Unlock the power of spatial analysis
Core Software Engineer – Security & Platform
Location
Spain
Posted
2 days ago
Salary
0
Seniority
Senior
Job Description
Core Software Engineer – Security & Platform
CARTO
• Improve the security of the platform through code. Work directly in the CARTO codebase to identify, prioritize, and fix security weaknesses. This may involve refactoring existing components, redesigning risky flows, improving authorization boundaries, strengthening input validation, removing unsafe patterns, or building new platform capabilities that make secure development easier for everyone. • Strengthen our cloud and infrastructure foundations. Work with our infrastructure and platform teams to harden CARTO’s cloud-native environments across GCP and AWS. You will contribute to areas such as IAM, Kubernetes, containerized workloads, networking, workload isolation, Infrastructure as Code, and secure-by-default deployment patterns. • Make security part of the development workflow. Build and improve tools, checks, libraries, CI/CD integrations, and engineering practices that help developers catch security issues early. The goal is not to create gates that slow teams down, but to make the secure path the easiest path. • Improve supply-chain security. Help protect CARTO from modern supply-chain attacks by improving dependency management, build integrity, container security, artifact provenance, CI/CD security, and automated scanning. Stay up to date with emerging attack techniques and translate that knowledge into practical protections. • Use AI to improve security. Experiment with the latest AI models and tools to assess and improve CARTO’s security posture. This could include AI-assisted code review, automated vulnerability discovery, codebase analysis, threat modeling, dependency analysis, or internal agents that continuously look for risky patterns and misconfigurations. • Secure AI and agentic systems. CARTO is building an Agentic GIS platform, which creates new security challenges. You will help us reason about and defend against risks such as prompt injection, tool misuse, data leakage, privilege escalation through agents, untrusted content flowing into automated workflows, and unsafe model/tool interactions. • Raise the security bar across engineering. Partner with engineering teams to review designs, identify risks, and implement improvements. Help make every team more security-aware while remaining pragmatic, collaborative, and focused on enabling product velocity.
Job Requirements
- 5+ years of experience as a software engineer, platform engineer, infrastructure engineer, or security-focused engineer.
- Strong hands-on programming skills in at least one of TypeScript, Python, or Go, and the ability to work across a large production codebase.
- Experience designing, refactoring, and operating complex cloud-native software systems.
- Strong understanding of application security, including authentication, authorization, input validation, secure API design, multi-tenant systems, and secure SDLC practices.
- Practical experience with cloud infrastructure on GCP or AWS, including IAM, secrets management, networking, containers, and Kubernetes.
- Experience with Infrastructure as Code, preferably Terraform or similar tools.
- Familiarity with software supply-chain security: dependency risks, CI/CD hardening, container scanning, build integrity, artifact provenance, and secure release processes
- Previous experience in using AI tools to analyze code, detect vulnerabilities, automate reviews, or improve engineering workflows.
- A collaborative, low-ego approach. You make security something engineers want to adopt, not something they try to work around.
- Nice to have
- Experience in application security, product security, penetration testing, or red-team exercises.
- Experience securing AI or agentic systems, including prompt-injection defense, tool sandboxing, model access controls, or AI data-exfiltration risks.
- Experience building internal developer platforms, secure libraries, CI/CD tooling, or engineering automation.
- Experience with SOC 2, ISO 27001, or similar compliance frameworks, especially if you have helped translate compliance needs into automated engineering controls.
- Contributions to open-source security tooling, security research, responsible disclosure, or technical writing on security topics.
- Experience with geospatial, data platforms, cloud data warehouses, or enterprise SaaS platforms.
Benefits
- Compensation based on experience, discussed transparently during the process, plus an annual bonus of up to 10% based on company objectives.
- The opportunity to contribute to a platform used by top companies around the world.
- A direct impact on the security, reliability, and future architecture of CARTO.
- Access to our Employee Stock Options Plan.
- Private medical insurance.
- Flexible compensation.
- Education stipend.
- Remote work stipend.
