HQ - Senior Information Security Engineer
Job description
About the role
Senior Information Security Engineer
This page presents the official opportunity for a Senior Information Security Engineer. The role is focused on protecting critical digital assets and ensuring the reliability of operations. It is designed for a professional who will manage responses to security events while actively strengthening the organization's defenses. The position is fully remote, allowing for work flexibility within one hour of Central European Time.
Position Overview
The Senior Information Security Engineer will take direct responsibility for incident management. This involves overseeing the complete lifecycle of security events from detection through resolution. The goal is to minimize the impact of incidents and prevent future occurrences. In addition to reactive duties, the role requires proactive enhancement of the security framework. The engineer will analyze current processes and implement changes to improve resilience. Success in this role means ensuring that security operations are both efficient and effective.
This position plays a key role in safeguarding the company's infrastructure, data, and business continuity. The work directly supports the organization's ability to operate securely in a evolving threat landscape. The engineer will help shape the security culture by demonstrating best practices and rigorous analysis. The role requires a balance of technical depth and process discipline. The position is based in a remote capacity with specific timing considerations.
Primary Responsibilities
A core duty is to design and manage the intake of security alerts. This ensures that potential incidents are captured and categorized correctly. The engineer will define the criteria used to scope incidents based on severity and impact. This structured approach allows the team to prioritize responses effectively.
The engineer will build and maintain monitoring rules and detection logic. These tools are used to identify unusual or suspicious behavior across the technology environment. The rules must be precise to reduce noise and highlight true threats. Regular review of these detection mechanisms is essential for maintaining accuracy.
The role includes facilitating review sessions for security findings. These meetings are used to assess the details of potential incidents. The outcomes of these reviews are used to refine and improve response procedures. Clear documentation of these changes ensures consistency in future responses.
Another key duty is coordinating the implementation of fixes and security controls. The engineer must manage the deployment of changes carefully. The objective is to reduce exposure without causing disruption to business operations. Testing and validation are critical steps in this process.
The engineer will also establish playbooks for external partners. These documents align vendors and collaborators on procedures for handling events. Consistent application of these playbooks ensures a unified response. This external coordination is vital for comprehensive security management.
Tooling configuration falls within the scope of this position. The engineer will implement solutions that centralize log collection. This centralization provides analysts with a clear view of the security landscape. Improved visibility allows for faster detection and investigation of threats.
The role drives broader security improvement initiatives. This includes hardening infrastructure and updating security configurations. The engineer will identify gaps and propose solutions to address them. These initiatives contribute to a more robust security posture over time.
Finally, maintaining detailed documentation is a required task. Documentation explains the reasoning behind key decisions. It supports internal audits and external compliance reviews. Good documentation also assists in onboarding new team members.
Required Qualifications
Candidates must have three to five years of relevant professional experience. This experience should involve managing security incidents and driving improvements. A proven track record in handling security events is essential.
Applicants need a strong understanding of common vulnerabilities. This includes knowledge of how these vulnerabilities are exploited. Familiarity with attack vectors and threat techniques is necessary. This knowledge is used to identify weaknesses and recommend fixes.
Experience applying security concepts in real-world scenarios is required. The engineer should be comfortable working with modern technology stacks. This includes cloud platforms, networks, and application environments. Technical knowledge must be current and practical.
Clear communication skills are a fundamental requirement. The engineer must explain technical topics to technical audiences. Equally important is the ability to communicate with non-technical stakeholders. This ensures that security issues are understood across the organization.
The position requires adherence to a specific work schedule. The engineer must be available with flexibility within one hour of CET. This schedule supports collaboration with global teams and partners.
Compensation and Location
The position is classified as a permanent engagement. The location for this role is listed as Madrid, Spain. The compensation range for this position is between 55,000 and 70,000 EUR per year. These figures are indicative and may vary based on experience.
What you'll do
- Meet the bar Practical notes