Corporate Security Engineer
SeQura
About seQura
seQura provides innovative, flexible and easy-to-use payment technologies that help merchants acquire, convert and retain more customers.
We make a difference in sales performance by tailoring our solutions to different sectors, to address their unique pain points and deliver superior results in Retail, Education, Eyewear, Repairs and Travel.
We also empower smart shopping to consumers who seek more value, convenience, and flexibility in their shopping, with new payment experiences that allow them to save, access interest-free credit, or pay in small, comfortable installments of up to 24 months.
Born in Barcelona, seQura is a privately-owned fintech, currently expanding throughout southern Europe and Latin America, growing above 50% CAGR.
Over 6000 businesses, almost 3 million shoppers, and almost 400 employees continue to rate us as one of the most loved and trusted fintechs out there, with an NPS of 87%, a Trustpilot rating of 4.7/5, and a Glassdoor rating of 4.1/5.
About the role
We are looking for a Corporate Security Engineer to own seQura’s internal corporate security layer, helping our teams work securely from anywhere without adding unnecessary friction to how the business runs.
This is the first role fully dedicated to our corporate security surface. Our cloud and product security areas already have dedicated ownership. Corporate security, meaning laptops, identities, SaaS applications, employee access and the way people join, move and leave, has grown faster than the dedicated ownership behind it.
This is a greenfield mandate, you will help define the corporate security standard, build it with the tools we already use (or new ones), and make the IT team able to run it without you in the room.
We are a regulated fintech. The controls you design need to stand up to PCI DSS assessments, DORA reviews, bank partner due diligence and, from 2027, ISO 27001 audits. And there is more to come, including frameworks like NIS2 as we continue expanding. Evidence matters here as much as the control itself.
If you want corporate security work where identity, devices, SaaS, automation and compliance meet, this role will give you real ownership. If you are looking for a pure SOC, application security or cloud security role, this is probably not the right fit.
What challenges you'll be solving
Raising the security capability of the IT team rather than absorbing their security work. You will co-author playbooks, run hands-on sessions and incident walkthroughs, define what IT can handle directly versus escalation, and help grow at least one security champion inside IT.
Leading corporate incident response for events such as phishing campaigns, credential leaks and lost or stolen hardware.
Defining the endpoint and device security baseline across EDR, MDM and device security practices. You will design what “correct” looks like, engineer and tune detections, build automated response actions, and review coverage and drift against the standard.
Assessing and hardening third-party SaaS applications, improving SaaS visibility and helping bring Shadow IT under control.
Owning the security posture of Google Workspace, including OAuth application governance, contextual access, DLP rules, Drive sharing, advanced phishing protection and admin audit logging.
Automating recurring security work such as alert triage, access reviews, offboarding revocation and posture reporting.
Governing one of the newest corporate security surfaces: the AI tools, agents, OAuth connections and browser extensions employees use to connect to company data.
Evaluating, procuring, and hardening third-party SaaS applications, selecting applications to fill critical gaps.
About the team
Team mission
To protect seQura’s environment in a way that supports secure growth, regulatory readiness and low-friction collaboration across the company.
The team helps ensure that employees can work securely from anywhere, while the business continues to move quickly and make decisions based on trusted controls, reliable evidence and clear ownership.
What we own
Corporate identity and access security.
Endpoint and device security standards.
Google Workspace security posture.
Corporate SaaS security and OAuth governance.
Corporate incident response playbooks and enablement.
Security automation for recurring workflows.
Security evidence for PCI DSS, DORA, bank partner due diligence and ISO 27001 readiness.
Security enablement for IT, Cloud Platform and business operations.
Audits response.
Team Structure
You will join a security and platform group that includes:
2 Cybersecurity and Compliance Engineers.
4 Cloud Platform Engineers.
1 Team Lead.
You will work closely with Cloud Platform and IT to deliver controls, with Legal and Corporate Governance on compliance direction, and with product engineering teams on security in seQura’s products.
