Senior Security Engineer & CISO (Spain) (Cequeliños)

Senior Security Engineer & CISO (Spain) (Cequeliños)

17 ago
|
Ledn
|
Cequeliños

17 ago

Ledn

Cequeliños

Desplácese hacia abajo y descubra qué habilidades, experiencia y cualificaciones académicas se necesitan. Ledn is the leading bitcoin-backed lender dedicated to providing secure, transparent, and efficient digital asset solutions. Our mission is to help clients build long-term wealth in hard assets through interest-earning accounts, loans, and trading services.

What we all have in common is an unshakeable conviction that digital assets can democratize access to the integral economy and Ledn's suite of products & services can play a critical role in doing so.

The core values that guide us are: act with integrity always, own it, have a passion for progress, and lead with empathy. As a full-time Sr.

Security

Engineer & CISO, you'll be a hands-on, high-ownership individual contributor strengthening our product, cloud, and software delivery security. You'll find vulnerabilities before attackers do, build controls that prevent entire classes of issues from reaching production, and help engineers ship securely. A builder-and-breaker role: you'll assess our applications, APIs, AWS environment, Cloudflare edge, and GitHub workflows from an adversary's perspective, then partner with owners to remediate findings and validate fixes.

You'll turn lessons learned into standards, automation, and measurable improvements, while collaborating with Software Engineering, DevOps, Risk, and Compliance to deliver technical controls, audit evidence, and incident readiness. Beyond hands-on security engineering, you'll serve as the Spain entity's CISO within the second line of defense — owning the local Information Security Framework and ICT Risk Register, reporting periodically to the Board, and acting as primary contact for the CNMV and external auditors on cybersecurity and DORA compliance.

Penetration Testing: Plan and execute hands-on testing of web apps, APIs, mobile-facing services, and infrastructure

- Adversarial Validation: Run red-team and purple-team exercises around realistic attack paths; work with defenders to improve preventive controls, telemetry, detections, and response playbooks.

Product & API Security: Review production code and architecture for vulnerabilities in authentication, authorization, session handling, data protection, and business logic

- AWS Security: Assess and harden our multi-account AWS environment across IAM, network boundaries, encryption, logging, workload identity, and service configuration,



using automation and policy-as-code where practical.

Cloudflare Security: Review and harden WAF rules, rate limiting, bot controls, DNS/TLS configuration, edge access policies, and change governance without disrupting legitimate client traffic.

GitHub & Software Supply Chain: Own security governance for repositories and CI workflows — branch protection, CODEOWNERS, least-privilege tokens, pinned actions, dependency controls, artifact integrity, and guardrails for AI-assisted code.

Vulnerability Management: Triage findings from internal testing, scanners, third-party assessments, and disclosures

- Cybersecurity Framework & Board Reporting: Own the local Information Security Framework and ICT Risk Register; report periodically to the Board on information security and ICT risk; ensure immediate reporting of major incidents to Management and the Board.

DORA Governance & Compliance: Direct the ICT Risk Management Framework and sign off its annual regulatory report; oversee the annual digital operational resilience testing programme (system/network testing plus BCP/DRP exercises); validate the ICT third-party register for CNMV submission. Serve as point of contact for the CNMV and external auditors on information security and DORA matters, in Spanish, including CNMV notification of significant incidents within DORA deadlines. Supervise vulnerability management and day-to-day technical security operations, escalating critical vulnerabilities and driving remediation with the ICT team. 5+ years in security engineering, application/product security, or software/platform engineering with a demonstrable security focus.

Hands-on penetration testing across web applications, APIs, and cloud infrastructure, producing clear, reproducible findings and validating fixes. Production code review skills in JavaScript/TypeScript, Python, Go, or similar, with practical knowledge of authentication, authorization, injection, data exposure, and business-logic risks. Strong AWS security expertise in multi-account environments, including IAM, networking, KMS, logging/detection services,



and workload configuration.

Cloudflare or similar edge-security experience covering WAF, rate limiting, bot management, DNS/TLS, and access controls. GitHub and CI/CD security experience with branch protection, review workflows, repository rules, workflow permissions, token hygiene, and secure automation. Secure SDLC tooling knowledge — SAST, DAST, software composition analysis, secret scanning, container scanning — and how to tune controls so engineers act on results.

Software supply-chain and IaC security, including dependency/artifact risks and reviewing Terraform, Helm, or similar configuration for security gaps. Automation skills in Python, Bash, Go, or JavaScript to extend testing, analyze evidence, and build lightweight security tooling.

Experience in a fintech/regulated environment where audit trails, evidence quality, data protection, and cross-functional partnership matter.

Fluent

English and Spanish, able to explain a technical finding to an engineer and its business risk to senior stakeholders, given this role's CNMV and Board-facing responsibilities. DORA and regulatory governance experience in a European financial-services environment — ICT risk management frameworks, digital operational resilience testing. ICT third-party registers, and acting as a regulator/Board point of contact

- Must be willing to undergo applicable background checks, per local law, if selected. Digital-asset/fintech/payments security experience, especially with account-takeover, fraud-adjacent, custody, or transaction-integrity threat models. Detection and response engineering using cloud telemetry, SIEM tooling, or attack simulation to build actionable detections and playbooks. MiCA familiarity or other EU digital-asset regulatory frameworks, alongside core DORA expertise. Be comfortable owning a complex area end to end and moving fast under pressure, especially when priorities shift or the path forward isn't fully mapped out yet Tremendous growth opportunities within a global digital asset leader Option to work remotely somewhere other than your home base for up to 180 days per year (subject to restrictions) Ledn Working Environment: Our global team operates across North America, Latin America, South Africa, and Europe in a remote-first setup. Due to high application volume, only qualified candidates will be contacted. No agencies or recruiters, please.

📌 Senior Security Engineer & CISO (Spain) (Cequeliños)
🏢 Ledn
📍 Cequeliños

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior security engineer & ciso (spain) (cequeliños) / cequeliños

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior security engineer & ciso (spain) (cequeliños) / cequeliños