- English classes.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Design and implement security solutions to protect systems, networks, and data from cyber threats across our cloud and application ecosystem. • Embed Security into Workflows (DevSecOps): Work directly with engineering teams to integrate automated security scanning (SAST, DAST, SCA) and validation into CI/CD pipelines. • Cloud Infrastructure Security: Implement security controls as code (Infrastructure as Code) to ensure our AWS environment is secure by default, including container hardening and network security groups. • Network & Web Security: Manage and optimize our Cloudflare implementation, including WAF, Zero Trust, and CDN tooling to protect our web applications. • Vulnerability Management & Incident Response: Monitor security systems, act as the primary responder for security incidents, and conduct regular security assessments, threat modeling, and code reviews. • Champion Security Culture: Act as a security consultant and mentor to software engineers, promoting secure coding practices and fostering a culture of technical excellence. • Manage External Testing: Coordinate and assist in running penetration testing, bug bounty programs, and red teaming exercises.
Role Description ADP is hiring an Enterprise Account Executive, based in Germany, to specialise in our Workforce Software Suite. This role involves: - Driving enterprise growth by selling a leading workforce management application within the ADP Workforce Suite. - Owning a regional enterprise quota and leading complex, multi-stakeholder sales cycles with Fortune 1000 and upper mid-market accounts. - Partnering with solutions consultants, product, marketing, and customer success to land new logos and expand strategic accounts. - Achieving consistent over-quota performance, high win rates against top competitors, and repeatable, executive-trusted sales motion. Key Responsibilities - Pipeline generation and territory planning: - Build and execute a territory plan targeting enterprise HR, Operations, and Finance buyers. - Prospect into C‑level and VP stakeholders (CHRO, COO, CFO, VP Operations, HRIS) using multi-threaded outreach and partner channels. - Consultative, value-led selling: - Lead discovery to quantify business pain around labor cost control, forecasting, scheduling, time capture accuracy, union/CBAs, compliance, and workforce insights. - Map ADP Workforce Management capabilities to measurable business outcomes. - Deal orchestration: - Run complex sales cycles (6–12 months typical) from qualification through negotiation and signature. - Coordinate solution demos, pilots/POCs, and value assessments with Solutions Consulting. - Executive influence and governance: - Develop executive sponsors; lead QBRs and steering meetings. - Navigate procurement, InfoSec, legal, and data privacy to close enterprise agreements. - Forecasting and reporting: - Maintain accurate CRM hygiene, stage definitions, and forecast cadence. - Track KPIs: coverage, conversion, cycle length, ASP, and win/loss insights. - Partner and ecosystem: - Leverage alliances and referral partners; coordinate with implementation and customer success for seamless handoff. - Market intelligence: - Monitor competitor landscape, vertical requirements, and regulatory trends impacting labor compliance. Qualifications - 7+ years of enterprise SaaS new-business sales experience; 3+ years selling into HR, Operations, or Workforce Management domains. - Proven track record of meeting/exceeding $1M+ annual new ARR quotas with complex, multi-threaded sales. - Experience selling to CHRO, COO, CFO, and Operations leaders; comfortable leading executive-level conversations and board-ready business cases. - Familiarity with workforce management concepts: demand forecasting, advanced scheduling, union rules/CBAs, premiums/differentials, leave/absence, labor compliance, mobile workforce, and analytics. - Strong understanding of enterprise integrations and security: SSO/SAML, data privacy, HRIS/payroll connectors, APIs, and implementation considerations. - Excellent negotiation, objection handling, and closing skills; disciplined CRM usage (Salesforce or similar). - Fluent in German and English. Preferred Qualifications - Vertical experience in complex labor environments (retail, hospitality, manufacturing, healthcare, logistics, public sector). - History of displacing incumbent WFM providers or expanding within large installed bases. - Financial acumen to build ROI/TCO and quantify productivity, compliance risk reduction, and labor cost savings. Key Competencies - Executive presence and storytelling. - Strategic account planning and multi-threading. - Discovery and problem mapping. - Deal strategy and competitive positioning. - Commercial negotiation and procurement management. - Cross-functional leadership and collaboration. - Data-driven forecasting and pipeline discipline. Success Metrics - Quota attainment (new ARR) and average selling price. - Win rate vs. named competitors and reduction in cycle time. - Multi-thread depth (stakeholder coverage) and expansion within landed accounts. - Forecast accuracy and stage conversion. - Customer outcomes tied to ROI/business case delivered. Location and Travel Remote within the region; travel to client sites, events, and internal meetings as needed. This role is ideal for a high-achieving enterprise seller who thrives on solving complex labor challenges and can translate ADP Workforce Management capabilities into clear executive business outcomes.