How we work
Low-friction security: we prefer controls people can adopt without being chased over perfect controls that people work around.
Being able to make your work visible for the rest of the company.
Evidence-based security: in a regulated fintech, a control needs to be designed, tested, explained and trusted.
Enablement over dependency: success is measured by how much routine security work IT can close without you, not by how much you personally close.
Automation as a foundation: We don’t want a huge security operations team, we can only support a growing company by automating what repeats.
Cross-team delivery: you will deliver through IT, Cloud Platform, Legal, Corporate Governance and business operations, not around them.
What to expect in the next 90 days
Month 1:
You will get under the hood of our SaaS footprint, Identity (IAM), endpoints, and internal networks to map our actual attack surface. Identify Quick Wins: Pinpoint immediate low-hanging fruit in access management, endpoint posture, or high-risk configuration gaps.
You will meet your allies: Platform, IT; People Ops, Engineering, Compliance… Security here is an enabler, not a bottleneck.
Month 2:
You will be involved in critical projects affecting all the company circles. You will start measuring the impact and you will define the best strategy to succeed with the project. You will roll out high-impact security baseline improvements across Zero Trust access, user management, and SaaS governance.
Month 3:
You will own the roadmap setting the long-term corporate security strategy, turning risk mitigation into a strategic advantage for the entire company.
You will enable frictionless security by launching self-service security tools that keep teams moving fast without compromising safety.
Tech stack & environment
Our corporate security environment includes MDM, EDR, identity providers, Google Workspace, GRC tooling and automation workflows.
You will work with tools such as Hexnode, DEX, Google Workspace, Vanta, Claude and DefectDojo, while also helping define the security requirements for ZTNA and SASE as we move away from our legacy VPN model.
You do not need to have used our exact stack before. What matters more is your judgement around security priorities and impact: endpoint security, identity, SaaS governance, automation and how much friction a control is worth.
What you’ll need
Minimum 4 years of relevant experience across corporate security, identity, endpoint security, SaaS security or security engineering.
Hands-on ownership of an IDP and a SASE posture.
At least one corporate security incident handled end to end, from detection to closure.
Experience raising the security capability of a team you did not manage, through playbooks, training, security champions or handing over a control you used to run yourself.
Enough AI usage and scripting ability to automate triage and workflow tasks, using Python, Ruby on Rails, Golang or similar.
Strong understanding of endpoint security, including EDR, MDM and device security best practices.
Experience with authentication and access policies, including MFA, contextual controls, session controls, privileged access and joiner-mover-leaver flows.
Comfort delivering through other teams instead of doing everything yourself.
Working-level Spanish and English.
Nice to have
Experience with our specific stack: Hexnode for MDM, DEX and Google Workspace as identity providers, Vanta for GRC, and DefectDojo for vulnerability management.
Experience evaluating, configuring or managing a SIEM or centralised log management.
Exposure to PCI DSS, DORA or ISO 27001 in a regulated environment.
Provider management experience.
Experience building phishing simulation or security awareness programmes.
Experience using AI assistants or automation platforms to increase your own throughput, such as n8n, Claude Code, Codex or similar.
What we offer
We have a strong and sustainable foundation, where we provide a secure and reliable workplace. You have the freedom and trust to make the best contribution possible.
One of our most valued strengths by our employees is our fellowship and supportive culture, which fosters a sense of belonging by working closely with our values. With us, you will have challenging projects to work on and push your skills and knowledge.
In addition, we are very proud of the unique office we have, which offers a comfortable and inspiring environment to work in with everything you need.
23 vacation days + 2 days of free disposal per year.
Flexible compensation plan for transportation, restaurants, and kindergarten with Cobee.
