← Back to job listings
BY
Security Engineer
Bynder · Spain
About The Role
Join Bynder, a leading cloud-native SaaS platform, as a Security Engineer. In this role, you will be responsible for executing penetration tests, embedding security across the SDLC, evolving our cloud security posture, championing security controls within CI/CD pipelines, supporting security incident response, translating compliance requirements into technical controls, conducting vendor and third-party security risk assessments, and sharing knowledge across the engineering team. You will work closely with platform teams, engineering, and business stakeholders to continuously raise the bar for security.
- Plan and execute penetration tests against web applications, APIs, and cloud infrastructure, and manage external pentest engagements.
- Embed security across the full SDLC: leading threat modeling, security assessments, and vulnerability remediation in close collaboration with engineering and product teams.
- Own and evolve our cloud security posture across our AWS environment, working with Wiz to drive risk prioritization, misconfiguration remediation, and shift-left security workflows.
- 3–7 years of hands-on experience in application security, cloud security (AWS), or a broad security engineering role
- Solid understanding of AWS security: IAM, VPC design, cloud-native architecture and a clear intuition for what secure cloud infrastructure looks like
- A growth mindset and genuine curiosity, you’re comfortable operating across domains, actively building skills you don’t yet have, and you see a broad scope as an opportunity, not a burden
- Proven experience conducting penetration tests on web applications, APIs, and/or cloud environments, with a solid grip on OWASP Top 10 and common vulnerability classes
- Strong communication skills, you can explain security risks clearly to both engineers and non-technical stakeholders, and you don’t default to “no” when there’s a smarter path forward
- Familiarity with application security testing tools (SAST, DAST) and a practical understanding of DevSecOps: you know where to plug in and how to make it stick with developers
- Have hands-on experience with Wiz, or other CSPM/CNAPP platforms
- Hold an offensive security certification (OSCP or similar) or have contributed to bug bounty programmes
- Have experience with AI/ML security risks and frameworks (OWASP LLM Top 10, MITRE ATLAS)
- Write security scripts, tinker with tools, or keep a personal GitHub with automation or research projects
- Have hands-on experience with Kubernetes and container security
- Have experience with Terraform or IaC security scanning
- Are familiar with common programming languages (e.g. Python, Java, Scala) and can read and reason about code to support security reviews
- If you don’t tick every box but you’re the kind of person who figures things out, speaks up, and raises the standard around you, we’d still love to hear from you
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring