Senior Security Engineers & CISOs (Spain), we want to hear from you! Ledn is a general financial services company built for digital assets, helping to improve the everyday lives of Bitcoin holders while building generational wealth for the future.
We offer a suite of egalitarian lending, savings and trading products to digital asset holders in over 120 countries around the world. Through our products & services, we can make a difference in the lives and futures of our clients - in real terms. Our team at Ledn is a passionate group of individuals from diverse backgrounds.
What we all have in common is an unshakeable conviction that digital assets can democratize access to the global economy and Ledn’s suite of products & services can play a critical role in doing so.
The core values that guide us are: act with integrity always, own it, have a passion for progress, and lead with empathy. Combining these values with our conviction make Ledn an unstoppable force in changing the world for the better. Come join us as we build, innovate and revolutionize financial services!
The Opportunity
As a full-time Senior Security Engineer & CISO(Spain), you will be a hands-on, high-ownership individual contributor responsible for strengthening Ledn's product, cloud, and software delivery security. You will find vulnerabilities before attackers do, build controls that prevent entire classes of issues from reaching production, and help engineers ship securely. This is a builder-and-breaker role: you will assess our applications, APIs, AWS environment, Cloudflare edge, and GitHub workflows from an adversary's perspective, then partner with owners to remediate findings and validate the fixes.
You will turn lessons from individual issues into practical standards, automation, and measurable improvements. You'll work closely with Software Engineering, DevOps & Infrastructure, Risk, and Compliance. In a regulated digital-asset environment, you will contribute technical controls, evidence, and incident readiness that support Ledn's security and regulatory obligations This is a unique, dual-mandate role based in Spain.
Alongside the hands-on security engineering work above, you will also serve as the Ledn Spain entity’s Chief Information Security Officer (CISO), operating within the second line of defense. In that capacity, you will own the local Information Security Framework and ICT Risk Register, report periodically to the Board on information security and ICT risk, and act as the primary point of contact for the CNMV and external auditors on cybersecurity and DORA matters.
About The Role Senior Security Engineer Core Responsibilities: Secure Design & Threat Modeling Lead security reviews for new designs and existing features, translating threats into concrete engineering requirements before code reaches production.
Penetration Testing
Plan and execute hands-on testing of web applications, APIs, mobile-facing services, and infrastructure; document reproducible findings, validate remediation, and coordinate independent assessments where needed.
Adversarial Validation
Run red-team and purple-team exercises around realistic attack paths, then work with defenders to improve preventive controls, telemetry, detections, and response playbooks.
Secure Pull Requests
Define a risk-based security standard for pull requests, including review requirements and tuned merge gates for secret scanning, SAST, dependency review, and sensitive-code ownership. Product & API Security Review production code and architecture for vulnerabilities in authentication, authorization, session handling, data protection, and business logic; help teams address root causes rather than isolated symptoms. AWS Security Assess and harden our multi-account AWS environment across IAM, network boundaries, encryption, logging, workload identity, and service configuration,
using automation and policy-as-code where practical.
Cloudflare Security
Review and harden WAF rules, rate limiting, bot controls, DNS and TLS configuration, edge access policies, and change governance without disrupting legitimate client traffic. GitHub & Software Supply Chain Own security governance for repositories and CI workflows, including branch protection, CODEOWNERS, least-privilege tokens, pinned actions, dependency controls, artifact integrity, and guardrails for AI-assisted code.
Vulnerability Management
Triage findings from internal testing, scanners, third-party assessments, and vulnerability disclosures; set risk-based remediation targets, track issues to closure, retest fixes, and report meaningful trends.
Incident
Readiness &
• Security Enablement Support security investigations, tabletop exercises, and post-incident hardening while providing secure patterns, targeted guidance, and security-champion support that help engineering teams move safely at scale. CISO, Ledn Spain Entity Core Responsibilities Cybersecurity Framework &
• Board Reporting Own and oversee the local Information Security Framework and ICT Risk Register; report periodically to the Board on information security and ICT risk; ensure immediate reporting of major incidents to Management and the Board. DORA Governance &
• Compliance Direct the ICT Risk Management Framework and sign off its annual regulatory report; oversee the annual digital operational resilience testing programme (system and network testing plus BCP/DRP exercises) to confirm resilience against disruption; validate the ICT third-party register for CNMV submission. Regulatory &
• Audit Liaison Serve as the point of contact for the CNMV and external auditors on information security and DORA matters, in Spanish, including CNMV notification of significant incidents within DORA deadlines.
