Offensive Security Engineer

Hace 7 días

Barcelona, Cataluña, España Factorial HR Jornada completa

Application Security Engineer

Hey there, Cybersecurity Enthusiasts At Factorial, we’re on the hunt for a skilled Application Security Engineer to join our Security Team. We need your expertise to proactively hunt for vulnerabilities and strengthen our defenses against cyber threats. If you have a passion for ethical hacking and want to make an impact in a dynamic tech environment, we’d love to hear from you

Ready to be part of the challenge?

About the team

Security at Factorial works side by side with Product and Engineering to help a fast-moving, AI-native company ship without losing control of risk. Our mission is to protect Factorial and our customers while making security a practical part of how software is designed, built, tested, and operated.

The work goes far beyond finding vulnerabilities: we test real product surfaces, help teams fix issues properly, and turn repeated security needs into guardrails, automation, and CI/CD controls that developers can use every day. AI is part of Factorial’s culture, product, and way of working from day one, so Security also helps define how teams use agents, LLMs, tools, and company data safely at scale, while actively challenging those systems with an attacker mindset.

It’s a team for people who want to keep learning, move across different security problems, and build security that can keep up with the speed of the company.

What You’ll be doing?

  • Perform proactive penetration testing across Factorial’s applications, APIs, infrastructure, and AI-powered features.
  • Reproduce and validate vulnerability reports submitted by third parties, like our bug bounty program.
  • Collaborate with development teams to remediate security findings and enhance secure coding practices.
  • Improve how we validate, triage, and remediate vulnerabilities from bug bounty reports, internal testing, automated controls, and external research.
  • Hunt for recurring or legacy vulnerability patterns based on root cause analysis, previous incidents, and security findings.
  • Build and improve security automations, agents, skills, and CI/CD controls that help engineering teams catch and fix issues earlier.
  • Help secure Factorial’s use of AI across product and internal workflows, including LLMs, agents, data access, tools, permissions, and abuse scenarios.
  • Contribute to the development of our security tools, automations, and infrastructure.
  • Stay up-to-date with the latest security research, threats, attack techniques, and emerging AI security risks.

What are we looking for?

  • You have 3+ years of professional experience in Application Security, Offensive Security, or Penetration Testing. Web Application Penetration Testing experience is mandatory.
  • You hold a degree in Engineering or Computer Science and have strong knowledge of web applications, databases, network protocols, and operating systems.
  • You possess strong knowledge in cybersecurity fundamentals, CVSS, testing methodologies, and tooling.
  • You are fluent with scripting or programming languages used in security testing and automation, such as Python or Bash.
  • You are technical, curious, and comfortable moving across different security problems instead of specializing in one area.
  • You like to attack systems, but you also enjoy building tools, automations, guardrails, and practical solutions that make security scale.
  • You do not need to be an expert in every technology, but you should be able to reason critically, learn fast, use AI effectively, and design pragmatic solutions.
  • You have curiosity and willingness to learn about AI security topics such as LLM testing, prompt injection, agentic workflows, data exposure, tool permissions, RAG security, and secure AI adoption.
  • Certifications like BSCP or eWPTX are highly regarded but not mandatory.
  • Experience with Ruby / Ruby on Rails applications is highly regarded, but not mandatory.
  • Fluency in English is required.

Compensation

At Factorial we don't evaluate you by years of experience but by your knowledge and skills. We use our Career Path with a rubric framework where we define what is expected for each experience level and skill. This framework allows you to know your current level and what you need to keep growing. We love transparency, so our Career Path includes the salaries for each level, which we share during the first interview to ensure alignment. The salary range for this position is between 40.000 - 55.000€ base + 7-10% variable based on performance paid quarterly + ESOP plan.

How We Work

At Factorial, we believe the best products are built when people come together—in person—to collaborate, challenge ideas, and move fast. That’s why our Engineering Team follows an office-first, flexible approach.

We work on-site several days a