Careers at Q-SEC
Build cybersecurity Europe can trust
We defend European organisations against real-world threats. Join a team of pentesters, SOC analysts and engineers who take security personally.
Open roles
Open positions
Find yours below and apply in a couple of clicks.
No roles match those filters.
-
Security Engineer Own and evolve our security platforms by building integrations, automating workflows, and enabling all cybersecurity functions.Hybrid in Valencia / remote worldwide Cybersecurity Full-time Middle+
Working Conditions
- Cooperation model: B2B contract
- Contract type: Permanent cooperation
- Probation period: 3 months
- Work location: Hybrid in Valencia / remote worldwide
- Working hours: Standard business hours
- Stable long-term cooperation within a structured ICT environment
- Competitive compensation aligned with experience and qualifications
Key Responsibilities
- Administer and maintain the SIEM platform, log pipeline, and data ingestion infrastructure
- Create, tune and optimize SIEM detection rules based on requirements from the SOC Team and Red Team findings
- Onboard new log sources and maintain existing log integrations across the environment
- Administrate the AV/EDR platform including policy management, exception handling and reporting
- Administrate the DLP platform at a technical level — platform configuration, policy enforcement rules and integration maintenance (policy ownership remains with the IS Team)
- Manage vulnerability scanning infrastructure, track findings, automate reporting workflows and optimize the remediation coordination process with IT to reduce mean time to patch
- Develop security automation scripts and custom integrations between security tools
- Resolve integration and tooling challenges across SOC, Red Team, and IS teams
- Provide technical support and troubleshooting for all security tooling across the team
- Administer Cloud Security Posture Management (CSPM) tooling and maintain cloud security configurations
- Maintain inventory and lifecycle management of all security tools
- Enforce endpoint security baseline and coordinate patch management with IT
Required Skills and Experience
- 3+ years in security engineering, security operations, or a hybrid DevSecOps/SecOps role
- Solid hands-on SIEM administration experience with strong KQL proficiency — Microsoft Sentinel experience is preferred, but candidates with deep KQL skills and experience on other platforms (Splunk SPL, Elastic EQL) will be considered
- Experience writing and tuning detection rules covering lateral movement, persistence, exfiltration and command and control scenarios
- Practical experience with AV/EDR platform administration at policy and configuration level
- Experience with DLP platform administration at the technical level (Microsoft Purview, Forcepoint or similar)
- Hands-on vulnerability management experience (Tenable Nessus, Qualys or similar) including automation of scan scheduling and finding workflows
- Scripting proficiency in Python, PowerShell or Bash for automation and integration tasks
- Understanding of log formats, syslog, API-based log ingestion
- Solid Windows and Linux system administration fundamentals
- English — working proficiency for technical documentation
Nice to Have
- Experience with Fortinet stack (FortiGate, FortiMail, FortiAnalyzer, FortiEMS) — directly relevant to our environment
- Experience with Cloudflare WAF configuration and custom rule writing
- Cloud Security Posture Management (CSPM) experience (Microsoft Defender for Cloud, Wiz or Prisma Cloud)
- Experience integrating security tools via REST API
- Familiarity with SOAR platforms and automation playbook development
- Knowledge of Azure or AWS environments from a security administration perspective
- Certifications: SC-200, GCIA, CompTIA CySA+ or equivalent
- Ukrainian or Russian language is a plus
-
SOC Analyst L1/L2 Lead and develop our Cybersecurity practice, driving security operations, technologies, and strategy across Q-Sec.Hybrid in Valencia / remote worldwide Cybersecurity Full-time Middle
Working Conditions
- Cooperation model: B2B contract
- Contract type: Permanent cooperation
- Probation period: 3 months
- Work location: Hybrid in Valencia / remote worldwide
- Working hours:
- Initial period – standard business hours
- After onboarding – possibility of shift-based schedule
- Stable long-term cooperation within a structured ICT environment
- Competitive compensation aligned with experience and qualifications
Key Responsibilities
- Monitor and triage security alerts from SIEM, AV/EDR and other security tooling
- Classify alerts as True Positive or False Positive with documented justification
- Perform deep incident investigations including multi-source event correlation
- Execute containment and eradication actions for confirmed incidents
- Conduct root cause analysis and produce post-incident reports
