Offensive Security Engineer
de 40000 a 55000 €/añoFactorial
.
Hey there, Cybersecurity Enthusiasts! At Factorial, we're on the hunt for a skilled Application Security Engineer to join our Security Team. We need your expertise to proactively hunt for vulnerabilities and strengthen our defenses against cyber threats. If you have a passion for ethical hacking and want to make an impact in a dynamic tech environment, we'd love to hear from you!
Ready to be part of the challenge?
About The Team
Security at Factorial works side by side with Product and Engineering to help a fast-moving, AI-native company ship without losing control of risk. Our mission is to protect Factorial and our customers while making security a practical part of how software is designed, built, tested, and operated. The work goes far beyond finding vulnerabilities: we test real product surfaces, help teams fix issues properly, and turn repeated security needs into guardrails, automation, and CI/CD controls that developers can use every day. AI is part of Factorial’s culture, product, and way of working from day one, so Security also helps define how teams use agents, LLMs, tools, and company data safely at scale, while actively challenging those systems with an attacker mindset. It’s a team for people who want to keep learning, move across different security problems, and build security that can keep up with the speed of the company.
What You’ll be doing?
- Perform proactive penetration testing across Factorial’s applications, APIs, infrastructure, and AI-powered features.
- Reproduce and validate vulnerability reports submitted by third parties, like our bug bounty program.
- Collaborate with development teams to remediate security findings and enhance secure coding practices.
- Improve how we validate, triage, and remediate vulnerabilities from bug bounty reports, internal testing, automated controls, and external research.
- Hunt for recurring or legacy vulnerability patterns based on root cause analysis, previous incidents, and security findings.
- Build and improve security automations, agents, skills, and CI/CD controls that help engineering teams catch and fix issues earlier.
- Help secure Factorial’s use of AI across product and internal workflows, including LLMs, agents, data access, tools, permissions, and abuse scenarios.
- Contribute to the development of our security tools, automations, and infrastructure.
- Stay up-to-date with the latest security research, threats, attack techniques, and emerging AI security risks.
What are we looking for?
- You have 3+ years of professional experience in Application Security, Offensive Security, or Penetration Testing. Web Application Penetration Testing experience is mandatory.
- You hold a degree in Engineering or Computer Science and have strong knowledge of web applications, databases, network protocols, and operating systems.
- You possess strong knowledge in cybersecurity fundamentals, CVSS, testing methodologies, and tooling.
- You are fluent with scripting or programming languages used in security testing and automation, such as Python or Bash.
- You are technical, curious, and comfortable moving across different security problems instead of specializing in only one area.
- You like to attack systems, but you also enjoy building tools, automations, guardrails, and practical solutions that make security scale.
- You do not need to be an expert in every technology, but you should be able to reason critically, learn fast, use AI effectively, and design pragmatic solutions.
- You have curiosity and willingness to learn about AI security topics such as LLM testing, prompt injection, agentic workflows, data exposure, tool permissions, RAG security, and secure AI adoption.
- Certifications like BSCP or eWPTX are highly regarded but not mandatory.
- Experience with Ruby / Ruby on Rails applications is highly regarded, but not mandatory.
- Fluency in English is required.
Compensation
At Factorial we don't evaluate you by years of experience but by your knowledge and skills.
We use our Career Path with a rubric framework where we define what is expected for each experience level and skill. This framework allows you to know your current level and what you need to keep growing. We love transparency, so our Career Path includes the salaries for each level, which we share during the first interview to ensure alignment.
The salary range for this position is between 40.000 - 55.000€ base + 7-10%variable based on performance payed quarterly + ESOP plan.
How We Work
At Factorial, we believe the best products are built when people come together—in person—to collaborate, challenge ideas, and move fast. That’s why our Engineering Team follows an office-first, flexible approach.
We work on-site several days a week (80%), using that time to connect, align, and innovate as a team. However, we also understand the importance of focus and flexibility, so we support remote work when it makes sense (20%), whether for deep work, personal needs, or just a change of scenery.
This balance helps us stay agile, creative, and closely connected, while giving everyone the space to do their best work.
Our Hiring Process
- Intro Call → Chat with our Talent Partner about your journey and goals.
- Hiring Manager Interview → Deep dive into your product mindset, teamwork, and problem-solving.
- Technical Interview → A collaborative technical discussion based on real-life problems.
- Final Coffee Chat → A relaxed conversation with our CTO & VP of Engineering to explore our vision, culture, and your growth.
The whole process is remote, using videoconferencing tools!
About Factorial
At Factorial, we’re building the leading AI Business Management Software for companies of all sizes. Our platform centralizes key workflows across HR, Finance, Talent, Operations, and IT, freeing teams from manual processes so they can focus on what really matters: leading, growing, and taking care of their people. With over 1,500 employees across Europe, Asia, Africa, and America. We are one of Europe’s fastest-growing SaaS companies, proudly headquartered in Barcelona. If you're excited to shape the future of business management technology, we’d love to meet you.
