368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$36k – $93k per year (Estimated)
Location
Remote/Hybrid (Barcelona, Spain)
Seniority
Middle · 3+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Contentsquare is a global digital experience analytics platform that helps businesses understand how users interact with their websites and mobile applications. By automatically capturing behavioral data, user intent, and technical performance, it provides AI-driven insights such as heatmaps, customer journey tracking, and session replays. Ultimately, the platform enables marketing, product, and e-commerce teams to optimize user engagement, eliminate UX friction, and drive conversion rates.

The Contentsquare Security team is looking for an application security engineer (Appsec) who can work closely with the development team, product managers and diverse third-party groups (including bug bounty hunters).

Contentsquare provides a globally leading SaaS service and commits to the highest security standards for its customers. We are ISO 27001 and ISO 27701 certified and maintain robust security initiatives (SOC 2 Type 2 report, private bug bounty program, SIEM, advanced security awareness, etc.). Working alongside other cybersecurity experts, your mission will be to ensure the security of Contentsquare’s products and for keeping Contentsquare’s users and customers safe. You will work out of our Barcelona office.

What you'll do

  • Conduct continuous, automated security audits of our global SaaS applications to identify misconfigurations and ensure strict adherence to industry-standard security benchmarks and internal best practices.

  • Serve as a strategic security consultant to product and engineering teams, facilitating complex threat modeling sessions and AppSec reviews during the design phase to proactively mitigate risks.

  • Perform deep-dive, security-focused code reviews and mentor developers on secure coding patterns to minimize the introduction of high-impact vulnerabilities.

  • Architect and manage the end-to-end vulnerability lifecycle, developing sophisticated automation for the triage, reporting, and remediation tracking of security flaws across cloud infrastructure and application layers.

  • Orchestrate and optimize AI-driven security workflows, leveraging LLMs and autonomous agents to conduct scaleable, proactive vulnerability discovery and validation within our CI/CD pipelines.

  • Lead "Shift-Left" initiatives by integrating security checkpoints into the automation stack, developing custom security-as-code tools that empower developers to own security outcomes.

  • Oversee the strategic direction of our private and public bug-bounty programs, ensuring high-quality engagement with the researcher community and rapid internal response to critical findings.

  • Coordinate specialized external penetration testing engagements and customer-driven security assessments, acting as the primary technical point of contact for complex security inquiries.

  • Drive the technical response to application-level security incidents, conducting root-cause analysis to prevent recurrence and enhance our defensive posture.

What you'll need

  • 3+ years of professional experience in Application Security Operations within a high-growth SaaS or cloud-native environment.

  • Advanced proficiency in securing modern technical stacks, with specific expertise in NestJS, Vue.js, and Angular frameworks.

  • Hands-on experience with enterprise security tooling, including Snyk, Datadog ASM/AppSec (WAF), Google SecOps, and Crowdstrike.

  • Deep architectural understanding of AWS and Azure environments, including Kubernetes/Docker container security and Infrastructure as Code (Terraform).

  • Demonstrated ability to apply AI and LLM technologies to automate security tasks, such as automated vulnerability validation or code analysis at scale.

  • Expertise in scripting and development (Python, Node.js, Shell) to build custom security tooling and integrations.

  • Comprehensive knowledge of web protocols, OWASP Top 10, and advanced threat frameworks (MITRE ATT&CK, NIST CSF).

  • Proven track record in ethical hacking, CTF competitions, or bug bounty hunting, showcasing a high level of technical tenacity and analytical rigor.

  • Exceptional cross-functional collaboration skills, with the ability to articulate complex security risks to both technical and non-technical stakeholders.

  • Fluency in English is mandatory

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Barcelona
$29k – $70k per year (Estimated) • Remote/Hybrid • Full-Time • 11+ years exp • Bachelor's Degree • Hyderabad
Python
SQL
Databases
Databricks
Snowflake
DevOps
AWS
Azure
CI/CD
Apply
$21k – $55k per year (Estimated) • In office • Full-Time • 3+ years exp • Navi Mumbai
C#
Java
C#
.NET
Java
Spring Boot
Databases
PostgreSQL
Redis
AI/ML
Copilot
DevOps
AWS
Azure
CI/CD
Amazon S3
GitHub
Apply
$54k – $85k per year (Estimated) • In office • Full-Time • 5+ years exp • Gdańsk
Python
SQL
Python
Django
FastAPI
Flask
DevOps
Azure
Bitbucket
CI/CD
GitHub
GitLab
Apply
$34k – $75k per year (Estimated) • Remote/Hybrid • Full-Time • 13+ years exp • Bachelor's Degree • Hyderabad
Java
Node JS
TypeScript
JavaScript
Databases
Cassandra
DynamoDB
Memcached
MySQL
PostgreSQL
Redis
Frontend
GraphQL
DevOps
AWS
CI/CD
Apply
$71k – $154k per year (Estimated) • In office • Full-Time • Dublin
Java
Databases
Apache Kafka
AI/ML
Copilot
LLM
LLM Guardrails
DevOps
AWS
CI/CD
Kubernetes
GitHub
Apply
$52k – $113k per year (Estimated) • Remote • Barcelona
SQL
Marketing
Salesforce
Apply
$81k – $156k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp
Apply
$70k – $132k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Paris
Apply
$57k – $118k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Barcelona
Apply
$111k – $175k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • London
Apply
$63k – $137k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Madrid • Barcelona
AI/ML
AI Agents
Apply
Business Analyst 7 hours ago
$43k – $99k per year (Estimated) • Remote/Hybrid • Full-Time • 7+ years exp • Barcelona
Apply
$31k – $88k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Barcelona
Python
SQL
AI/ML
Model Context Protocol
DevOps
GCP
Git
GitHub
Management
n8n
Apply
$38k – $87k per year (Estimated) • Equity • Remote/Hybrid • Internship • 3+ years exp • Bachelor's Degree • Barcelona
Python
SQL
Apply
$37k – $91k per year (Estimated) • In office • Full-Time • 3+ years exp • Barcelona
JavaScript
Kotlin
TypeScript
Mobile
Bitrise
Crashlytics
Espresso
DevOps
CI/CD
Drone
GCP
GitHub Actions
Grafana
GitHub
QA
Appium
Cucumber
Playwright
Rest-Assured
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.