- Write, update and maintain SOC playbooks based on investigation findings
- Coordinate with IT and engineering teams for remediation
- Provide actionable feedback to Security Engineer for SIEM rule tuning
- Escalate complex and high-severity cases with full investigation context
- Mentor L1 analysts through guidance and knowledge sharing
- Participate in Red Team debrief sessions to improve detection based on exercise findings
- Analyze and triage web application and API security alerts from WAF, proxy and application logs — including injection attempts, path traversal, authentication abuse, credential stuffing and API abuse patterns
Required Skills and Experience- 2+ years of hands-on SOC or incident response experience
- Proficient with at least one SIEM platform (Microsoft Sentinel, Splunk, QRadar or similar)
- Experience correlating events across multiple log sources: endpoint, network, email, identity
- Solid understanding of Windows and Linux system internals from a forensic perspective
- Familiarity with AV/EDR platforms and endpoint investigation techniques
- Knowledge of common attack techniques and Tactics, Techniques and Procedures (TTPs) mapped to MITRE ATT&CK
- Experience with network traffic analysis (Wireshark, Zeek or similar)
- Ability to recognize web application attack patterns in WAF and proxy logs (OWASP Top 10, API abuse, authentication attacks)
- Ability to write clear incident reports and root cause analyses
- English — professional working proficiency for reports and documentation
Nice to Have
- Experience with Microsoft Sentinel specifically — KQL proficiency is a strong plus
- Exposure to Fortinet stack (FortiGate, FortiMail, FortiAnalyzer)
- Familiarity with Cloudflare WAF and WAF log interpretation
- Basic scripting for log parsing or alert enrichment (Python or PowerShell)
- Experience with threat intelligence platforms or IOC enrichment workflows
- Exposure to email security investigation (header analysis, DMARC/SPF/DKIM)
- CEH, CompTIA CySA+, GCIH or equivalent certification
- Ukrainian or Russian language is a plus
-
Penetration Tester Identify security weaknesses through penetration testing and adversary simulations while helping strengthen our detection and response capabilities.Hybrid in Valencia / remote worldwide Cybersecurity Full-time Middle+
Working Conditions
- Cooperation model: B2B contract
- Contract type: Permanent cooperation
- Probation period: 3 months
- Work location: Hybrid in Valencia / remote worldwide
- Working hours: Standard business hours
- Stable long-term cooperation within a structured ICT environment
- Competitive compensation aligned with experience and qualifications
Key Responsibilities
- Plan and execute web application penetration tests across black box, grey box, and white box engagements
- Conduct API security testing including authentication, authorization, injection and business logic flaws
- Execute network and infrastructure penetration tests
- Plan and run Red Team exercises including full adversary simulation campaigns and attack scenario design
- Execute social engineering simulations at the technical level including phishing campaigns
- Identify and report business logic flaws with a focus on financial impact — fraud scenarios, unauthorized transactions, privilege abuse and data exposure
- Conduct SOC detection gap analysis — attack in a controlled manner and assess whether the SOC detects and responds correctly
- Validate SIEM rule effectiveness through controlled adversarial Tactics, Techniques and Procedures (TTPs) in coordination with Security Engineer
- Debrief SOC L1/L2 analysts after exercises explaining attacker Tactics, Techniques and Procedures (TTPs), tools used, and indicators that should have triggered detection
- Hand off detection gap findings to the SOC Team for use case development
- Produce clear, structured pentest reports with severity ratings, proof of concept, and remediation guidance
- Coordinate and execute retesting after remediation to verify fixes
- Stay current on CVEs, exploit techniques, and threat actor Tactics, Techniques and Procedures (TTPs) relevant to fintech
Required Skills and Experience
- 3+ years of hands-on penetration testing experience across web applications and infrastructure
- Proficiency in web application testing — OWASP Top 10, authentication flaws, injection, IDOR, business logic vulnerabilities
- Experience with API security testing (REST, GraphQL, OAuth flows)
- Solid understanding of network protocols and common infrastructure attack vectors
- Proficiency with standard offensive tooling: Burp Suite Pro, Metasploit, Nmap, Nuclei, SQLmap, Gobuster
- Ability to map findings to MITRE ATT&CK Tactics, Techniques and Procedures (TTPs)
- Experience producing professional pentest reports readable by both technical and non-technical audiences
- Understanding of how defensive tooling works — SIEM detection logic, AV/EDR behavioral rules, WAF signatures — to conduct realistic and evasion-aware testing
