logo[мetahunt]
> Djinni

Security Engineer

format:Hybridtype:Contract
penetration testingburp suitemetasploitcloud securitykubernetesmicroservices
adobe illustratorllmci/cd
experience5+ years
locationBarcelona, Spain
> full description

We are looking for an Application Security Research Engineer . In this role, you will work with a team of researchers and ethical hackers focused on offensive security testing, automated exploit discovery, and advanced application security research. Your work will directly influence the security posture of company products and help scale secure-by-design principles. This is a hands-on technical role with a strong emphasis on offensive security, code exploitation, automation, and innovation.
 

Responsibilities:

  • Help to reshape the company's Product Security
  • Plan and execute advanced penetration testing campaigns.
  • Develop tools and frameworks for scalable security testing and fuzzing.
  • Lead Security innovation by building and managing penetration testing tools \ AI Agents
  • Analyze vulnerabilities, perform root cause analysis, and develop proofs of concept.
  • Identify systemic product weaknesses and help define long-term mitigations.
  • Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.
  • Contribute to security research publications, CVE submissions, and industry knowledge sharing.
  • Continuously evolve internal testing capabilities using modern tooling and AI-assisted approaches.

 

Requirements:

  • 5+ years of experience in Research and penetration testing.
  • Strong coding skills and deep technical understanding of web, API, cloud-native, and backend technologies.
  • AI and LLM Penetration testing knowledge and Experience
  • Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and custom security tool development.
  • Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes).
  • Familiarity with secure software architecture and typical attack vectors.
  • Demonstrated ability to lead security testing engagements and report technical findings effectively.
  • Experience building or integrating automated PT or fuzzing pipelines is a strong advantage.
  • Knowledge and hands-on experience with SSDLC tools and CI/CD pipelines,
  • Publications or open-source contributions in the security domain are a plus.

 


Full-time, long-term position. The role is remote for the first 3–4 months, after which it becomes hybrid, with 2–3 days per week in the office, under a B2B contract.
The office is located in Barcelona. We will organize the relocation, but any additional relocation-related expenses will need to be covered by you.

You must already have the legal right to work in Europe, so there are no issues with working from Barcelona. We do not provide visa sponsorship, but we can assist with information or guidance if needed.