Senior Cybersecurity & Network Security Engineer
IntervAIAutomating early-stage recruitment with intelligent, bias-free AI interviews.
Role Description We are looking for experienced Senior Cybersecurity & Network Security Engineers who can help secure critical digital platforms, payment systems, enterprise infrastructure, and high-traffic customer-facing services. - Security Management: Manage and improve network security, server security, endpoint security, and data protection processes. - Technology Operations: Operate and enhance security technologies such as Firewall, IDS/IPS, WAF, DDoS protection, Web Proxy, EDR/XDR, Email Security, Sandbox, SIEM, DLP, and PAM. - Incident Response: Monitor security events, investigate incidents, coordinate remediation actions, and contribute to root cause analysis. - Risk & Vulnerability: Perform risk assessments, business impact analysis, vulnerability follow-ups, and security control reviews. - Compliance & Governance: Ensure compliance with relevant security standards and regulations such as KVKK, PCI DSS, ISO 27001, ITIL, COBIT, Law No. 5651, Law No. 6493, and payment systems information security requirements. - Infrastructure Security: Take ownership of security policy implementation, configuration hardening, access control, logging, monitoring, and audit readiness across cloud, on-premise, and hybrid environments. - Audits & Testing: Support penetration testing, vulnerability management, audit, and third-party security review processes. - Continuous Improvement: Follow emerging cybersecurity threats, translate them into practical security improvements, and prepare documentation/reports for stakeholders. Qualifications - Education: Bachelor’s degree in Computer Engineering, Electrical/Electronics Engineering, Telecommunications Engineering, Information Systems, or related fields. - Experience: Minimum 5 years of experience in Network Security, Information Security, Cybersecurity Operations, IT Risk, or IT Audit. - Core Tech Stack: Hands-on experience with Firewall, IDS/IPS, WAF, DDoS, VPN, Web Proxy, NAC, EDR/XDR, SIEM, DLP, or PAM technologies. - Networking Fundamentals: Strong knowledge of LAN/WAN, Routing & Switching, TCP/IP, IPSec/SSL VPN, VLAN, MPLS, NAT, BGP, and network segmentation. - Frameworks & Industry: Good understanding of regulatory frameworks (KVKK, PCI DSS, ISO 27001, ITIL, COBIT). Experience in financial services, fintech, payment systems, banking, retail technology, or high-transaction digital platforms is a strong plus. - Language: Good command of English. - Soft Skills: Strong analytical thinking, ownership, communication, and cross-functional collaboration skills. - Certifications (Preferred): Holding certifications such as CCNP, CCSA, PCNSA, CEH, CISSP, CISM, CISA, ISO 27001 LA, or equivalent. - Nice to Have: Experience with Forcepoint Web/Email Security or similar enterprise security products. - Knowledge of cloud security on Azure, AWS, or GCP. - Familiarity with MITRE ATT&CK, Cyber Kill Chain, NIST, or similar cybersecurity frameworks. - Experience with automation or scripting using Python, Bash, or PowerShell. - Experience in audit-heavy environments such as banking, insurance, fintech, telecom, or large-scale retail. How to Apply If you are an experienced security professional looking to protect high-impact digital systems—click here to submit your application. We’d love to hear from you!
