Todas las ofertas

Corporate Security Engineer

SeQura
Barcelona, CataluñaPublicada el 27 de agosto de 2026
TransparenciaBaja — lugar, empresa claros; no dice sueldo ni contrato ni jornada ni modalidad.
ActividadBaja — publicada hace 22 días, en la web de la empresa.
ConfianzaSin señales de riesgo — está en la web de la propia empresa.
Cómo apuntarse
  1. Se solicita en la web de la empresa, sin intermediarios.
Ver la oferta y apuntarse

About seQura
seQura provides innovative, flexible and easy-to-use payment technologies that help merchants acquire, convert and retain more customers.
We make a difference in sales performance by tailoring our solutions to different sectors, to address their unique pain points and deliver superior results in Retail, Education, Eyewear, Repairs and Travel.
We also empower smart shopping to consumers who seek more value, convenience, and flexibility in their shopping, with new payment experiences that allow them to save, access interest-free credit, or pay in small, comfortable installments of up to 24 months.
Born in Barcelona, seQura is a privately-owned fintech, currently expanding throughout southern Europe and Latin America, growing above 50% CAGR.
Over 6000 businesses, almost 3 million shoppers, and almost 400 employees continue to rate us as one of the most loved and trusted fintechs out there, with an NPS of 87%, a Trustpilot rating of 4.7/5, and a Glassdoor rating of 4.1/5.

About the role 🤓
We are looking for a Corporate Security Engineer to own seQura’s internal corporate security layer, helping our teams work securely from anywhere without adding unnecessary friction to how the business runs.
This is the first role fully dedicated to our corporate security surface. Our cloud and product security areas already have dedicated ownership. Corporate security, meaning laptops, identities, SaaS applications, employee access and the way people join, move and leave, has grown faster than the dedicated ownership behind it.
This is a greenfield mandate, you will help define the corporate security standard, build it with the tools we already use (or new ones), and make the IT team able to run it without you in the room.

We are a regulated fintech. The controls you design need to stand up to PCI DSS assessments, DORA reviews, bank partner due diligence and, from 2027, ISO 27001 audits. And there is more to come, including frameworks like NIS2 as we continue expanding. Evidence matters here as much as the control itself.

If you want corporate security work where identity, devices, SaaS, automation and compliance meet, this role will give you real ownership. If you are looking for a pure SOC, application security or cloud security role, this is probably not the right fit.

Requisitos:
What challenges you'll be solving 🚀
· Raising the security capability of the IT team rather than absorbing their security work. You will co-author playbooks, run hands-on sessions and incident walkthroughs, define what IT can handle directly versus escalate, and help grow at least one security champion inside IT.

· Leading corporate incident response for events such as phishing campaigns, credential leaks and lost or stolen hardware.

· Defining the endpoint and device security baseline across EDR, MDM and device security practices. You will design what “correct” looks like, engineer and tune detections, build automated response actions, and review coverage and drift against the standard.

· Assessing and hardening third-party SaaS applications, improving SaaS visibility and helping bring Shadow IT under control.

· Owning the security posture of Google Workspace, including OAuth application governance, contextual access, DLP rules, Drive sharing, advanced phishing protection and admin audit logging.

· Automating recurring security work such as alert triage, access reviews, offboarding revocation and posture reporting.

· Governing one of the newest corporate security surfaces: the AI tools, agents, OAuth connections and browser extensions employees use to connect to company data.

· Evaluating, procuring, and hardening third-party SaaS applications, selecting applications to fill critical gaps.

About the team 🧩
Team mission
To protect seQura’s environment in a way that supports secure growth, regulatory readiness and low-friction collaboration across the company.
The team helps ensure that employees can work securely from anywhere, while the business continues to move quickly and make decisions based on trusted controls, reliable evidence and clear ownership.

What we own
· Corporate identity and access security.

· Endpoint and device security standards.

· Google Workspace security posture.

· Corporate SaaS security and OAuth governance.

· Corporate incident response playbooks and enablement.

· Security automation for recurring workflows.

· Security evidence for PCI DSS, DORA, bank partner due diligence and ISO 27001 readiness.

· Security enablement for IT, Cloud Platform and business operations.

· Audits response.

Team Structure
You will join a security and platform group that includes:
· 2 Cybersecurity and Compliance Engineers.

· 4 Cloud Platform Engineers.

· 1 Team Lead.

You will work closely with Cloud Platform and IT to deliver controls, with Legal and Corporate Governance on compliance direction, and with product engineering teams on security in seQura’s products.

How we work
· Low-friction security: we prefer controls people can adopt without being chased over perfect controls that people work around.

· Being able to make your work visible for the rest of the company.

· Evidence-based security: in a regulated fintech, a control needs to be designed, tested, explained and trusted.

· Enablement over dependency: success is measured by how much routine security work IT can close without you, not by how much you personally close.

· Automation as a foundation: We don’t want a huge security operations team, we can only support a growing company by automating what repeats.

· Cross-team delivery: you will deliver through IT, Cloud Platform, Legal, Corporate Governance and business operations, not around them.

What to expect in the next 90 days 🏁
Month 1:
You will get under the hood of our SaaS footprint, Identity (IAM), endpoints, and internal networks to map our actual attack surface. Identify Quick Wins: Pinpoint immediate low-hanging fruit in access management, endpoint posture, or

¿Encajas en esta oferta? Te lo decimos con tu CV.

Visual Job mide tu compatibilidad real con cada oferta, te avisa de las que huelen mal, prepara la candidatura y sigue quién te contesta. Gratis para empezar.

Empezar gratis