1 week ago Be among the first 25 applicants
We seek an experienced, technically strong, and highly hands-on Senior Cyber Security Engineer to secure our websites, digital assets, and cloud infrastructure, focusing on AWS security, web application security, and practical threat prevention.
This is not a policy or governance role : we're looking for someone who enjoys rolling up their sleeves, solving security issues directly, working alongside engineers and DevOps, and implementing robust protective measures to prevent real-world attacks.
Responsibilities
- Harden and maintain the security of our websites and web applications
- Implement, monitor, and optimise WAFs (AWS WAF, Cloudflare) — focusing on real-world traffic filtering and rule fine-tuning
- Perform regular application security scans, vulnerability assessments, and coordinate annual third-party penetration tests
- Fix and patch vulnerabilities proactively in collaboration with developers
AWS & Cloud Security
Own the security of our AWS environments : IAM, networking, patch management, secure configurations, change control, and monitoringAction recommendations from our security tools and track remediationEnforce best practices for infrastructure as code, deployment pipelines, and container securityThreat Detection & Incident Response
Deploy and operate SIEM (Security Information and Event Management) tools to detect and respond to security threats in real-timeDevelop and maintain runbooks for incident handling and forensic investigationPerform root cause analysis of security incidents and implement preventive measuresRisk & Assurance
Produce regular security status reports and product risk assessments for General Managers and senior leadershipStay ahead of emerging threats relevant to our industry (affiliate marketing and crypto) and adapt controls accordinglyCollaboration & Knowledge Sharing
Work closely with engineering and DevOps to embed security into the development lifecycle and deploymentsProvide hands-on guidance and training to engineers on secure coding, secrets management, and AWS securityFoster a culture of practical security awareness across the companyRequirements
Minimum 5 years of practical cybersecurity experience in a hands-on technical roleDeep knowledge of AWS security, web architecture, and cloud-native security patternsProven experience deploying and tuning WAFs (AWS, Cloudflare) and handling real security incidentsSolid understanding of DevOps pipelines and how to secure CI / CD processesProficient with modern security tooling : SIEM, vulnerability management, endpoint security, firewalls, 2FA, email / web securitySeniority level
Seniority level Not ApplicableEmployment type
Employment type Full-timeJob function
Job function Information TechnologyIndustries Technology, Information and MediaReferrals increase your chances of interviewing at Find.co by 2x
Get notified about new Cyber Security Engineer jobs in Barcelona, Catalonia, Spain .
Security Architect and Cyber-Threat Intelligence Analyst Application Security Engineer (100% remote-friendly within Spain) Linux Cryptography and Security Engineer
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
J-18808-Ljbffr