26 sep
|
Jobrapido
|
Barcelona
26 sep
Jobrapido
Barcelona
Overview As an Application Security Engineer at Factorial, you help build secure software at speed by actively hunting vulnerabilities and shaping practical security practices. You’ll work with Product and Engineering to integrate security into design, testing, and operations, including AI-enabled features. You’ll fix issues, build guardrails, and automate security controls used by developers daily. This role offers exposure to a fast-moving, AI-driven environment with real impact on product security and risk posture.
Compensaciones / Beneficiosprivate health insuranceWellhub fitness benefitsCobee expense savingslanguage classesoffice breakfast and organic fruitpet-friendly office ResponsabilidadesConduct proactive penetration testing across applications, APIs, infrastructure, and AI featuresReproduce and validate vulnerability reports from third parties and bug bounty programsCollaborate with development teams to remediate findings and improve secure coding practicesImprove validation, triage, and remediation workflows for vulnerabilities from bugs, automated controls, and external researchIdentify recurring or legacy vulnerability patterns via root cause analysis and past incidentsBuild and enhance security automations, agents,
and CI/CD controls for earlier issue detectionSecure AI usage across product and internal workflows, including LLMs, data access, tools, permissions, and abuse scenariosContribute to security tools, automations, and infrastructure developmentStay current with security research, threats, and emerging AI security risks Requisitos principales3+ years of experience in Application Security, Offensive Security, or Penetration Testing with mandatory Web Application Penetration TestingDegree in Engineering or Computer Science with solid knowledge of web apps, databases, networks, and operating systemsStrong grounding in cybersecurity fundamentals, CVSS, testing methodologies, and toolingScripting/programming skills used in security testing and automation (e.g., Python or Bash)Ability to move across different security problems, balance attack focus with tool-building, and design pragmatic solutionsCuriosity about AI security topics (LLM testing, prompt injection, agentic workflows, data exposure, tool permissions, RAG security)Certifications like BSCP or eWPTX are valued but not requiredExperience with Ruby/Ruby on Rails is a plus but not mandatoryEnglish fluencycuriousproblem-solving mindsetcollaborative teamworkWeb Application Penetration Testingsecure coding practicesScripting in Python or Bash
📌 Offensive Security Engineer (Barcelona)
🏢 Jobrapido
📍 Barcelona