The English-language job board for Spain
Overview
Job details
Full-time hours
Per the ad.
Fully remote
Per the ad.
Requirements
Have the right to work in Spain
Kestra doesn't mention sponsorship, but this role may fit the Digital nomad visa.
Work in English
English is required, per the ad.
Have 5+ years of experience
Senior-level role.
Pay & benefits
What you'll get
Work from anywhere: We're a remote-first company, so you can work from wherever feels like home. Plus, you'll have access to coworking spaces worldwide if you ever need a change of scenery.
Health coverage: From medical support, dental, and vision, we've got you covered.
Home office setup on us: We'll provide all the equipment you need to work comfortably.
Requirements
What we're looking for
5+ years of experience in Security Engineering, Product Security, DevSecOps, or a combined Offensive/Defensive role.
Strong hands-on penetration testing background, with proven ability to discover application, API, and network-level vulnerabilities.
A builder/fixer mindset: You don't just export scanner PDFs; you can read code, understand exploits, write fixes, or provide clear remediation steps to engineers.
Deep familiarity with cloud security (AWS or GCP) and containerized environments (Kubernetes, Docker).
Experience with dependency and supply-chain security (CVE management, open-source licensing, SCA tools).
Fluent in English and comfortable working autonomously in a fully remote environment.
Adaptability to a fast-paced open-source startup environment where pragmatism and execution speed matter.
The role
Kestra runs arbitrary, user-defined code at scale. Our users write workflows that execute scripts, containers, and queries against their own production systems, through hundreds of community-built plugins, on a platform whose entire source code is public. That is an unusually rich attack surface, and securing it is a genuinely hard engineering problem rather than a checklist exercise.
You would be our first dedicated security hire. We're looking for a Senior Security Engineer to own and elevate the end-to-end security posture of our platform, infrastructure, and open-source ecosystem.
This is a unique, hybrid role for someone who excels at both sides of security: actively breaking systems to find vulnerabilities (hands-on penetration testing) and actively fixing them (opening PRs, patching infrastructure, and managing supply chain risks). If you want to build a world-class security foundation for a fast-growing open-source and SaaS platform, this role is for you.
This is a hands-on engineering role, not a GRC or compliance one.
What you'll do
Conduct hands-on penetration testing and threat modeling across our web application, APIs, control plane, and cloud environments.
Manage end-to-end vulnerability tracking across our codebases, software dependencies (SCA), container images, and cloud infrastructure.
Proactively fix security flaws by writing patches, submitting Pull Requests (PRs), or collaborating directly with product teams to guide remediation.
Audit and harden our cloud infrastructure (GCP, Kubernetes clusters, and networking configurations) against external and internal threats.
Automate security tooling into our CI/CD pipelines (SAST, DAST, dependency scanners) to catch CVEs before code reaches production.
Perform security code reviews and evaluate third-party dependencies, open-source integrations, and supply-chain risks.
Lead incident response efforts and establish continuous monitoring, detection, and mitigation strategies.
Own our public security posture as an open-source project: vulnerability disclosure process, CVE handling, security advisories, and the trust model of our plugin ecosystem.
About Kestra
Kestra is the universal orchestration platform: open source, declarative, and designed to orchestrate data pipelines, IT automation, business workflows, and AI/agentic systems.
Trusted by over 10,000 organizations worldwide, including JPMorgan Chase, Bloomberg, FILA, and Crédit Agricole, Kestra orchestrates mission-critical workloads at scale. The open-source project has close to 30,000 GitHub stars, hundreds of contributors, and a fast-growing global community.
What you would do
Your first six months would focus on the first three points below. The rest is where the role grows.
Our Tech Stack
Security & Vulnerability Tools: Trivy, GitHub Security / Dependabot, Elastic Security
Infrastructure: Docker, Kubernetes, Terraform
Cloud: GCP
Programming language: Java, Typescript, Javascript
Datastore: PostgreSQL, Elasticsearch
Queuing: Redis, Kafka, AMQP
Monitoring & Logs: ELK, Prometheus, Grafana
Deployment & Repository: GitHub Actions, ArgoCD
Hiring process
We aim to move quickly (2-3 weeks), but we can adjust the timeline if needed.
Intro call with the hiring manager (30 min)
Technical scenario / Practical assessment (2 hours, asynchronous homework focusing on threat assessment and remediation)
Team chat with one of your future colleagues (30 min)
Final discussion with one of our co-founders (30 min)
About Kestra
Kestra is a French technology company that builds open-source orchestration and scheduling platforms for data workflows. The company provides a unified solution for managing complex data pipelines, event-driven workflows, and infrastructure automation, positioning itself as a key player in the modern data engineering ecosystem. Kestra's platform is designed to be cloud-agnostic and vendor-neutral, allowing organizations to orchestrate their data processes with a high degree of flexibility and control.
Kestra has a growing presence in Spain, with a dedicated team of engineers and product managers working remotely. The company's culture is remote-first and highly technical, making it an attractive option for international professionals looking to work on cutting-edge data infrastructure. With roles in engineering, product management, and quality assurance, Kestra offers opportunities for those with strong technical skills to contribute to a rapidly scaling open-source project.
- Industry
- Data Orchestration
- Founded
- 2021
- Employees
- 11–50
- Headquarters
- Pau, France
- In Spain
- Remote (Spain)
- Website
- kestra.io
Good to know if you are moving
- Kestra is a remote-first company, allowing employees to work from anywhere in Spain or globally.
- The company is open-source, meaning all code and documentation are publicly accessible, which is a strong plus for engineers who value transparency.
- Kestra's tech stack is modern and includes Java, Micronaut, and various cloud-native technologies, offering a great opportunity to work with cutting-edge tools.
- The company has a strong focus on developer experience and community, with a public roadmap and a highly active Slack community.
- As a French company, Kestra offers a gateway to the European tech market, with Spain being a key hub for its remote-first hiring.
More jobs like this
or browse Security·Security·Senior·Remote·Cybersecurity·Digital nomad visa fit·Data Orchestration




