Security Engineer
Málaga, Spain
We don't wait for the future—we build it. We are Clavium.
We’re driven by the concept of the breakthrough – those that open the door to ground-breaking technology and foster a deeper level of sovereignty while contributing to a better, more autonomous digital world.
We’re looking for a Security Engineer to help us secure the infrastructure, applications, and services that power our everyday operations. As a key member of our security team, you’ll be instrumental in shaping our security posture, ensuring that Clavium stays ahead of emerging threats, and protecting our valuable digital assets.
Reporting directly to the Head of Security and Platform Engineering, you’ll work across multiple data centres and cloud environments, implementing security best practices, and automating tasks like security scanning, patching, and configuration management. You will proactively identify and address security vulnerabilities while collaborating with cross-functional teams to embed security into their workflows.
What you’ll do
Implement & Manage Security Systems: Oversee security across Clavium’s infrastructure, applications, and data to protect against security threats.
Collaborate with Teams: Work closely with networks, applications, and engineering teams to harden technology platforms and ensure the right level of observability.
Provide Guidance: Advise product delivery teams on security architecture, design, and development, ensuring secure deployment practices across the software lifecycle.
Proactive Security Measures: Identify and recommend improvements to security systems, applications, and deployments.
Enforce Security Standards: Assist in enforcing security policies, ensuring compliance with industry standards and relevant regulations.
Incident Management: Work with internal teams and vendors to resolve security incidents quickly, and conduct post-incident root cause analysis.
Stay Ahead of Threats: Keep up to date with the latest security trends, technologies, and vulnerabilities to continuously improve the company’s security posture.
Security Training: Contribute to the development and delivery of security awareness and training programs for all employees.
What you’ll bring
Experience with DevSecOps: Familiarity with security principles and frameworks like OWASP, NIST, and the implementation of secure development lifecycle (SDLC) processes.
Threat Modelling & Risk Assessment: Experience in identifying and assessing security risks, and implementing mitigation strategies.
Secure Code Development: Knowledge of secure coding practices and how to integrate security throughout the software development lifecycle.
Incident Response: Proven experience handling security incidents, breaches, and performing forensic investigations.
Enterprise Security Tools: Experience with tools like IDS/IPS, SIEM, and content filtering to monitor and defend enterprise environments.
Network & Web Protocols: In-depth understanding of networking, the OSI model, and web protocols like TCP/IP, HTTP, and DNS.
Communication Skills: Ability to explain complex security concepts to non-technical stakeholders at all levels of the organisation.
Problem-Solving: Strong analytical skills with a methodical approach to problem-solving and decision-making in high-pressure situations.
Team-Oriented: Collaborative mindset with the ability to work independently in a fast-paced, evolving environment.
Interview Process: Our interview process consists of; a short call with our internal talent team, followed by a 1 hour technical interview and finally a 1 hour competency interview. Our talent team will be there to give guidance and support you through the process.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Cloud Compliance DevSecOps DNS IDS Incident response IPS NIST OWASP Risk assessment SDLC SIEM TCP/IP Vulnerabilities
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.