We believe in diverse talent: we welcome applicants from all backgrounds and strongly encourage people of diverse experiences and identities to apply.
We believe in inclusion: we are committed to equal opportunities and actively promote workplace inclusion of people with disabilities. If you would like to learn more about our inclusive recruitment processes, you are welcome to indicate so optionally and we will share additional information with you.
Our Values
- We own it: We take responsibility for every project. We make decisions, not excuses.
- We learn and teach: We're dedicated to learning something new every day and, above all, share it.
- We partner: Every decision is a team decision. We trust each other.
- We grow fast: We act fast. We think that the worst mistake is not learning from them.
Wanna learn more about us? Check our website!
Perks of being part of Factorial
- High growth, multicultural and friendly environment
- Alan as private health insurance
- Healthy life with Wellhub (Gyms, pools, outdoor classes)
- Save expenses with Cobee
- Language classes
- Breakfast in the office and organic fruit
- Food discounts with Nora
- Pet Friendly
- Much more that we'll spill during the interview process!
de 40000 a 55000 €/año
...Application Security Engineer Hey there, Cybersecurity Enthusiasts! At Factorial, we’re on the... ...security findings and enhance secure coding practices. Improve how we validate... ...professional experience in Application Security, Offensive Security, or Penetration Testing. Web...Ofertas de empleo recomendadasTrabajar en la oficinaRemotode 40000 a 55000 €/año
...with development teams to remediate security findings and improve secure coding practices Improve... ...experience in Application Security, Offensive Security, or Penetration Testing... ...Penetration Testing ~ Degree in Engineering or Computer Science ~ Strong knowledge...Ofertas de empleo recomendadasTrabajar en la oficina- ...Vivid is seeking a Security Engineer to own and scale security across identities, SaaS, endpoints, and networks in a cloud-native AWS setup. You will design controls, automate security workflows, and lead security initiatives with minimal oversight. You will manage...Ofertas de empleo recomendadas
- ...Lead complex cloud security investigations. Work with modern security engineering and automation. A leading European digital marketplace company that operates... ...modern technologies and best practices to build secure, high-availability products that impact users across...Ofertas de empleo recomendadasTrabajo híbrido
- N26 ищет ведущего специалиста по безопасности продуктов для определения стратегии безопасности и наставничества инженерных команд. Вы будете направлять работу по микросервисам, мобильным приложениям и управляемым AI-решениям, обеспечивая безопасную разработку и внедрен...Ofertas de empleo recomendadasRemoto
- ...Factorial is seeking an Application Security Engineer in Barcelona to proactively hunt for vulnerabilities and strengthen defenses. You will test applications, APIs, and AI-powered features, reproduce external reports, and work with product teams to remediate issues....Trabajar en la oficinaTrabajo híbrido
- ...careers blog. The Contentsquare Security team is looking for an application security engineer (Appsec) who can work closely... ...Security Engineer, you'll help secure Contentsquare's applications... ...prevented. You'll bring a strong offensive security mindset and hands-on...Tiempo completo
- ...design support digital banking services across Europe. Задачи Drive the product security strategy across N26's diverse product portfolio; Guide software engineers in building secure products and services across microservices, mobile applications, and AI-driven...Patrocinio de visaTrabajar en la oficinaDesde casaRemoto1 día a la semana
- ...Kiwi.com, a global travel-tech company, is seeking a Security Engineer to design, deploy, and maintain agentic AI systems that embed security... ...in on-call rotations, and collaborate with leadership to reduce risk while delivering secure, scalable #J-18808-LjbffrTrabajar en la oficinaTrabajo híbrido
- ...About The Role We’re looking for a Security Engineer to own and improve the security of our internal environment - the identities, SaaS... ...automated remediation. Defend against phishing and spoofing - secure email gateway rules, DMARC/SPF/DKIM - and run phishing...Trabajar en la oficinaRemotoInicio inmediatoTrabajo híbrido
- Factorial ищет специалиста по безопасности приложений. Вы будете проводить активное тестирование на проникновение во все приложения, API и инфраструктуру, воспроизводить отчеты об уязвимостях и помогать командам исправлять проблемы. Требуется 3+ года опыта в области б...Remoto
- ...We are looking for an Application Security Research Engineer in Barcelona. In this role, you will... ...researchers and ethical hackers focused on offensive security testing, automated exploit... ...of company products and help scale secure-by-design principles. This is a hands...
