
Corporate Security Engineer
- Hybrid
- Barcelona, Catalunya [Cataluña], Spain
- Tech
Job description
About seQura
seQura provides innovative, flexible and easy-to-use payment technologies that help merchants acquire, convert and retain more customers.
We make a difference in sales performance by tailoring our solutions to different sectors, to address their unique pain points and deliver superior results in Retail, Education, Eyewear, Repairs and Travel.
We also empower smart shopping to consumers who seek more value, convenience, and flexibility in their shopping, with new payment experiences that allow them to save, access interest-free credit, or pay in small, comfortable installments of up to 24 months.
Born in Barcelona, seQura is a privately-owned fintech, currently expanding throughout southern Europe and Latin America, growing above 50% CAGR.
Over 6000 businesses, almost 3 million shoppers, and almost 400 employees continue to rate us as one of the most loved and trusted fintechs out there, with an NPS of 87%, a Trustpilot rating of 4.7/5, and a Glassdoor rating of 4.1/5.
About the role 🤓
We are looking for a Corporate Security Engineer to own seQura’s internal corporate security layer, helping 450+ employees work securely from anywhere without adding unnecessary friction to how the business runs.
This is the first role fully dedicated to our corporate security surface. Our cloud and product security areas already have dedicated ownership. Corporate security, meaning laptops, identities, SaaS applications, employee access and the way people join, move and leave, has grown faster than the dedicated ownership behind it.
This is a greenfield mandate, you will help define the corporate security standard, build it with the tools we already use (or new ones), and make the IT team able to run it without you in the room.
We are a regulated fintech. The controls you design need to stand up to PCI DSS assessments, DORA reviews, bank partner due diligence and, from 2027, ISO 27001 audits. Evidence matters here as much as the control itself.
If you want corporate security work where identity, devices, SaaS, automation and compliance meet, this role will give you real ownership. If you are looking for a pure SOC, application security or cloud security role, this is probably not the right fit.
Job requirements
What challenges you'll be solving 🚀
Raising the security capability of the IT team rather than absorbing their security work. You will co-author playbooks, run hands-on sessions and incident walkthroughs, define what IT can handle directly versus escalate, and help grow at least one security champion inside IT.
Leading corporate incident response for events such as phishing campaigns, credential leaks and lost or stolen hardware.
Defining the endpoint and device security baseline across EDR, MDM and device security practices. You will design what “correct” looks like, engineer and tune detections, build automated response actions, and review coverage and drift against the standard.
Assessing and hardening third-party SaaS applications, improving SaaS visibility and helping bring Shadow IT under control.
Owning the security posture of Google Workspace, including OAuth application governance, contextual access, DLP rules, Drive sharing, advanced phishing protection and admin audit logging.
Automating recurring security work such as alert triage, access reviews, offboarding revocation and posture reporting.
Governing one of the newest corporate security surfaces: the AI tools, agents, OAuth connections and browser extensions employees use to connect to company data.
Evaluating, procuring, and hardening third-party SaaS applications, selecting applications to fill critical gaps.
About the team 🧩
Team mission
To protect seQura’s environment in a way that supports secure growth, regulatory readiness and low-friction collaboration across the company.
The team helps ensure that employees can work securely from anywhere, while the business continues to move quickly and make decisions based on trusted controls, reliable evidence and clear ownership.
What we own
Corporate identity and access security.
Endpoint and device security standards.
Google Workspace security posture.
Corporate SaaS security and OAuth governance.
Corporate incident response playbooks and enablement.
Security automation for recurring workflows.
Security evidence for PCI DSS, DORA, bank partner due diligence and ISO 27001 readiness.
Security enablement for IT, Cloud Platform and business operations.
Audits response.
Team Structure
You will join a security and platform group that includes:
2 Cybersecurity and Compliance Engineers.
4 Cloud Platform Engineers.
1 Team Lead.
You will work closely with Cloud Platform and IT to deliver controls, with Legal and Corporate Governance on compliance direction, and with product engineering teams on security in seQura’s products.
How we work
Low-friction security: we prefer controls people can adopt without being chased over perfect controls that people work around.
Evidence-based security: in a regulated fintech, a control needs to be designed, tested, explained and trusted.
Enablement over dependency: success is measured by how much routine security work IT can close without you, not by how much you personally close.
Automation as a foundation: We don’t want a huge security operations team, we can only support a growing company by automating what repeats.
Cross-team delivery: you will deliver through IT, Cloud Platform, Legal, Corporate Governance and business operations, not around them.
