Security Operations Engineer (SOC + Offensive)
3 days ago
Barcelona
ppWe are Qalea, a fast-growing, early-stage cybersecurity startup on a mission to make digital security intuitive and accessible for every business. We've built a platform that puts simplicity, usability, and real impact at the core of cybersecurity. /p pWe've raised 1.5M€ and are backed by top-tier investors, from cybersecurity unicorn founders to leading VC firms. We're also proud to be part of the Google for Startups AI-Cybersecurity program, working alongside some of the brightest minds in product and security. /p pWe move fast, stay curious, and care deeply about what we're building. What matters to us is making an impact and building together, while enjoying the ride. /p h3The Mission /h3 pWe're looking for a Security Operations Engineer (SOC + Offensive) to join the operations team and help lead how we detect, respond to, and proactively test threats across our customers. /p pYou'll wear two hats. On one side, you'll drive our SOC and incident response practice across clients: shaping detection and response strategy, coordinating the operation, and making sure incidents are handled fast and well. On the other, you'll bring hands‑on offensive security: running penetration testing where depth matters, and thinking like an attacker to stay ahead of real threats. /p pThis is a role with real ownership and visible impact from day one. You'll work shoulder-to-shoulder with a strong team, raising the bar on a security operation that our customers rely on every day and helping it scale as we grow. /p h3What You'll Do /h3 ul liOwn the SOC and incident response layer end to end across customers: drive the detection and response strategy, coordinate the operation, and ensure incidents are triaged and handled fast and well, continuously refining playbooks and detection logic, and working with the product team to keep it automated and scalable. /li liRun penetration testing engagements, combining manual testing where depth matters with automated approaches for scale, bringing an attacker's mindset to surface real risk before others do. /li liBe the trusted technical voice for customers' security operations: clarify findings, prioritize what matters, and make sure remediation actually happens. /li liPartner closely with engineering to evolve our scanning capabilities across infrastructure, cloud, and code (external internal vulnerability scanning, CSPM/misconfigurations, SAST, DAST, SBOM), and act as the technical backbone for the operations team on these topics. /li /ul h3Must-Haves /h3 ul libStrong client-facing skills /b - you can explain complex security topics clearly, build trust with customers, and handle technical conversations with confidence. /li lib3+ years /b in security operations, incident response, or SOC environments, this is the core of the role. /li liSolid command of the bdetection and response lifecycle /b end to end: triage, investigation, containment, and coordination across stakeholders. /li liPractical bpenetration testing skills /b, both manual and automated, backed by OSCP (or a clear path to it / equivalent offensive certification). /li liWorking knowledge of bvulnerability scanning /b across infrastructure, cloud, and code. /li liComfortable partnering with engineering on security tooling and acting as a technical reference for the operations team. /li liA proactive, deeply technical, bhands‑on mindset /b. You thrive in ambiguity and bring structure where there is none. /li liComfort working across both defense and offense. You can lead a SOC/IR operation and also run a pentest. /li /ul h3Nice-to-Haves /h3 ul liExperience in early‑stage startups or fast‑paced SaaS environments. /li liHands‑on with SIEM / EDR / detection engineering and modern threat hunting. /li liExperience helping automate or scale security operations workflows. /li liComfortable using AI tools to amplify your work and move faster. You see AI as a partner, not a threat. /li /ul h3Cultural Fit /h3 ul libSolution‑Oriented: /b You bring solutions, not problems. You're proactive in overcoming blockers. /li libAccountability: /b You create clarity rather than expecting others to create it for you. You understand that responsibility is the ability to respond, and accountability is the ownership of the (quantifiable) result. /li libOwnership Mindset: /b You're autonomous, decisive, and lead with confidence. /li libCollaboration: /b You work seamlessly with Product Engineering. /li libCommunication: /b Native‑level fluency in Spanish and professional fluency in English is mandatory. /li /ul h3Our Benefits /h3 ul liImpact: Be part of our startup journey early, playing a key role in our growth and building something meaningful. /li liGrowth: Help shape the engineering culture of a Google‑backed startup from the early stages. /li liExtra days of vacation, 26 days total (23 days vacation + your Birthday + Dec 24th 31st). /li liWorking remotely in summer and Christmas to visit family or other places. /li liGympass included to support your fitness and well‑being. /li liFree fresh fruit every day to help you care for your health. /li liUnlimited specialty coffee (Syra). /li liA discount @ Nora food where you can also get daily menu deals. /li liA cool corner office in Barcelona’s Poblenou, surrounded by a thriving tech scene. We work mostly in‑person because decisions happen live and ideas evolve on the whiteboard, with flexibility on hybrid where it makes sense. /li liContinuous learning, including but not limited to mentoring, coaching, workshops, and opportunities to attend security conferences. /li liTeam gatherings and celebrations, because we love to build connections and celebrate achievements together. /li liA collaborative culture because we foster hard work, teamwork, transparency, and respect, encouraging open communication and a positive environment where your voice matters. /li /ul h3Recruitment Process /h3 ul libStage 1: Phone Screen (15 mins): /b quick check on experience, location, and expectations. /li libStage 2: Technical Deep Dive (45 mins): /b we get into your real work: SOC/IR, pentests, scanning, tooling, and why Qalea. /li libStage 3: Practical Exercise (60‑90 mins): /b a hands‑on technical challenge so we can see how you approach problems and how you think. /li libStage 4: Cultural Fit with the CEO (30 mins): /b a final conversation to make sure we’re fully aligned on both sides before making it official. /li /ul pTimeline: 2‑3 weeks from first call to offer. /p pReady to shape the future of cybersecurity? /p /p #J-18808-Ljbffr