- ...Stock Exchange since 2017 and is part of the MDAX stock market index. Job Description Glovo is seeking a proactive Security GRC Engineer to help strengthen our global security posture and navigate a rapidly evolving regulatory environment. In this multifaceted...Tiempo completoContrato
- ...helps organizations modernize financial operations, increase visibility, and optimize spend across the enterprise. As a Senior Security Engineer, you will play a crucial role in maintaining and enhancing our organization's security posture. You will be responsible for...Tiempo completo
- OT Security Engineer We are looking for the very Top Talent and we would be delighted if you were to join our team! More in details, UST... ...closely with infrastructure and engineering teams to ensure secure configuration, patching, and hardening of OT assets. Analyze...Trabajo de veranoTiempo completoTrabajar en la oficinaRemotoTrabajo híbrido
- ...seguridad? En SIRT , compañía tecnológica con más de 28 años de experiencia en el sector TIC, buscamos incorporar un/a Network & Security Engineer para participar de forma dedicada al 100% en uno de nuestros proyectos estratégicos en cliente final. Te integrarás en un...AprendizTiempo completoEmpleo permanenteTrabajar en la oficinaRemotoTrabajo híbrido
- ...autonomy. The Role As a Senior Security Engineer , you will be the cornerstone of our... ...designs, threat modelling, coaching on secure practices — and your impact will be measured... ..., security operations and a degree of offensive security. Breadth matters less as a...Tiempo completoTrabajar en la oficinaRemotoHorario flexible
- ...Michael Page is assisting a leading European digital marketplace company seeking a Cloud Security Lead in Spain. You will lead complex investigations, work with modern security engineering, automation, and cloud infrastructure to protect high-availability platforms. You...
- ...implementing, and managing comprehensive security solutions across our global... ...PowerShell for automation. ~ Experience with secure software development lifecycle (SDLC) and... ...loss prevention (DLP). ~ Exposure to offensive security practices. ~ Hands-on IT Infrastructure...
- ...dLocal is seeking a Senior Network & Edge Security Engineer in Barcelona, Spain, to design, operate, and secure our global cloud and hybrid network perimeter. You will own secure connectivity, WAF and firewall controls, and automation at scale, collaborating with Platform...Trabajo híbrido
- ...Factorial is seeking an Application Security Engineer to proactively hunt vulnerabilities across its applications, APIs, and AI-powered features... ...with Product and Engineering to remediate findings, improve secure coding, and scale security through automation. The role...
- ...HappyRobot in Madrid is seeking a Cloud Security Engineer to own cloud posture across AWS, Azure, and GCP, ensuring security baseline and remediation SLAs in a fast-paced enterprise environment. The role requires 4–6 years of cloud security experience, CNAPP/CSPM proficiency...
- ...the opportunity? We are looking for a Senior Network & Edge Security Engineer to help design, operate, and evolve dLocal’s global cloud and... ...expertise with a strong security mindset: you will own secure connectivity, traffic protection, WAF and firewall controls,...Trabajo híbrido
- ...enterprise that runs the real economy. Learn more about our vision in our manifesto. Role Overview We are looking for a Cloud Security Engineer to join our team. You will be the single accountable owner for cloud security posture across AWS, Azure, and GCP — bringing...Trabajo por turnos
- ...the opportunity? We are looking for a Senior Network & Edge Security Engineer to help design, operate, and evolve dLocal's global cloud and... ...expertise with a strong security mindset: you will own secure connectivity, traffic protection, WAF and firewall controls,...Trabajo híbrido
- ...than 60 countries. Задачи: Drive the security strategy for cloud environments and... ...CNAPP, CSPM, and vulnerability scanners Secure infrastructure and runners within CI/CD... ...in Infrastructure Security or Security Engineering ~ Experience with cloud environments,...Trabajar en la oficina
- ...Yassir, a leading super app expanding across continents, seeks a DevSecOps Engineer to design secure, scalable infrastructure and automate security across the development lifecycle. You will collaborate with engineering teams to embed security into features, monitor production...
- ...Buscamos un/a Senior JBoss / Java Security Remediation Engineer para incorporarse a un proyecto del sector bancario, participando en la identificación, análisis, remediación y validación de vulnerabilidades en aplicaciones Java desplegadas sobre JBoss y entornos AWS...
- ...TECDATA ENGINEERING busca un Senior JBoss / Java Security Remediation Engineer para un proyecto en el sector bancario. Identificar, analizar, remediar y validar vulnerabilidades en aplicaciones Java desplegadas sobre JBoss y entornos AWS, trabajando con herramientas SAST...
- ...CrowdStrike is seeking a Cloud Sales Engineer to support our Southern Europe teams. You will act as a trusted advisor, aligning CrowdStrike... ...and collaborating with partners and customers to advance cloud security initiatives. The role requires 5+ years in cloud or security...Trabajo híbrido
¿Quieres recibir más ofertas?
Suscríbete y recibe ofertas similares para Offensive Security Engineer. ¡Entérate antes que nadie!


