The English-language job board for Spain
Cloud & Application Security Engineer
Remote, Castellón de la Plana·Full-time·Added 5 days ago
Overview
Job details
Permanent contract
Full-time hours.
Fully remote
Per the ad.
Requirements
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
This job was automatically translated to English.
Pay & benefits
What you'll get
We take care of our team with facts and conditions designed for high performance and well-being:
- 💼 Stability: Indefinite contract and competitive salary according to your technical experience (we will tell you this with transparency in our first meet)
- ⏰ Real flexible scheduling: We trust your responsibility and autonomy; we have flexible hours and a time bank.
- 🏥 Health and Well-being: Private medical insurance covered by the company
- 🎂 Your time matters: Your birthday is a day off, in addition to special rest holidays (December 24 and 31)
- 🚀 Continuous training: Access to specialized training in cybersecurity, cloud, certifications, and the entire crypto/Web3 ecosystem.
- ⚡ Agile culture: You will work with state-of-the-art tools in a team where your contributions are executed and have direct visibility
Requirements
What we're looking for
- Sec & DevOps Mindset: A solid understanding of how security is built from the origin of the code, how CI/CD pipelines operate, how IaC is managed, and how to structure effective remediation.
- Practical experience in Public Cloud: Proficient handling of core services in IAM, networking, and logging (we work intensively with GCP; if your experience comes from AWS or Azure, we assume the transfer curve).
- Container and Kubernetes Fundamentals: Ability to understand the anatomy of a pod, node, or ingress, and fluency in inspecting and correcting manifests (we will not ask you to operate or administer the cluster alone).
- Solid foundation in Linux and Networking: Mastery of network protocols (TCP/IP, DNS), firewalls, VPNs, and perimeter segmentation.
- Technical prioritization criteria: CVSS is the floor, not the ceiling. We need you to be able to argue and prioritize with business common sense (why an Internet-exposed medium vulnerability takes precedence over a critical one in an isolated internal service).
- Ownership and influence without hierarchy: A large part of your recommendations will be implemented by other Engineering teams. You need skills to communicate the "why," document technical agreements, and drive closure constructively.
Nice to have
- Handling or reading Terraform modules.
- Experience configuring or fine-tuning tools in CI/CD pipelines.
- Familiarity with financial regulations and security frameworks (ISO 27001, MiCA, DORA).
- Automation and scripting via Python, Go, or Bash.
- Adoption of AI tools applied to the technical workflow (Claude Code, Cursor, Claude) to accelerate finding triage, scripting, and code review.
- Practical technical certifications in Cloud or Cybersecurity.
- Experience coordinating operations with external partners and SOC providers.
- Passion or curiosity for the crypto / blockchain ecosystem (a great plus, never an excluding filter).
The role
Are you motivated to protect a crypto infrastructure operating under the MiCA standard, where every line of defense has a real impact on millions of transactions?
At Bit2Me, cybersecurity is not an audit passed once a year or a report that is filed away: it is the core of our product. As the first MiCA-licensed exchange and the leading crypto fintech in Europe, we operate with the highest technical and regulatory demands.
We are not looking for a PDF generator or a desk auditor. We are looking for a Cloud & Application Security Engineer who wants to get into the technical trenches, work shoulder to shoulder with Engineering and SRE, and solve the industry's most critical challenge: closing the gap between detecting a flaw and remediating it in production.
🌟 Your mission: From finding to remediation in code
Your daily focus will be to execute defensive and operational security hand-in-hand with the development and infrastructure teams: prioritizing by real impact and risk (not by theoretical numbers), executing the hardening of our environments, and transforming cybersecurity policies into automated controls as code (IaC and DevSecOps).
You will be part of the Information Security team (reporting to the Security Management), in constant communication with Cloud Security, AppSec, SRE, Software Engineering, and our specialized SOC and vulnerability management partners.
What you'll do
- Living management of the vulnerability lifecycle: You will perform triage by CVE, evaluating real contextual risk (base severity, active exploitability, Internet exposure, and existing compensatory controls), pushing each ticket until its verified closure in production.
- Governance and prioritization of the security backlog: You will maintain and organize the technical vulnerability board by asset, establishing realistic resolution cycles and systematically expanding our perimeter coverage.
- Hardening and Cloud infrastructure security: You will analyze and fine-tune security rules and alerts, audit project configurations, IAM policies, and cloud network segmentation.
- Security integrated into CI/CD (DevSecOps): You will implement and maintain DAST, SAST, SCA, and secret scanning controls in deployment pipelines, mitigating technical debt and validating the security of relevant architectural changes.
- Security as Code (IaC): You will collaborate with the SRE team on the terraformization of security controls so that infrastructure is deployed hardened by default (Security by Design & Default).
🙅 What we will NOT ask of you
We believe in honest offers that represent real work:
- It is NOT a Pentesting or Red Team position: For intrusion exercises and offensive audits, we rely on specialized external partners and companies.
- We do NOT require previous experience in Blockchain or Web3: It is the industry where you will operate, but what we value from the start is your rigor in cloud and application security.
- You will NOT have direct communication with the regulator: The Compliance and Legal area handles that layer.
- We are NOT looking for a "unicorn" who is an absolute expert in Cloud, AppSec, and IaC all at once: We are looking for a solid technical base in security and infrastructure, combined with autonomy and a real desire to deepen knowledge in the other areas.
About Bit2Me
Bit2Me is a Spanish cryptocurrency exchange and digital asset platform founded in 2014, headquartered in Madrid. It provides a comprehensive suite of services including crypto trading, custody, payments, and educational resources, and has grown to become one of the most prominent crypto companies in Spain and Latin America. The platform is known for its user-friendly interface and has expanded its offerings to include a crypto card and institutional services.
Bit2Me has a strong presence in Spain, with its main office in Madrid and additional operations in other Spanish cities. The company is actively expanding its team, particularly in HR and operations, as it scales its business. For international professionals, Bit2Me offers a dynamic, fast-paced work environment in the fintech/crypto sector, with opportunities to contribute to the growth of a leading European crypto platform. The company values innovation and is committed to regulatory compliance, making it a stable yet exciting place to work.
- Industry
- Crypto
- Founded
- 2014
- Employees
- 100–500
- Headquarters
- Madrid, Spain
- In Spain
- Madrid, Barcelona
- Website
- bit2me.com
Good to know if you are moving
- Bit2Me is headquartered in Madrid, offering a central location in Spain's capital with a growing tech and crypto ecosystem.
- The company is a pioneer in the Spanish crypto market, being one of the first to obtain regulatory approval from the Bank of Spain.
- Bit2Me has a strong focus on education and innovation, providing a dynamic environment for professionals looking to grow in the blockchain industry.
- The company supports remote work and has a multicultural team, making it accessible for international hires.
- Bit2Me is expanding its operations in Latin America, offering opportunities for professionals interested in international markets.
More jobs like this
or browse Security·Mid-level·Remote·Banking & Fintech·Cybersecurity·Crypto & Blockchain·Crypto


