Data Engineer
We are looking for a Data Engineer to join our technological and data projects. You will work in an international environment with cloud and AI technologies.
The English-language job board for Spain
88,000+ live jobsPermanent contract
Full-time hours.
Fully remote
Only from certain places, per the ad: “con posibilidad de trabajar desde cualquier punto de España”
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Work in English
English is required, per the ad.
Have 4+ years of experience
Senior-level role.
University degree
“Formación técnica en Ingeniería Informática, Telecomunicaciones, Ciberseguridad o similar.” — per the ad.
This job was automatically translated to English.
📝 Stable employment at an international company.
💰 Salary range according to your experience and responsibilities.
📊 Flexible compensation.
📖 Continuous training and specialization in AppSec, DevSecOps, and Cloud Security.
🚀 Participation in strategic cybersecurity and application security projects.
🏠 100% remote work and flexible scheduling.
📈 Professional development plan within a specialized team and with exposure to emerging security technologies.
📩 If you have experience in AppSec and want to participate in the evolution of application security programs, evaluation of new technologies, and the definition of Security by Design, we would love to meet you!
Technical training in Computer Engineering,
Minimum 4 years of experience in AppSec or related disciplines such as Cloud Security, DevSecOps or Offensive Security.
Experience in at least two of the following areas:
Security by Design.
Verification & Continuous Testing.
Design and evolution of AppSec frameworks.
Experience evaluating new security technologies, performing PoCs, and documenting adoption recommendations.
Ability to analyze and compare security solutions from an independent perspective.
Experience with SAST / AI-SAST tools, such as SonarQube, Semgrep, GitHub Advanced Security/CodeQL, Checkmarx, or Snyk Code.
Knowledge of SCA and reachability analysis, using tools such as Prisma Cloud App Security, JFrog X-Ray, Dependency Track, or Trivy.
Experience or knowledge in DAST, IAST, RASP, and API Security.
Knowledge of DefectDojo and prioritization models based on EPSS, CISA KEV, reachability, and asset context.
Experience with containers and Kubernetes from a security standpoint.
Fluent English for technical communication with international teams and vendors.
Experience building or leading an AppSec program from scratch or in a significant evolution phase.
Knowledge of offensive security and exploit chains, including BOLA, SSRF, IDOR, and vulnerability chaining.
Experience in AI/ML Security, including OWASP LLM Top 10, security of models in production, and AI supply chain.
Certifications such as CCSP, OSCP, CSSLP, AWS Security Specialty, CKS or equivalents.
Knowledge of regulatory frameworks such as NIS2, ENS, or IEC 62443.
We are looking for an AppSec Specialist, with solid experience in Application Security, DevSecOps, Cloud Security or Offensive Security, to reinforce the team responsible for the evolution of the AppSec framework for one of our main clients.
The selected person will have a specialized role in three key areas: Security by Design, Verification & Continuous Testing and the development of new initiatives, participating both in the definition of frameworks and in the evaluation of new technologies and security capabilities.
Lead the Security by Design (SbD) practice, defining security requirements and controls and integrating them into the development cycle.
Conduct sessions with development teams to ensure the correct application of security requirements.
Design and evolve the Verification & Continuous Testing model, defining the different layers of analysis and testing.
Establish vulnerability prioritization and security gate criteria within the production deployment cycle.
Participate in the evolution of the AppSec framework, identifying new needs and capabilities.
Lead PoCs and benchmarks of new technologies within the AppSec Laboratory.
Define evaluation criteria, execute proof of concepts, analyze results, and prepare adoption recommendations.
Evaluate solutions independently, identifying the most suitable technology for each need without dependency on a specific vendor.
Collaborate with development, security, and technology teams to integrate AppSec capabilities into their processes.
Work with advanced vulnerability prioritization models, considering factors such as reachability, EPSS, KEV, and asset context.
📍 Work model
Excelia is a Canadian IT services and consulting company headquartered in Montreal, specializing in cybersecurity, cloud solutions, data analytics, and enterprise software implementation. The company operates across multiple countries, offering services such as managed IT support, security consulting, and implementation of platforms like Microsoft Dynamics 365 and Azure. With a workforce of several hundred employees, Excelia serves clients in various industries, focusing on digital transformation and IT security.
In Spain, Excelia has established a significant presence with offices in Madrid, Barcelona, and Bilbao, and is actively hiring for over 50 roles in cybersecurity, cloud architecture, software development, and data engineering. The company's work culture emphasizes technical expertise and professional growth, making it an attractive option for international professionals with skills in Microsoft technologies, cybersecurity, and data. Excelia offers opportunities for both junior and senior roles, including internships, and supports relocation for qualified candidates.
At Excelia, a multinational consulting, technology, and professional services firm, we have over 25 years of experience and a presence in more than 50 countries across Europe, Latin America, and the United States, through our 9 own offices.
or browse Madrid·Security·Security·Senior·Remote·Cybersecurity·Community of Madrid