Active Cyber Defense Expert
Spain·Added 6 days ago
202 open roles
What they ask for
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Speak fluent Spanish
Listed as a requirement in the ad.
Work in English
English is required, per the ad.
Work on-site in Spain
No relocation package mentioned.
Have 10+ years of experience
Senior-level role.
About the job
This job was automatically translated to English, .
We connect the present. We transform the future.
Have you ever wondered what makes it possible for millions of people to be connected at the same time, from anywhere in the world, without anything failing?
At Telefónica, we make it possible.
We are a global telecommunications and technology company that connects people, businesses, and communities through next-generation networks and advanced digital solutions such as cloud, artificial intelligence, IoT, and cybersecurity.
With over 100 years of history, we work every day to ensure that innovation serves society, driving a digital transformation that is responsible, sustainable, and has real impact.
Here, we don't just design infrastructure—we design the future. We are looking for people who are curious, enthusiastic, and passionate about what they do, who never settle, and who want to build the Telefónica of tomorrow.
If you are passionate about technology that transforms lives, this is your place.
The Global Active Cyber Defense team is responsible for the identification, analysis, and validation of vulnerabilities in infrastructures, applications, and services within the Internet-exposed attack surface of the entire Telefónica group, supporting this through specialized tools, offensive techniques, and the use of AI technology.
What skills are we looking for in you? 🔎
What you'll do
- Management and execution of vulnerability scans:
- Configure, launch, and maintain periodic scans using tools such as Nessus, Acunetix, and other scanning platforms.
- Vulnerability analysis and prioritization:
- Review scan results, eliminating false positives and validating findings.
- Prioritize risks based on business impact, criticality, and exposure (CVSS, internal context).
- Security assessment in web applications:
- Use tools such as Acunetix to detect OWASP Top 10 vulnerabilities (SQLi, XSS, CSRF, etc.).
- Perform complementary manual reviews to validate critical vulnerabilities.
- Vulnerability lifecycle management:
- Coordinate remediations with technical teams (IT, development, cloud).
- Follow up until closure and verification of fixes.
- Tool development and offensive automation:
- Create and maintain proprietary tooling for offensive operations (scripts, payloads, attack infrastructure).
- Innovate in evasion and persistence techniques.
- Offensive cybersecurity research:
- Analyze new vulnerabilities, attack techniques, and trends.
- Adapt team capabilities to emerging scenarios.
What other aspects are relevant?📚
What we're looking for
- Ability to carry out a pentest in all its stages (planning, scoping, execution, reporting):
- Performing technical security audits (black box, white box, and grey box) of systems, networks, and web applications, APIs,
- Intrusion testing (internal, external, and active directory).
- Security reviews of mobile device applications (Android and iOS),
- WiFi audits, cloud security reviews (IaaS, PaaS, SaaS, CaaS), in virtual desktop infrastructure (VDI) and thick clients.
- Static code audits, network traffic analysis, denial of service testing, social engineering testing, forensic analysis, script development, vulnerability research.
- Performing security reviews on ATMs, payment systems, and OT networks.
- Development knowledge:
- Python and Go lang.
- Web development (Python Backend, VueJS Frontend).
- Deployment via Docker.
- Ability to develop or modify the necessary tools.
- Development of malware or APT simulation tools.
- OS internals (Windows + Linux).
- Knowledge of Windows AD intrusion.
- Reverse engineering.
- High level of Spanish and English, allowing for effective communication and collaboration in multinational environments, including meetings and workshops. Knowledge of Portuguese and German will be valued.
- AI knowledge: Solid understanding of artificial intelligence fundamentals and their practical application in cybersecurity use cases.
- Communication and management ability with the teams responsible for the affected systems, cooperation for vulnerability resolution.
How will you contribute to the purpose of the role with your skills? 💼
- Bachelor's Degree in Computer Engineering, Telecommunications, or equivalent work experience.
- University Master's in Cybersecurity or equivalent work experience.