Security Operations Oversight
Supervise vulnerability management and day-to-day technical security operations, escalating critical vulnerabilities and driving remediation with the ICT team.
What You Bring To
Ledn 5+ years in security engineering, application or product security, or software/platform engineering with a sustained and demonstrable security focus. Hands-on penetration testing experience across web applications, APIs, and cloud infrastructure, with the ability to produce clear, reproducible findings and validate fixes. Production code review skills in JavaScript/TypeScript, Python, Go, or a comparable language, with practical knowledge of authentication, authorization, injection, data exposure, and business-logic risks.
Threat modeling and secure design experience that turns ambiguous risks into actionable engineering requirements and defensible architecture decisions. Strong AWS security expertise in multi-account environments, including IAM, networking, KMS, logging and detection services, and workload configuration. Cloudflare or comparable edge-security experience covering WAF, rate limiting, bot management, DNS/TLS, and access controls.
GitHub and CI/CD security experience with branch protection, review workflows, repository rules, workflow permissions, token hygiene, and secure automation. Secure SDLC tooling knowledge of SAST, DAST, software composition analysis, secret scanning, container scanning, and how to tune controls so engineers act on the results. Software supply-chain and IaC security including dependency and artifact risks and the ability to review Terraform, Helm,
or similar configuration for security gaps.
Practical automation skills in Python, Bash, Go, or JavaScript to extend testing, analyze evidence, and build lightweight security tooling. Vulnerability lifecycle ownership from risk-based triage and remediation targets through retesting, closure, and useful metrics.
Experience in fintech or another regulated environment where audit trails, evidence quality, data protection, and cross-functional partnership matter.
Fluent
English and Spanish with the ability to explain a technical finding to an engineer and communicate its business risk to senior stakeholders; required given this role's CNMV and Board-facing responsibilities in Spain. DORA and regulatory governance experience in a European financial-services environment, including ICT risk management frameworks, digital operational resilience testing, ICT third-party registers, and acting as a regulator or Board point of contact; CNMV experience is a strong plus. Must be willing to undergo applicable background checks, in compliance with local laws and regulations, if selected.
Nice To Have
Offensive security depth demonstrated through an OSCP, OSWE, comparable certification, research, responsible disclosures, or a strong practical portfolio. Digital-asset, fintech, or payments security experience, especially with account-takeover, fraud-adjacent, custody, or transaction-integrity threat models. Detection and response engineering experience using cloud telemetry, SIEM tooling, or attack simulation to improve actionable detections and playbooks.
Vulnerability disclosure or bug bounty experience triaging researcher reports, managing communication, and coordinating fixes and retests. MiCA familiarity or other EU digital-asset regulatory frameworks, alongside your core DORA expertise.
Experience working in GDPR / SOC regulated environments.
Culture Fit
We're looking for more than technical security expertise — we want an individual who thrives in a startup technology environment and embodies our values.
The ideal candidate will: Be adaptable and resilient, with a passion for progress and comfort navigating ambiguity in a high-growth, fast-paced environment. Bring a builder’s mindset and be excited to create, iterate, and scale. Collaborate across functions and cultures, influencing with empathy and clarity.
Demonstrate integrity and accountability, especially in managing confidential information across multiple teams. A Taste Of What We Provide As one of the world’s leading digital asset businesses, we provide tremendous growth opportunities. Comprehensive, best-in-class total rewards package that starts on your first day!
We offer a competitive PTO package that ensures you have the time off you deserve. Ownership in the business. Through shared equity, Ledn staff are stakeholders in the business and the future of the digital economy.
We offer every staff member the opportunity to work remotely anywhere in the world for 180 days (subject to restrictions). A career that provides you with purpose in your job. We remove barriers so you love what you do.
We are an equal opportunity employment organization and pride ourselves on inclusivity, diversity, and the success that comes from diversity. You may reach out to the Ledn team by emailing
[email protected] for reasonable accommodation requests throughout all stages of the recruitment process. Requests will be addressed confidentially.
Ledn Working Environment: Our Ledn team is truly global in nature with our people spanning across North America, Latin America, South Africa and Europe. We are a remote first environment. Please note, due to the high volume of applications, only those applicants that qualify will be contacted. No agencies or recruiters please. We do not accept unsolicited agency resumes and we are not responsible for any fees related to unsolicited resumes.
📌 Senior Security Engineer u0026 CISO (Spain) (España)
🏢 Ledn
📍 España