Senior Cybersecurity Engineer

DevoteamBarcelonaJob.bopublished 09/24/2026
Must-have:AzureCloudAISecuritySenior
Machine translation — original language: Spanish.Show original

Devoteam is a leading European consultancy focused on digital strategy, technological platforms, cybersecurity, and business transformation through technology. Technology is in our DNA and we believe in it as a lever capable of driving change for the better, maintaining a balance that allows us to offer our client portfolio top-tier technological tools, but always with the closeness and professionalism of a team that acts as a guide along the way. Devoteam has been committed to technology at the service of people for more than 30 years. With more than 10,000 people in the group, in 20 countries across Europe, the Middle East, and Africa.

We are looking to permanently join our CYBER project unit as a Senior Cybersecurity Engineer capable of designing, implementing, operating, and proposing improvements in the domains of cloud, identity, endpoints, networks, monitoring, and security in Artificial Intelligence. You will work for one of our direct clients, a multinational in the transport sector. Availability for a hybrid modality is required (2 days remote work, 3 days office in the Viladecans area).

REQUISITOS:

Professional Experience: Demonstrated experience in cybersecurity engineering, security architecture, or advanced security operations.

Key Technologies: Solid practical experience in Microsoft Defender XDR, Entra ID, Purview, CrowdStrike Falcon, Microsoft Azure, and Akamai (WAF/CDN).

Desirable Knowledge: Zero Trust architecture, SaaS/SSPM governance, detection engineering, resilience against cyberattacks/ransomware, and regulatory frameworks (NIS2, ISO 27001, NIST CSF, or aviation sector regulations).

Competencies: Risk-based thinking, ability to execute the transition from architecture to technical operation, communication skills, and preparation of detailed documentation.

FUNCIONES:

  1. Security Engineering and Architecture
  • Cloud and Zero Trust Architectures: Design and support cloud security architectures and Zero Trust models (Microsoft Azure, Microsoft 365, and SaaS).
  • Identity Management: Support identity architecture through Microsoft Entra ID (SSO, MFA, Conditional Access, PIM, and lifecycle management).
  • Security by Design: Integrate 'Secure by Design' principles into technological initiatives, application architectures, and digital capabilities.
  • Microsoft and Endpoint Platforms: Configure capabilities in Defender, Entra, Purview; deploy and optimize CrowdStrike Falcon for endpoints and workloads.
  • Edge Security and Resilience: Support Akamai tools (WAF, bot mitigation, CDN) and design backup plans, ransomware recovery, and cloud resilience.
  1. Security Platform Operation
  • Microsoft Stack Management: Operate Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office, Defender for Cloud, and Defender for Cloud Apps.
  • Data Protection and Governance: Administer DLP configurations, Information Protection, Insider Risk, Communication Compliance, and SaaS governance (SCIM, OAuth permissions, SSPM).
  • Technical Hygiene: Perform continuous configuration reviews, status assessments, and technical audits on deployed platforms.
  1. Detection Engineering and Monitoring
  • Telemetry Integration: Connect new log sources and native connectors to the SIEM and monitoring ecosystem.
  • Use Cases with the SOC: Collaborate with the SOC to optimize alerts, reduce false positives, refine use cases, and provide support in advanced incident investigation.
  1. Security Advisory
  • Internal Consulting: Advise technology, digital, data, and business teams on security-by-design reviews and technical architectures.
  • Vendor Management: Participate in discussions with third parties regarding control design and secure architecture integration.
  1. Continuous Improvement and AI Security
  • Posture Assessment (Secure Score): Perform audits based on Microsoft and Azure Secure Score to identify and execute rapid remediations.
  • AI Governance: Evaluate the security of Artificial Intelligence use cases (Microsoft Copilot, use of Shadow AI tools, and DSPM for AI).

English B2