Senior Security Engineer at Spendesk | Barcelona, Barcelona, ES | Rezi

Senior Security Engineer at Spendesk

Senior Security Engineer

Spendesk · Barcelona, Barcelona, ES

Yesterday

Senior Security Engineer

Spendesk · Barcelona, Barcelona, ES

a day ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Senior Security Engineer role.

Rezi rewrites your resume against Spendesk's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Senior Security Engineer posting at Spendesk — free, in seconds.

About the Role

Spendesk is seeking a Senior Security Engineer to establish and lead the new Security Engineering function. This individual contributor role will focus on building security tooling, training developers, and implementing secure-by-default solutions to protect the platform and respond to threats. You will own the technical security roadmap, mentor an Associate Security Engineer, and influence security practices across engineering squads.

Responsibilities

  • Own and operate the bug bounty program, including platform management, escalation thresholds, and strategic improvements.
  • Act as the escalation point for vulnerability triage, leading complex or high-severity findings.
  • Lead security incident response, including qualification, forensics, fix coordination, post-mortem, and resolution tracking.
  • Own the SIEM platform (ElasticSearch, multi-node Linux), including architecture, detection rules, and indicators of compromise.
  • Build and evolve detection coverage, prioritizing signal quality.
  • Build and maintain security runbooks and operational documentation.
  • Own IAM implementation and operations for product and infrastructure systems.
  • Implement SSO/MFA configuration, role and access-rights, periodic permission reviews, and secrets rotation.
  • Embed security into the development lifecycle through threat modeling, secure code patterns, and CI/CD hardening.
  • Conduct technical security reviews of code (TypeScript, Node.js, Python), infrastructure-as-code (Terraform), and AWS environments.
  • Drive security tooling in CI/CD, designing and owning the automated gate suite (SAST, SCA, container scanning, AI-generated code risk detection).
  • Assess and govern AI tooling adoption across engineering, defining security standards and conducting AI-specific threat modeling.
  • Coordinate and execute penetration tests and security audits, managing environments, auditor relationships, and action plans.
  • Drive remediation within defined qualification rules and timeframes.
  • Coach engineers on secure development through workshops, guidance, and design reviews.
  • Surface security risks and recommendations to engineering leadership.
  • Own the security backlog and roadmap.
  • Partner with Infrastructure on secure-by-default solutions.

Requirements

  • A track record of owning security outcomes end to end.
  • Hands-on experience across at least three of: code auditing, infrastructure security (AWS/Linux), penetration testing, SIEM operations, incident response.
  • Ability to own a roadmap: identify priorities, build a plan, execute autonomously, and communicate progress to non-specialists.
  • Deep understanding of modern web architectures (microservices, cloud-native, PaaS/SaaS) and their vulnerabilities.
  • Strong scripting and automation ability (Python, Bash, or similar).
  • Experience mentoring other engineers or security practitioners.
  • Excellent communication skills, able to explain technical security risks to non-technical stakeholders.
  • Experience with ElasticSearch / ELK stack in production (nice-to-have).
  • Familiarity with AWS, GCP, Snowflake, Datadate, Okta (nice-to-have).
  • Knowledge of security standards and frameworks (ISO 27001, OWASP, SOC 2, PCI-DSS) (nice-to-have).
  • Experience in a regulated fintech or payments environment (nice-to-have).
  • Reverse engineering and analysis of minified/obfuscated code (nice-to-have).

Skills

  • Code auditing
  • Infrastructure security (AWS/Linux)
  • Penetration testing
  • SIEM operations
  • Incident response
  • Roadmap ownership
  • Modern web architectures
  • Scripting and automation (Python, Bash)
  • Mentoring
  • Communication
  • ElasticSearch / ELK stack
  • AWS
  • GCP
  • Snowflake
  • Datadog
  • Okta
  • ISO 27001
  • OWASP
  • SOC 2
  • PCI-DSS
  • Fintech security
  • Reverse engineering
  • Code analysis

Location

  • Remote

Work Type

  • Flexible on-site and remote policy
  • Full-time

Experience Level

  • Senior
  • Individual contributor

Benefits

  • Flexible on-site and remote policy
  • Latest Apple equipment
  • Access to Moka.care for emotional and mental health wellbeing
  • Great office snacks
  • Positive team environment
  • Location-specific benefits (health insurance, wellness allowances, commuter support, meal vouchers, gym memberships)

About the Company

  • Spendesk is the AI-powered spend management and procurement platform that transforms company spending.
  • It simplifies procurement, payment cards, expense management, invoice processing, and accounting automation.
  • The platform provides visibility and control over all company spend, even in multi-entity structures.
  • Spendesk is trusted by thousands of companies and supports over 200,000 users.
  • The company has offices in the United Kingdom, France, Spain, and Germany.
  • Spendesk values community, liberation, ownership, and growth.
  • Spendeskers are described as bold, ever-curious, kind, and positive.

Equal Opportunity

  • Spendesk is committed to fostering an environment where all differences are encouraged, supported, and celebrated.
  • The company aims to build a diverse, equal, and inclusive team where everyone feels welcome.
  • People from all backgrounds are encouraged to apply.