- ...seQura is seeking a Corporate Security Engineer to own the corporate security surface, defining standards and enabling IT to operate securely from anywhere. You will work across identity, devices, SaaS governance and automation to build scalable controls for a regulated...Ofertas de empleo recomendadas
de 74000 a 101000 €/año
...Okta provides Workforce and Customer Identity Clouds that enable secure access, authentication, and automation. Its identity... ...discovery to resolution, including triage, impact assessment, engineering coordination, fix validation, and stakeholder communication...Ofertas de empleo recomendadas- ...Ireland, and other locations. Задачи: Administer and improve security controls across endpoint, server, identity, network, cloud and... ...Minimum 5 years’ experience in Security Operations, Security Engineering, Incident Response or Infrastructure Security Strong...Ofertas de empleo recomendadasTrabajo híbrido2 días a la semana
- ..., and React stacks; Configure, manage, and optimize enterprise security scanners, including Wiz, Snyk, Qualys, Burp Suite Enterprise/Pro... ...reviews and threat modeling based on OWASP SAMM principles; Secure and harden hybrid architecture spanning AWS cloud environments,...Ofertas de empleo recomendadasTrabajo híbrido
- ...Estamp Int is seeking a cybersecurity leader to safeguard its IT and OT environments. You will implement and enforce security policies, manage third‑party risks, and drive security awareness across the group. Travel to international plants may be required to coordinate...Ofertas de empleo recomendadas
- Factorial ищет специалиста по безопасности приложений. Вы будете проводить активное тестирование на проникновение во все приложения, API и инфраструктуру, воспроизводить отчеты об уязвимостях и помогать командам исправлять проблемы. Требуется 3+ года опыта в области б...Remoto
de 40000 a 55000 €/año
...Application Security Engineer Hey there, Cybersecurity Enthusiasts! At Factorial, we’re on the hunt for a skilled Application Security Engineer... ...development teams to remediate security findings and enhance secure coding practices. Improve how we validate, triage, and...Trabajar en la oficinaRemoto- ...Openchip is building new RISC-V chips with security at heart, enabling safer and more... ...models. As a Senior Offensive Security Engineer, you will help to ensure that our software... ...guidelines and best practices for implementing a secure development lifecycle (SDL). Work...RemotoTrabajo híbrido
- ...Factorial is seeking an Application Security Engineer in Barcelona to proactively hunt for vulnerabilities and strengthen defenses. You will test applications, APIs, and AI-powered features, reproduce external reports, and work with product teams to remediate issues....Trabajar en la oficinaTrabajo híbrido
- N26 ищет ведущего специалиста по безопасности продуктов для определения стратегии безопасности и наставничества инженерных команд. Вы будете направлять работу по микросервисам, мобильным приложениям и управляемым AI-решениям, обеспечивая безопасную разработку и внедрен...Remoto
- ...frameworks including ISF SoGP, ISO 27001, and NIST CSF Design and document processes and procedures that strengthen Clariant's security services portfolio Support the design and delivery of security awareness training programs tailored to diverse internal audiences...Horario flexible
- ...design support digital banking services across Europe. Задачи Drive the product security strategy across N26's diverse product portfolio; Guide software engineers in building secure products and services across microservices, mobile applications, and AI-driven...Patrocinio de visaTrabajar en la oficinaDesde casaRemoto1 día a la semana
de 40000 a 55000 €/año
...program Collaborate with development teams to remediate security findings and improve secure coding practices Improve vulnerability validation,... ...in Web Application Penetration Testing ~ Degree in Engineering or Computer Science ~ Strong knowledge of web applications...Trabajar en la oficina- ...A proactive and detail-oriented OT Security Specialist with a strong analytical mindset... ...transparent solutions ensuring they become secure. With foundational expertise in OT... ...other teams—such as operations, IT, and engineering—to assess risks, strengthen network segmentation...Temporal
- Bacardi is seeking an experienced Network & Collaboration Services professional to own day-to-day operation of Aruba LAN and WLAN across campuses and sites. You will implement and manage Aruba switching, controllers/APs, and ClearPass, while leading incident and change...