Title: SAP Security Engineer (GRC – Technical) Job Description: Bright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions that help businesses automate and optimize their operations. We leverage cutting-edge technologies to create scalable, secure, and user-friendly applications. As we continue to grow, we’re looking for a skilled SAP Security Engineer (GRC – Technical) to join our dynamic team and contribute to our mission of transforming business processes through technology. This is a fantastic opportunity to join an established and well-respected organization offering tremendous career growth potential. Location: 100% Remote (Continental United States) Position Type: In-house Bright Vision Technologies SOW engagement (no third-party client or vendor) Experience: 5+ years Salary: 100k - 150k Sponsorship: No new H1B sponsorship available. H1B transfers welcomed for qualified candidates. Employment Type: Full-time, direct W2 with Bright Vision Technologies (no C2C, no 1099, no third-party) Engagement: Long-term, multi-year, aligned to the Bright Vision SOW delivery roadmap Compensation: Competitive base salary commensurate with experience, plus benefits. Employment Terms & Visa Policy This is a 100% remote, full-time, direct W2 position with Bright Vision Technologies. This role is part of Bright Vision Technologies’ in-house Statement of Work (SOW) engagement. The client, end customer, and employer for this position is Bright Vision Technologies — there is no third-party client, vendor, or implementation partner involved. We do not engage in C2C, 1099, or third-party arrangements for this role. BUT STRICTLY NO C2C/1099/3RD PARTY COMPANIES. ALL OUR ROLES ARE W2 AND NO 3RD PARTY BROKERING PLEASE. Candidates must be willing to work directly as a full-time W2 employee of Bright Vision Technologies and contribute to our in-house SOW deliverables. No new H1B sponsorship is available for this role. However, candidates who are currently on a valid H1B visa and require a transfer are welcome to apply. We will support H1B transfers for qualified candidates. For every role, a technical coding assessment is mandatory. Please apply only if you are confident in your technical abilities and hands-on experience. Job Summary We are seeking an experienced SAP Security and GRC (Governance, Risk, and Compliance) Engineer to design, implement, and operate security and access-control frameworks for complex SAP landscapes, including S/4HANA, ECC, BW/4HANA, Fiori, BTP, and SuccessFactors. In this role you will be responsible for SAP role design, user provisioning, segregation-of-duties analysis, audit support, and the technical operation of SAP GRC suites. The ideal candidate will combine deep expertise in SAP authorization concepts with strong hands-on experience operating SAP GRC Access Control and Process Control, and will partner closely with audit, compliance, and business teams to deliver a secure, auditable SAP environment. Key Responsibilities - Design and maintain SAP authorization concepts and role structures aligned with business processes and least-privilege principles. - Build and maintain master, derived, composite, and business roles for S/4HANA, ECC, and Fiori applications. - Configure and operate SAP GRC Access Control (ARA, ARM, BRM, EAM), including ruleset management, mitigating controls, and emergency access management. - Perform segregation-of-duties analysis and remediation in collaboration with business process owners and internal audit. - Configure user provisioning workflows in SAP GRC ARM, including request types, approval paths, and integration with IDM/IAM platforms. - Operate SAP GRC Process Control for continuous controls monitoring and policy management. - Implement security for Fiori applications, including catalogs, groups, and front-end authorizations. - Configure and operate security for SAP BTP and cloud applications using XSUAA, IAS, and IPS. - Support SAP audits (SOX, GxP, PCI) and respond to audit findings with documented remediation plans. - Implement transport security, table logging, and audit logging in line with internal security policies. - Monitor and remediate SAP Security Notes in coordination with Basis and DBA teams. - Maintain comprehensive, current technical documentation — including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures — so that the system remains supportable, auditable, and easy to onboard new engineers onto over time. - Mentor junior team members and support knowledge transfer across the security team. Required Qualifications - Bachelor’s degree in Computer Science, Engineering, or a related technical discipline. - Five or more years of SAP Security / GRC experience in enterprise landscapes. - Strong hands-on experience with SAP authorization concepts and role design. - Deep experience operating SAP GRC Access Control (ARA, ARM, BRM, EAM). - Experience supporting SAP audits and remediation activities. - Hands-on experience securing Fiori, BTP, and cloud SAP applications. - Familiarity with SAP IDM or third-party IGA tooling. - Working knowledge of SAP Process Control. - Strong understanding of regulatory frameworks such as SOX, GxP, and PCI. - Excellent communication and documentation skills. Preferred Qualifications - SAP-certified Security or GRC credentials. - Experience with SAP Cloud Identity services (IAS, IPS) and SCIM-based integrations. - Familiarity with HANA security and analytic privileges. - Experience with continuous controls monitoring frameworks. - Exposure to SAP RISE / Grow security operating models. How to Apply Would you like to know more about this opportunity? We recognize that our people are our strength, and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Bright Vision Technologies is an Equal Opportunity Employer, including Disability/Veterans. Position offered by “No Fee Agency.” Equal Employment Opportunity (EEO) Statement Bright Vision Technologies (BV Teck) is committed to equal employment opportunity (EEO) for all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected status as defined by applicable federal, state, or local laws. This commitment extends to all aspects of employment, including recruitment, hiring, training, compensation, promotion, transfer, leaves of absence, termination, layoffs, and recall. BV Teck expressly prohibits any form of workplace harassment or discrimination. Any improper interference with employees' ability to perform their job duties may result in disciplinary action up to and including termination of employment.



