Active Cyber Defense Expert

Spain·Added 6 days ago

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Speak fluent Spanish

    Listed as a requirement in the ad.

  • Work in English

    English is required, per the ad.

  • Work on-site in Spain

    No relocation package mentioned.

  • Have 10+ years of experience

    Senior-level role.

About the job

This job was automatically translated to English, .

We connect the present. We transform the future.

Have you ever wondered what makes it possible for millions of people to be connected at the same time, from anywhere in the world, without anything failing?

At Telefónica, we make it possible.

We are a global telecommunications and technology company that connects people, businesses, and communities through next-generation networks and advanced digital solutions such as cloud, artificial intelligence, IoT, and cybersecurity.

With over 100 years of history, we work every day to ensure that innovation serves society, driving a digital transformation that is responsible, sustainable, and has real impact.

Here, we don't just design infrastructure—we design the future. We are looking for people who are curious, enthusiastic, and passionate about what they do, who never settle, and who want to build the Telefónica of tomorrow.

If you are passionate about technology that transforms lives, this is your place.

The Global Active Cyber Defense team is responsible for the identification, analysis, and validation of vulnerabilities in infrastructures, applications, and services within the Internet-exposed attack surface of the entire Telefónica group, supporting this through specialized tools, offensive techniques, and the use of AI technology.

What skills are we looking for in you? 🔎

What you'll do

  • Management and execution of vulnerability scans:
  • Configure, launch, and maintain periodic scans using tools such as Nessus, Acunetix, and other scanning platforms.
  • Vulnerability analysis and prioritization:
  • Review scan results, eliminating false positives and validating findings.
  • Prioritize risks based on business impact, criticality, and exposure (CVSS, internal context).
  • Security assessment in web applications:
  • Use tools such as Acunetix to detect OWASP Top 10 vulnerabilities (SQLi, XSS, CSRF, etc.).
  • Perform complementary manual reviews to validate critical vulnerabilities.
  • Vulnerability lifecycle management:
  • Coordinate remediations with technical teams (IT, development, cloud).
  • Follow up until closure and verification of fixes.
  • Tool development and offensive automation:
  • Create and maintain proprietary tooling for offensive operations (scripts, payloads, attack infrastructure).
  • Innovate in evasion and persistence techniques.
  • Offensive cybersecurity research:
  • Analyze new vulnerabilities, attack techniques, and trends.
  • Adapt team capabilities to emerging scenarios.

What other aspects are relevant?📚

What we're looking for

  • Ability to carry out a pentest in all its stages (planning, scoping, execution, reporting):
  • Performing technical security audits (black box, white box, and grey box) of systems, networks, and web applications, APIs,
  • Intrusion testing (internal, external, and active directory).
  • Security reviews of mobile device applications (Android and iOS),
  • WiFi audits, cloud security reviews (IaaS, PaaS, SaaS, CaaS), in virtual desktop infrastructure (VDI) and thick clients.
  • Static code audits, network traffic analysis, denial of service testing, social engineering testing, forensic analysis, script development, vulnerability research.
  • Performing security reviews on ATMs, payment systems, and OT networks.
  • Development knowledge:
  • Python and Go lang.
  • Web development (Python Backend, VueJS Frontend).
  • Deployment via Docker.
  • Ability to develop or modify the necessary tools.
  • Development of malware or APT simulation tools.
  • OS internals (Windows + Linux).
  • Knowledge of Windows AD intrusion.
  • Reverse engineering.
  • High level of Spanish and English, allowing for effective communication and collaboration in multinational environments, including meetings and workshops. Knowledge of Portuguese and German will be valued.
  • AI knowledge: Solid understanding of artificial intelligence fundamentals and their practical application in cybersecurity use cases.
  • Communication and management ability with the teams responsible for the affected systems, cooperation for vulnerability resolution.

How will you contribute to the purpose of the role with your skills? 💼

  • Bachelor's Degree in Computer Engineering, Telecommunications, or equivalent work experience.
  • University Master's in Cybersecurity or equivalent work experience.
  • Demonstrable experience of 10 years.

What advantages will you have by being part of our team?💙

What you'll get

  • Transformative projects. At Telefónica, you will be part of high-impact projects that set trends and address the connectivity and digital transformation challenges of our society.
  • Professional development. You will have a long career path and learning opportunities on a global scale, thanks to our presence in different geographies. We will share with you opportunities for development, training and mobility options. We want to grow and build a future with you!
  • Flexibility. We are committed to the balance between professional and personal life. At Telefónica, we care about flexibility, positioning ourselves as a benchmark in new ways of working and work-life balance measures.
  • 27 working days of vacation to enjoy.
  • Benefits. You will enjoy a comprehensive package of social benefits, including:
    • Life and accident insurance
    • Health insurance for you and your family unit (spouse and children)
    • Meal voucher card
    • Flexible compensation plan with numerous options to choose from.
    • Pension plan

And much more!

Additional information

At Telefónica, we are committed to building a diverse, inclusive, and sustainable work environment where every person feels valued, respected, and free. Our culture is based on equal opportunity and inclusion because we have the responsibility to transform society and make the world a better place.

If you want to be part of an innovative team and contribute to a better future, we are waiting for you!

WhatsApp