- .... Задачи Ensure that the platform complies with industry security practices and standards, including ISO27001, C5, and SOC2 Introduce... ...such as DDoS or abuse cases Audit PMS systems, support secure migration to the central platform, and interpret global...Trabajo de veranoPrácticaInicio inmediatoHorario flexible
- ...experiencia en el sector TIC, buscamos incorporar un/a Network & Security Engineer para participar de forma dedicada al 100% en uno de... ...Administración y operación de infraestructuras de red corporativas. Configuración, mantenimiento y resolución de incidencias...Empleo permanenteTrabajar en la oficinaRemotoTrabajo híbrido
- ...Tokio Marine HCC in Barcelona is seeking a Cyber Security Engineer to strengthen detection, investigation and response across our international technology environment. You will administer security controls, design preventive and detective measures, investigate incidents...Trabajo híbrido
- ...MediaMarktSaturn Technology in Barcelona is seeking a skilled DevSecOps and platform security engineer to design and implement security controls for our AI platforms, oversee governance and compliance, and collaborate with global teams to protect data and systems. You...Patrocinio de visaTrabajo híbrido
- ...Tokio Marine HCC in Barcelona is seeking a Cyber Security Engineer to strengthen our detection, investigation and response capabilities within the International Security Operations function. You will work with Security Engineering, Infrastructure and Technology teams to...Trabajo híbrido
- ...cutting edge technology to create highly scalable, customisable and secure products and components that free up development time and... ...data. We are looking for an experienced defensive security engineer with hands‑on expertise in incident response and security operations...Temporal
- ...Office, is responsible for ensuring the security of the organization’s IT and OT... ...standards, and procedures aligned with corporate and regulatory requirements (TISAX, ISO... ...Information Technology, Cybersecurity, Computer Engineering, or a related field. Knowledge of...Trabajar en la oficina
- ...SIRT, con más de 26 años en el sector TIC, busca Security Engineer para cliente final en Barcelona. Te integrarás en un equipo de operación y seguridad, gestionando infraestructuras críticas y asegurando disponibilidad y protección de entornos tecnológicos. La posición...Remoto
- ...AG Solution is seeking an OT Security Specialist to strengthen industrial network security, focusing on risk assessment, segmentation, and secure architecture. You will collaborate with operations, IT, and engineering teams to implement robust protective measures across...
- ...infraestructuras críticas. Actualmente buscamos incorporar un/a Security Engineer para formar parte de un servicio estable en cliente final... ...y mejora continua de plataformas de seguridad y redes corporativas, contribuyendo a garantizar la disponibilidad, seguridad y...AprendizEmpleo permanenteTrabajar en la oficinaRemotoLunes a viernes
- ...Infrastructure Security Engineer Factorial is looking for a skilled and experienced Infrastructure Security Engineer to join our team... ...our global infrastructure remains resilient, compliant, and secure. You’ll work closely with SRE and IT teams to maintain a strong...Trabajar en la oficinaRemoto
- ...helps organizations modernize financial operations, increase visibility, and optimize spend across the enterprise. As a Senior Security Engineer, you will play a crucial role in maintaining and enhancing our organization's security posture. You will be responsible for...Tiempo completo
- ...MISSION The Security Engineer is responsible for designing, implementing, and managing security technologies across the organization, ensuring... ...performance and security. Support and maintain Cisco Secure Access Service Edge (SASE) infrastructure for secure remote and...Trabajar en la oficinaRemotoVisa de trabajo
- OT Security Engineer We are looking for the very Top Talent and we would be delighted if you were to join our team! More in details, UST... ...closely with infrastructure and engineering teams to ensure secure configuration, patching, and hardening of OT assets. Analyze...Trabajo de veranoTiempo completoTrabajar en la oficinaRemotoTrabajo híbrido
- Defensive Security Engineer Lead advanced incident response investigations, particularly involving cloud infrastructure and platform environments... ...work with modern technologies and best practices to build secure, high-availability products that impact users across multiple...Tiempo completoTrabajo híbrido
¿Quieres recibir más ofertas?
Suscríbete y recibe ofertas similares para Corporate Security Engineer. ¡Entérate antes que nadie!


