Product Engineer (Security) (Barcelona)

Product Engineer (Security) (Barcelona)

27 sep
|
Noomeroo
|
Barcelona

27 sep

Noomeroo

Barcelona

ABOUT US

Noomeroo is an AI financial co-pilot for Spanish SMEs and the accountants who serve them. We're live and onboarding customers, with a lean, AI-augmented team that moves faster than companies several times our size.

We work differently from most companies our size. Our founders are technical and build alongside the engineering team with modern AI-assisted tooling. In this role you'll own the quality, security and reliability of what we ship, lead our compliance-critical integrations, and help set the engineering standard as we scale.

Security is a dedicated responsibility at Noomeroo from day one, because our clients trust us with their financial data. This role brings product engineering and security together: you'll build and review code, and you'll own how we protect client data.

We're looking for engineers who treat AI as a serious tool, one that accelerates good work but still needs sharp human judgement to ship safely. If that's how you already work, you'll feel at home here.

THE STACK

React/TypeScript frontend, Postgres + serverless backend, deployed on a modern PaaS. If those words mean something specific to you, you'll know what we're using.

WHAT YOU'LL ACTUALLY DO

Engineering

- Lead code review and quality standards. Set the bar for what reaches production: correctness, edge cases and security.
- Keep the platform fast and reliable. Monitor, diagnose and resolve issues quickly for the businesses that depend on us.
- Own our compliance integrations. E-invoicing, open banking and tax authority compliance are the highest-stakes parts of the stack. You own them end to end.
- Evolve our environments and release process. We run a structured staging-to-production promotion process. You'll develop it further as we scale.
- Build features. Using the same AI-assisted tooling we all use. No religion about who writes what.

Security





- Own security across the stack. Multi-tenant data isolation, access control, authentication, secrets and key management.
- Harden what we depend on. Dependency management, vulnerability scanning and supply-chain security across everything we run.
- Own monitoring and incident response. Logging, alerting and a clear, practised response process, owned by you.
- Be our security voice. Answer security questionnaires from banking and compliance partners, work with external auditors when needed, and keep our data-protection controls in shape.

WHO YOU ARE

- Proven shipping experience. You've built and run production apps with React, TypeScript and a serverless Postgres stack
- Security-minded by instinct. You know the OWASP Top 10 well, you've implemented or reviewed auth and access control, and you think about how things break before you think about how they work
- Fluent with AI-assisted development. You have opinions about prompts, context files and when AI gets things wrong, and you bring engineering judgement to every line that ships
- Sharp debugger. You can read an error, open the right file and find the cause in minutes
- Low ego, high standards. You don't care who wrote the code. You care that it works, that it's secure, and that it ships
- Energised by impact. You like a focused team where your work is visible and matters from week one
- Based in Barcelona, or ready to relocate. This role is in-office
- Bonus: fintech or regulated-data experience, GDPR in practice,



or a security certification. If the instinct is there, we'll back you to grow the rest

YOU'LL PROBABLY LOVE THIS IF

- You've been quietly frustrated that the industry hasn't caught up with how you actually work
- You want to ship things real people use, not maintain a legacy codebase
- You want to join the core team early, with real ownership and equity upside
- You want to grow into security with real responsibility, not a ticket queue
- You like working in person, with fast whiteboard sessions and tight feedback loops

YOU'LL PROBABLY HATE THIS IF

- You believe AI-assisted code is fundamentally unreliable
- You need months of architecture work before shipping anything
- You want heavyweight process and long sprint rituals
- You prefer process over judgement, or need approvals to fix things
- You're looking for full-remote

WHAT WE OFFER

- €45-50K base + equity
- Barcelona office, in person, with founders who ship daily and respect engineering work
- Real investment in your security growth: training, certifications, conference time
- A clear path to lead engineering as we grow

HOW TO APPLY

Send us

1. A short note (5-10 lines is fine): how you use AI in your day-to-day work, and one thing you've shipped recently you're proud

of
1. Links to your work: GitHub, side projects, anything that shows how you build
2. One paragraph on this: "Our team ships with AI-assisted tooling and every change is reviewed before production. How would

you design that review process so it stays rigorous without slowing delivery?"
1. One sentence: in a multi-tenant Postgres app, how would you verify tenant isolation actually holds?

Skip the formal CV unless you really want to. We care more about how you think than where you worked. Apply here: [email protected]

📌 Product Engineer (Security) (Barcelona)
🏢 Noomeroo
📍 Barcelona

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: product engineer (security) (barcelona) / barcelona