Security Operations Engineer (SOC + Offensive)
15 hours ago
Alicante
About Qalea We are Qalea, a fast-growing, early-stage cybersecurity startup on a mission to make digital security intuitive and accessible for every business. We've built a platform that puts simplicity, usability, and real impact at the core of cybersecurity. We've raised 1.5M€ and are backed by top-tier investors, from cybersecurity unicorn founders to leading VC firms. We're also proud to be part of the Google for Startups AI-Cybersecurity program, working alongside some of the brightest minds in product and security. We move fast, stay curious, and care deeply about what we're building. What matters to us is making an impact and building together, while enjoying the ride. The Mission We're looking for an Security Operations Engineer (SOC + Offensive) to join the operations team and help lead how we detect, respond to, and proactively test threats across our customers. You'll wear two hats. On one side, you'll drive our SOC and incident response practice across clients: shaping detection and response strategy, coordinating the operation, and making sure incidents are handled fast and well. On the other, you'll bring hands-on offensive security: running penetration testing where depth matters, and thinking like an attacker to stay ahead of real threats. This is a role with real ownership and visible impact from day one. You'll work shoulder-to-shoulder with a strong team, raising the bar on a security operation that our customers rely on every day and helping it scale as we grow. What You'll Do • Own the SOC and incident response layer end to end across customers: drive the detection and response strategy, coordinate the operation, and ensure incidents are triaged and handled fast and well, continuously refining playbooks and detection logic, and working with the product team to keep it automated and scalable., • Run penetration testing engagements, combining manual testing where depth matters with automated approaches for scale, bringing an attacker's mindset to surface real risk before others do., • Be the trusted technical voice for customers' security operations: clarify findings, prioritize what matters, and make sure remediation actually happens., • Partner closely with engineering to evolve our scanning capabilities across infrastructure, cloud, and code (external & internal vulnerability scanning, CSPM/misconfigurations, SAST, DAST, SBOM), and act as the technical backbone for the operations team on these topics. Must-Haves • Strong client-facing skills - you can explain complex security topics clearly, build trust with customers, and handle technical conversations with confidence., • 3+ years in security operations, incident response, or SOC environments, this is the core of the role., • Solid command of the detection and response lifecycle end to end: triage, investigation, containment, and coordination across stakeholders., • Practical penetration testing skills, both manual and automated, backed by OSCP (or a clear path to it / equivalent offensive certification)., • Working knowledge of vulnerability scanning across infrastructure, cloud, and code., • Comfortable partnering with engineering on security tooling and acting as a technical reference for the operations team., • A proactive, deeply technical, hands-on mindset. You thrive in ambiguity and bring structure where there is none., • Comfort working across both defense and offense. You can lead a SOC/IR operation and also run a pentest. Nice-to-Haves • Experience in early-stage startups or fast-paced SaaS environments., • Hands-on with SIEM / EDR / detection engineering and modern threat hunting., • Experience helping automate or scale security operations workflows., • Comfortable using AI tools to amplify your work and move faster. You see AI as a partner, not a threat. Cultural Fit • Solution-Oriented: You bring solutions, not problems. You're proactive in overcoming blockers., • Accountability: You create clarity rather than expecting others to create it for you. You understand that responsibility is the ability to respond, and accountability is the ownership of the (quantifiable) result., • Ownership Mindset: You're autonomous, decisive, and lead with confidence., • Collaboration: You work seamlessly with Product & Engineering., • Communication: Native-level fluency in Spanish and professional fluency in English is mandatory. Our Benefits • 🧩 Impact: Be part of our startup journey early, playing a key role in our growth and building something meaningful, • 🚀 Growth: Help shape the engineering culture of a Google-backed startup from the early stages., • 📅 Extra days of vacation, 26 days total (23 days vacation + your Birthday + Dec 24th & 31st), • 🌍 Working remotely in summer and Christmas to visit family or other places, • 🏋🏻♂️ Gympass included to support your fitness and well-being, • 🍏 Free fresh fruit every day to help you care for your health, • ☕ Unlimited specialty coffee (Syra), • 🍴 A discount @ Nora food where you can also get daily menu deals, • 🏖️ A cool corner office in Barcelona's Poblenou, surrounded by a thriving tech scene and it's where we actually build. We work mostly in-person because decisions happen live and ideas evolve on the whiteboard, with flexibility on hybrid where it makes sense., • 📚 Continuous learning, including but not limited to mentoring, coaching, workshops, and opportunities to attend security conferences, • 🎉 Team gatherings and celebrations, because we love to build connections and celebrate achievements together, • 👨💻 A collaborative culture because we foster hard work, teamwork, transparency, and respect, encouraging open communication and a positive environment where your voice matters. Recruitment Process • Stage 1: Phone Screen (15 mins): quick check on experience, location, and expectations, • Stage 2: Technical Deep Dive (45 mins): we get into your real work: SOC/IR, pentests, scanning, tooling, and why Qalea, • Stage 3: Practical Exercise (60-90 mins): a hands-on technical challenge so we can see how you approach problems and how you think, • Stage 4: Cultural Fit with the CEO (30 mins): a final conversation to make sure we're fully aligned on both sides before making it official Timeline: 2-3 weeks from first call to offer Ready to shape the future of cybersecurity? 👉🏻 https://navy-flare-a24.notion.site/c8b2bcea0d718370a2d0018ddc0cab78?pvs=105