What to expect in the next 90 days 🏁
Month 1:
You will get under the hood of our SaaS footprint, Identity (IAM), endpoints, and internal networks to map our actual attack surface. Identify Quick Wins: Pinpoint immediate low-hanging fruit in access management, endpoint posture, or high-risk configuration gaps.
You will meet your allies: Platform, IT; People Ops, Engineering, Compliance… Security here is an enabler, not a bottleneck.
Month 2:
You will be involved in critical projects affecting all the company circles. You will start measuring the impact and you will define the best strategy to succeed with the project. You will roll out high-impact security baseline improvements across Zero Trust access, user management, and SaaS governance.
Month 3:
You will own the roadmap setting the long-term corporate security strategy, turning risk mitigation into a strategic advantage for the entire company.
You will enable frictionless security by launching self-service security tools that keep teams moving fast without compromising safety.
Tech stack & environment 🛠️
Our corporate security environment includes MDM, EDR, identity providers, Google Workspace, GRC tooling and automation workflows.
You will work with tools such as Hexnode, DEX, Google Workspace, Vanta, Claude and DefectDojo, while also helping define the security requirements for ZTNA and SASE as we move away from our legacy VPN model.
You do not need to have used our exact stack before. What matters more is your judgement around security priorities and impact: endpoint security, identity, SaaS governance, automation and how much friction a control is worth.
What you’ll need 🤝
Minimum 4 years of relevant experience across corporate security, identity, endpoint security, SaaS security or security engineering.
Hands-on ownership of an IDP and a SASE posture.
At least one corporate security incident handled end to end, from detection to closure.
Experience raising the security capability of a team you did not manage, through playbooks, training, security champions or handing over a control you used to run yourself.
Enough AI usage and scripting ability to automate triage and workflow tasks, using Python, Ruby on Rails, Golang or similar.
Strong understanding of endpoint security, including EDR, MDM and device security best practices.
Experience with authentication and access policies, including MFA, contextual controls, session controls, privileged access and joiner-mover-leaver flows.
Comfort delivering through other teams instead of doing everything yourself.
Working-level Spanish and English.
Nice to have
Experience with our specific stack: Hexnode for MDM, DEX and Google Workspace as identity providers, Vanta for GRC, and DefectDojo for vulnerability management.
Experience evaluating, configuring or managing a SIEM or centralised log management.
Exposure to PCI DSS, DORA or ISO 27001 in a regulated environment.
Provider management experience.
Experience building phishing simulation or security awareness programmes.
Experience using AI assistants or automation platforms to increase your own throughput, such as n8n, Claude Code, Codex or similar.
What we offer 😎
We have a strong and sustainable foundation, where we provide a secure and reliable workplace. You have the freedom and trust to make the best contribution possible.
One of our most valued strengths by our employees is our fellowship and supportive culture, which fosters a sense of belonging by working closely with our values. With us, you will have challenging projects to work on and push your skills and knowledge.
In addition, we are very proud of the unique office we have, which offers a comfortable and inspiring environment to work in with everything you need.
23 vacation days + 2 days of free disposal per year.
Flexible compensation plan for transportation, restaurants, and kindergarten with Cobee.
Health insurance discounts with Sanitas and DKV.
Flexible working hours.
A personal budget for professional development.
Office workshops and meet-ups to encourage community participation and career growth.
Hybrid work from Barcelona HQ, with around 10-20% of your time on-site.
Which are the next steps? 🙌
The hiring process will be confirmed before publishing, but we expect it to include:
Interview with People Team.
Hiring Manager interview with the Head of Engineering.
Technical discussion based on a real corporate incident and baseline design.
Panel with IT and Cloud Platform, the two teams you will work with every week.
Offer.
Our target is three weeks from first call to offer.
We kindly ask that you submit your CV in English, as it is the official language of our community.
We promote equal opportunity to all, regardless of age, color, gender identity, medical condition, physical or mental disability, race, religion, sexual orientation, or any other characteristic. We have an inclusive environment, and respect is above all.
A note on applying:
If you match most of the requirements but not all of them, we still encourage you to apply.
The specific tools are learnable in weeks. The judgement about which control is worth the friction, and the ability to make another team better at security, are harder to teach. Those are the things we are really hiring for.
Do you want to be part of the change? Join us!👇
or
All done!
Your application has been successfully submitted!
You've already applied for this job
We appreciate your interest in this position. Unfortunately, you have already applied for this job.