- Demonstrable experience of 10 years.
What advantages will you have by being part of our team?💙
What you'll get
- Transformative projects. At Telefónica, you will be part of high-impact projects that set trends and address the connectivity and digital transformation challenges of our society.
- Professional development. You will have a long career path and learning opportunities on a global scale, thanks to our presence in different geographies. We will share with you opportunities for development, training and mobility options. We want to grow and build a future with you!
- Flexibility. We are committed to the balance between professional and personal life. At Telefónica, we care about flexibility, positioning ourselves as a benchmark in new ways of working and work-life balance measures.
- 27 working days of vacation to enjoy.
- Benefits. You will enjoy a comprehensive package of social benefits, including:
- Life and accident insurance
- Health insurance for you and your family unit (spouse and children)
- Meal voucher card
- Flexible compensation plan with numerous options to choose from.
- Pension plan
And much more!
Additional information
At Telefónica, we are committed to building a diverse, inclusive, and sustainable work environment where every person feels valued, respected, and free. Our culture is based on equal opportunity and inclusion because we have the responsibility to transform society and make the world a better place.
If you want to be part of an innovative team and contribute to a better future, we are waiting for you!
Conectamos el presente. Transformamos el futuro.
¿Alguna vez te has preguntado qué hace posible que millones de personas estén conectadas al mismo tiempo, desde cualquier lugar del mundo, sin que nada falle?
En Telefónica, hacemos que sea posible.
Somos una compañía global de telecomunicaciones y tecnología que conecta a personas, empresas y comunidades a través de redes de última generación y soluciones digitales avanzadas como cloud, inteligencia artificial, IoT o ciberseguridad.
Con una trayectoria de más de 100 años, trabajamos cada día para que la innovación esté al servicio de la sociedad, impulsando una transformación digital responsable, sostenible y con impacto real.
Aquí no solo diseñamos infraestructuras, diseñamos el futuro. Buscamos personas que tengan inquietudes, entusiasmo y pasión por lo que hacen, que no se conformen y que quieran crear la Telefónica del mañana.
Si te apasiona la tecnología que transforma vidas, este es tu lugar.
El equipo de Ciberdefensa activa Global es el encargado de realizar la identificación, análisis y validación de vulnerabilidades en infraestructuras, aplicaciones y servicios de la superficie de ataque expuesta en Internet de todo el grupo Telefónica, apoyándose para ello en herramientas especializadas, técnicas ofensivas y el uso de tecnología IA.
¿Qué capacidades buscamos en ti? 🔎
What you'll do
- Gestión y ejecución de escaneos de vulnerabilidades:
- Configurar, lanzar y mantener escaneos periódicos con herramientas como Nessus, Acunetix y otras plataformas de scanning.
- Análisis y priorización de vulnerabilidades:
- Revisar resultados de escaneo, eliminando falsos positivos y validando hallazgos.
- Priorizar riesgos en función del impacto de negocio, criticidad y exposición (CVSS, contexto interno).
- Evaluación de seguridad en aplicaciones web:
- Utilizar herramientas como Acunetix para detectar vulnerabilidades OWASP Top 10 (SQLi, XSS, CSRF, etc.).
- Realizar revisiones manuales complementarias para validar vulnerabilidades críticas.
- Gestión del ciclo de vida de vulnerabilidades:
- Coordinar remediaciones con equipos técnicos (IT, desarrollo, cloud).
- Hacer seguimiento hasta su cierre y verificación de correcciones.
- Desarrollo de herramientas y automatización ofensiva:
- Crear y mantener tooling propio para operaciones ofensivas (scripts, payloads, infraestructura de ataque).
- Innovar en técnicas de evasión y persistencia.
- Investigación en ciberseguridad ofensiva:
- Analizar nuevas vulnerabilidades, técnicas de ataque y tendencias.
- Adaptar las capacidades del equipo a escenarios emergentes.
