Sr. Security Engineers & CISOs (Spain), we want to hear from you!
Ledn is the leading bitcoin-backed lender dedicated to providing secure, transparent, and efficient digital asset solutions. Our mission is to help clients build long-term wealth in hard assets through interest-earning accounts, loans, and trading services. Serving 100+ markets with $11B in loans issued since 2018, Ledn continues to expand its reach, giving clients access to reliable financial products worldwide.
Our team is a passionate group from diverse backgrounds. What we all have in common is an unshakeable conviction that digital assets can democratize access to the integral economy and Ledn’s suite of products & services can play a critical role in doing so. The core values that guide us are: act with integrity always, own it, have a passion for progress, and lead with empathy. Combining these values with our conviction make Ledn an unstoppable force in changing the world for the better.
The Opportunity:
As a full-time Sr. Security Engineer & CISO , you'll be a hands-on, high-ownership individual contributor strengthening our product, cloud, and software delivery security. You'll find vulnerabilities before attackers do, build controls that prevent entire classes of issues from reaching production, and help engineers ship securely. A builder-and-breaker role: you'll assess our applications, APIs, AWS environment, Cloudflare edge, and GitHub workflows from an adversary's perspective, then partner with owners to remediate findings and validate fixes. You'll turn lessons learned into standards, automation, and measurable improvements,
while collaborating with Software Engineering, DevOps, Risk, and Compliance to deliver technical controls, audit evidence, and incident readiness.
This dual-mandate role is based in Spain . Beyond hands-on security engineering, you'll serve as the Spain entity's CISO within the second line of defense — owning the local Information Security Framework and ICT Risk Register, reporting periodically to the Board, and acting as primary contact for the CNMV and external auditors on cybersecurity and DORA compliance.
About The Role:
Sr. Security Engineer Core Responsibilities:
- Secure Design & Threat Modeling : Lead security reviews for new designs and existing features, translating threats into concrete engineering requirements before production.
- Penetration Testing: Plan and execute hands-on testing of web apps, APIs, mobile-facing services, and infrastructure;
document reproducible findings, validate remediation, and coordinate independent assessments.
- Adversarial Validation: Run red-team and purple-team exercises around realistic attack paths;
work with defenders to improve preventive controls, telemetry, detections, and response playbooks.
- Secure Pull Requests: Define risk-based security standards for pull requests, including review requirements and tuned merge gates for secret scanning, SAST, dependency review, and sensitive-code ownership.
- Product & API Security : Review production code and architecture for vulnerabilities in authentication, authorization, session handling, data protection, and business logic;
help teams fix root causes, not just symptoms.
- AWS Security: Assess and harden our multi-
📌 Senior Security Engineer & Ciso (Spain) (Valencia)
🏢 Ledn
📍 Valencia