Entity Core Responsibilities:

  • Cybersecurity Framework & Board Reporting: Own the local Information Security Framework and ICT Risk Register; report periodically to the Board on information security and ICT risk; ensure immediate reporting of major incidents to Management and the Board.
  • DORA Governance & Compliance: Direct the ICT Risk Management Framework and sign off its annual regulatory report; oversee the annual digital operational resilience testing programme (system/network testing plus BCP/DRP exercises); validate the ICT third-party register for CNMV submission.
  • Regulatory & Audit Liaison: Serve as point of contact for the CNMV and external auditors on information security and DORA matters, in Spanish, including CNMV notification of significant incidents within DORA deadlines.
  • Security Operations Oversight: Supervise vulnerability management and day-to-day technical security operations, escalating critical vulnerabilities and driving remediation with the ICT team.

Required:

  • 5+ years in security engineering, application/product security, or software/platform engineering with a demonstrable security focus.
  • Hands-on penetration testing across web applications, APIs, and cloud infrastructure, producing clear, reproducible findings and validating fixes.
  • Production code review skills in JavaScript/TypeScript, Python, Go, or similar, with practical knowledge of authentication, authorization, injection, data exposure, and business-logic risks.
  • Threat modeling and secure design experience that turns ambiguous risks into actionable engineering requirements and defensible architecture decisions.
  • Strong AWS security expertise in multi-account environments, including IAM, networking, KMS, logging/detection services, and workload configuration.
  • Cloudflare or similar edge-security experience covering WAF, rate limiting, bot management, DNS/TLS, and access controls.
  • GitHub and CI/CD security experience with branch protection, review workflows, repository rules, workflow permissions, token hygiene, and secure automation.
  • Secure SDLC tooling knowledge — SAST, DAST, software composition analysis, secret scanning, container scanning — and how to tune controls so engineers act on results.
  • Software supply-chain and IaC security, including dependency/artifact risks and reviewing Terraform, Helm, or similar configuration for security gaps.
  • Automation skills in Python, Bash, Go, or JavaScript to extend testing, analyze evidence, and build lightweight security tooling.
  • Vulnerability lifecycle ownership, from risk-based triage and remediation targets through retesting, closure, and useful metrics.
  • Experience in a fintech/regulated environment where audit trails, evidence quality, data protection, and cross-functional partnership matter.
  • Fluent English and Spanish, able to explain a technical finding to an engineer and its business risk to senior stakeholders, given this role's CNMV and Board-facing responsibilities.
  • DORA and regulatory governance experience in a European financial-services environment — ICT risk management frameworks, digital operational resilience testing.
  • ICT third-party registers, and acting as a regulator/Board point of contact; CNMV experience is a strong plus.
  • Must be willing to undergo applicable background checks, per local law, if selected.

Preferred:

  • Offensive security depth via OSCP, OSWE, comparable certification, research, responsible disclosures, or a strong portfolio.
  • Digital-asset/fintech/payments security experience, especially with account-takeover, fraud-adjacent, custody, or transaction-integrity threat models.
  • Detection and response engineering using cloud telemetry, SIEM tooling, or attack simulation to build actionable detections and playbooks.
  • Vulnerability disclosure or bug bounty experience triaging researcher reports, managing communication, and coordinating fixes and retests.
  • MiCA familiarity or other EU digital-asset regulatory frameworks, alongside core DORA expertise.
  • Experience working in GDPR/SOC regulated environments.

Culture Fit:

  • Bring a builder's mindset, comfortable creating, adapting, and iterating as the business and the role evolve
  • Be a collaborative partner, able to influence across functions and cultures with empathy and clarity
  • Demonstrate integrity and accountability, especially in managing confidential information across multiple teams
  • Be comfortable owning a complex area end to end and moving fast under pressure, especially when priorities shift or the path forward isn't fully mapped out yet

A Taste of What We Provide:

  • Tremendous growth opportunities within a global digital asset leader
  • Competitive total rewards package starting on day one:
  • Generous PTO package to ensure ample time off
  • Company ownership through shared equity
  • Option to work remote somewhere other than your home base for up to 180 days per year (subject to restrictions)
  • A purpose-driven environment where barriers are removed so you love your work

We are an equal opportunity employer committed to diversity and inclusion. Email for confidential accommodation requests during recruitment.

Ledn Working Environment: Our global team operates across North America, Latin America, South Africa, and Europe in a remote-first setup.

Please note: Due to high application volume, only qualified candidates will be contacted.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Security Engineer & Spain CISO — Remote
Senior Security Engineer & Spain CISO — Remote

Ledn • España

Presencial
EUR 90.000 - 150.000
Remote-first environment
Hands-On Security Engineer & CISO — Lead in Spain
Hands-On Security Engineer & CISO — Lead in Spain

Ledn • Madrid

Presencial
EUR 90.000 - 130.000
Generoso paquete de PTO
Opción de participación en acciones (e
Senior Cybersecurity Operations Engineer - ODS
Senior Cybersecurity Operations Engineer - ODS

Openbank • Madrid

Híbrido
EUR 90.000 - 120.000
BeHealthy wellness programme
Parental leave
Childcare support
+2
Senior Security Engineer & CISO — Remote (Spain) with Equity
Senior Security Engineer & CISO — Remote (Spain) with Equity

Ledn • Islas Baleares

Presencial
EUR 110.000 - 170.000
Remote work up to 180 days/year
Generous PTO
Head of Information Security
Head of Information Security

workfully • Madrid

Híbrido
EUR 90.000 - 130.000
Health & wellbeing program
Hybrid work options
Learning & development
+1
Engineering Manager - Security Standards and Hardening
Engineering Manager - Security Standards and Hardening

Jobgether • España

Presencial
EUR 110.000 - 170.000
Performance-driven annual bonus
Learning and development budget USD 2,
Travel opportunities
Lead Application Security Engineer ID71664
Lead Application Security Engineer ID71664

AgileEngine, LLC. • Madrid

Presencial
EUR 90.000 - 120.000
Remote work
Flexible hours
Learning budget
Engineering Manager – Access & Control Platform
Engineering Manager – Access & Control Platform

Jobgether • Madrid

A distancia
EUR 110.000 - 140.000
Fully remote Europe
Flexible hours
Private health insurance
+7
Remote-First Senior Security Engineer & CISO (Spain)
Remote-First Senior Security Engineer & CISO (Spain)

Ledn • Arbo

Presencial
EUR 90.000 - 130.000
Cloud Security Engineer
Cloud Security Engineer

Montash • Barcelona

Híbrido
EUR 70.000 - 95.000
Health insurance
Learning budget
Flexible working