¿Qué otros aspectos son relevantes?📚
What we're looking for
- Capacidad de llevar a cabo un pentest en todas sus etapas (planificación, scoping, ejecución, reporte):
- Realización de auditorías técnicas de seguridad (caja negra, caja blanca y caja gris) de sistemas, redes y aplicaciones web, API,
- Test de intrusión (interno, externos y directorio activo).
- Revisiones de seguridad de aplicaciones de dispositivos móviles (Android, e iOS),
- Auditorias WiFi, revisiones de seguridad en la nube (IaaS, PaaS, SaaS, CaaS), en infraestructura de escritorios virtuales (VDI) y clientes pesadas (thick client).
- Auditorías de código estático, análisis de tráfico de red, pruebas de denegación de servicio, pruebas de ingeniería social, análisis forense, desarrollo de scripts, investigación de vulnerabilidades.
- Realización de revisiones de seguridad en ATMs, sistemas de pago y redes OT.
- Conocimientos de desarrollo:
- Python y Go lang.
- Desarrollo web (Backend Python, Frontend VueJS).
- Despliegue mediante Docker.
- Capacidad de desarrollar o modificar las herramientas necesarias.
- Desarrollo de malware o herramientas de simulación APT.
- OS internals (windows + linux).
- Conocimientos de intrusión en Windows AD.
- Ingeniería inversa.
- Nivel alto de español e inglés, que permita comunicación y colaboración efectiva en entornos multinacionales, incluyendo reuniones y workshops. Se valorarán conocimientos de portugués y alemán.
- Conocimientos en IA: Sólida comprensión de los fundamentos de inteligencia artificial y de su aplicación práctica en casos de uso de ciberseguridad.
- Capacidad de comunicación y gestión con los equipos responsables de los sistemas afectados, cooperación para la resolución de vulnerabilidades.
¿Cómo contribuirás con tus capacidades al propósito del rol? 💼
- Licenciatura, Grado en Ingeniería de Informática, Telecomunicación o experiencia laboral equivalente.
- Máster universitario en Ciberseguridad o experiencia laboral equivalente.
- Experiencia demostrable de 10 años.
¿Qué ventajas tendrás por formar parte de nuestro equipo?💙
What you'll get
- Proyectos transformadores. En Telefónica formarás parte de proyectos de alto impacto, que marcan tendencia y responden a los retos de conectividad y transformación digital de nuestra sociedad.
- Desarrollo profesional. Tendrás un largo recorrido y aprendizaje a escala global, gracias a nuestra presencia en diferentes geografías. Compartiremos contigo oportunidades de desarrollo, formación y opciones de movilidad. ¡Queremos crecer y construir un futuro contigo!
- Flexibilidad. Apostamos por el equilibrio entre la vida profesional y personal. Desde Telefónica cuidamos la flexibilidad, posicionándonos como referente en nuevas formas de trabajo y medidas de conciliación.
- 27 días laborales de vacaciones para disfrutar.
- Beneficios sociales. Podrás disfrutar de un amplio paquete de beneficios sociales entre los que destacan:
- Seguro de vida y accidentes
- Seguro médico para ti y tu unidad familiar (cónyuge e hijos)
- Tarjeta cheques comida
- Plan de retribución flexible con numerosas opciones entre las que elegir.
- Plan de pensiones
¡Y mucho más!
Additional information
En Telefónica tenemos el compromiso de construir un entorno de trabajo diverso, inclusivo y sostenible, donde cada persona se sienta valorada, respetada y libre. Nuestra cultura se basa en la igualdad de oportunidades y en la inclusión, porque tenemos la responsabilidad de transformar la sociedad y hacer un mundo mejor.
Si quieres formar parte de un equipo innovador y contribuir a un futuro mejor, ¡te estamos esperando!
More jobs like this
or browse Security·Senior·IBEX 35·Telecommunications & Connectivity·Cybersecurity·Spanish Brands·Telecom·Python·Linux·Docker·Go




