Jobgether

Principal Security Engineer

Jobgether Spain

Internet Marketplace Platforms · 11-50 employees

13 h ago
Remote security Principal (10+ yrs) Full-time Spain
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will design, deploy, and operate security controls across cloud and on-premises infrastructure to protect critical trading systems. The role involves hands-on implementation of identity management, CI/CD pipeline hardening, and incident response automation.

What they look for

Security Engineering Cloud Security Identity and Access Management AWS Azure CI/CD Security Incident Response Security Automation Linux Python Bash Terraform Pulumi GitLab Cryptography Risk Management

Requirements

The role requires 8+ years of hands-on experience in security engineering with deep expertise in IAM and cloud security platforms like AWS and Azure. Candidates must possess strong scripting skills in Python or Bash and the ability to drive technical security initiatives independently.

Benefits

Direct ownership of security implementation High-impact role Significant autonomy Exposure to low-latency trading infrastructure Work on challenging security problems Hands-on technical environment

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security Engineer based in Spain.

As a Principal Security Engineer, you will take hands-on ownership of security implementation across a global, always-on digital asset trading environment. You will design, deploy and operate security controls across cloud, on-premises infrastructure and critical production systems. The role combines cloud security, identity and access management, key protection, CI/CD security, incident response and security automation. You will work closely with Infrastructure and Engineering teams to embed effective security controls directly into systems and development workflows. With a strong focus on practical execution, you will write code, configure systems and solve complex security challenges rather than focus on policy or people management. The environment is technically demanding and fast-moving, with resilience, low latency and risk discipline at its core. You will have significant autonomy and the opportunity to make an immediate impact on the security of critical trading infrastructure.

\n

Accountabilities

  • Implement, operate and continuously improve security controls across multi-cloud environments, primarily AWS and Azure, with exposure to GCP and AliCloud, as well as on-premises infrastructure.
  • Own the implementation of identity and access management strategies, designing secure, scalable and practical models for identities, permissions and privileged access.
  • Design and operate key management and custody security controls, including HSMs, secrets management and secure handling of sensitive cryptographic keys used in trading operations.
  • Harden GitLab CI/CD pipelines and integrate security controls throughout the software development and delivery lifecycle.
  • Configure and maintain corporate security technologies, including endpoint protection, mobile device management, Jamf, DLP and identity management platforms.
  • Respond to security incidents by triaging alerts, investigating threats, containing incidents and driving remediation through to completion.
  • Conduct security assessments across infrastructure and applications to identify vulnerabilities, weaknesses and opportunities for improvement.
  • Automate security operations, including detection, alerting, monitoring and response processes.
  • Partner closely with Infrastructure teams to embed security into cloud provisioning, infrastructure configuration and operational workflows.
  • Identify opportunities to improve security resilience while minimizing unnecessary friction for engineers and other technical stakeholders.
  • Own security problems end-to-end, from identifying risks and designing solutions through implementation, testing and ongoing operation.

Requirements

  • 8+ years of hands-on experience in security engineering, security operations or a closely related technical security discipline.
  • Deep expertise in identity and access management, including practical experience designing and implementing IAM across cloud environments.
  • Strong, well-developed opinions on IAM architecture, access models, permissions and identity security, backed by hands-on implementation experience.
  • Strong working knowledge of cloud security controls across multiple providers, particularly AWS and Azure.
  • Experience securing CI/CD platforms and software delivery pipelines, with GitLab experience preferred.
  • Familiarity with corporate IT security technologies such as Jamf, endpoint protection, DLP, SSO and identity providers.
  • Strong Linux skills and confidence with scripting and automation using Python, Bash or similar languages.
  • Experience with infrastructure-as-code technologies such as Terraform or Pulumi is an advantage.
  • Ability to investigate security incidents, assess infrastructure and application risks, and implement practical remediation.
  • Experience operating effectively in fast-paced, technically complex environments where security, resilience and availability are critical.
  • Strong problem-solving and ownership mindset, with the ability to independently drive technical initiatives from identification through implementation.
  • Clear communication skills and the ability to collaborate effectively with Infrastructure and Engineering teams.
  • Experience in financial services, digital assets, cryptocurrency or other regulated environments is beneficial but not required.
  • Demonstrated technical capability and practical experience are valued more highly than security certifications.

Benefits

  • Direct ownership of security implementation across critical infrastructure.
  • High-impact role within a small, highly technical security team.
  • Significant autonomy and responsibility over security engineering initiatives.
  • Opportunity to work closely with Infrastructure and Engineering teams and influence security architecture in practice.
  • Exposure to low-latency trading infrastructure and complex digital asset technology.
  • Opportunity to work on challenging security problems across multi-cloud and on-premises environments.
  • Hands-on technical role focused on building, automating and operating security controls rather than policy administration or people management.
  • Opportunity to make immediate, measurable contributions to security resilience and risk management.
  • Fast-paced technical environment with direct exposure to senior leadership and business-critical security decisions.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Similar roles