- English — professional proficiency for report writing and client communication
Nice to Have
- Experience running formal Red Team engagements beyond standard pentests
- Mobile application security testing (iOS and Android) using Frida, Objection or MobSF
- Active Directory attack techniques — Kerberoasting, DCSync, Pass-the-Hash, ADCS abuse
- Cloud environment testing (AWS, Azure or GCP)
- Custom script or tool development for specific attack scenarios (Python or Go)
- Familiarity with TIBER-EU or CBEST frameworks relevant to fintech regulatory context
- Experience in purple team exercises working alongside a defensive team
- OSCP, OSEP, BSCP, CRTE or equivalent certification
-
SOC Analyst L1/L2 (Junior) Monitor security events, perform initial incident triage, and grow your cybersecurity skills as part of our Security Operations Center.Hybrid in Valencia / remote worldwide Cybersecurity Full-time Junior
Working Conditions
- Cooperation model: B2B contract
- Contract type: Permanent cooperation
- Probation period: 3 months
- Work location: Hybrid in Valencia / remote worldwide
- Working hours:
- Initial period – standard business hours
- After onboarding – possibility of shift-based schedule
- Stable long-term cooperation within a structured ICT environment
- Competitive compensation aligned with experience and qualifications
Key Responsibilities
- Monitor security alerts from SIEM and AV/EDR during assigned shifts
- Triage and classify alerts as True Positive or False Positive following playbooks
- Create and document incident tickets with accurate and complete information
- Execute basic host isolation steps when required by playbook
- Escalate confirmed or unclear incidents to L2 analyst with documented context
- Record observations and suggestions for detection rule improvement
- Participate in handover briefings between shifts
- Support L2 analysts during incident investigations
- Recognize and triage web application and API security alerts from WAF and proxy logs including common attack patterns such as injection, path traversal and authentication abuse
Required Skills and Experience
- 0–1 year of experience in IT security, IT operations or a related field
- Basic understanding of TCP/IP, DNS and HTTP protocols
- Familiarity with Windows and Linux operating systems at user level
- Ability to read and interpret basic log formats (Windows Event Log, syslog)
- Understanding of core security concepts: malware types, phishing, brute force, DoS
- Basic awareness of web application attack patterns (OWASP Top 10 at a conceptual level)
- Ability to follow structured processes and document findings clearly
- English — ability to read technical documentation and write basic ticket entries
Nice to Have
- Any exposure to SIEM platforms (even lab or home lab experience)
- Familiarity with MITRE ATT&CK framework at a conceptual level
- CompTIA Security+, Google Cybersecurity Certificate or equivalent entry-level certification
- Experience with Wireshark or basic packet analysis
- Participation in CTF (Capture The Flag) competitions or cybersecurity coursework
- Exposure to WAF logs or web proxy logs
- Ukrainian or Russian language is a plus
-
L2 Engineer Administer hybrid Windows/Linux/VMware infrastructure and operate enterprise monitoring (SCOM, Zabbix, Grafana).Warsaw (office-based) Infrastructure & Monitoring Full-time Mid–Senior
Working conditions
- Cooperation model: B2B contract
- Contract type: Permanent cooperation
- Probation period: 3 months
- Work location: Office-based position in Warsaw
- Working hours: standard business hours during the initial period; after onboarding, the possibility of a shift-based schedule (no night shifts)
- Stable long-term cooperation within a structured ICT environment
- Exposure to hybrid infrastructure (on-prem + virtualization + cloud integrations)
- Opportunity to work with enterprise monitoring and infrastructure tools
- Competitive compensation aligned with experience and qualifications
Key responsibilities
Infrastructure & systems administration
- Administration and maintenance of Windows Server and Linux (Ubuntu) environments.
- Day-to-day server administration: patching, performance troubleshooting, and system health checks.
- Basic administration of Office 365, Apache, and Nginx services.
- Creation, configuration, and lifecycle management of virtual machines within VMware environments.
- Resolution of infrastructure-related incidents and technical issues in cooperation with internal teams.
Monitoring operations & incident handling
- Administration and daily operation of monitoring systems (SCOM, Zabbix, Grafana).
- Monitoring infrastructure health, availability, and performance.
- Handling and resolving monitoring alerts, incidents, and events.
- Root cause analysis and reduction of false positives.
- Working within ticketing systems (incident tracking, documentation, escalation).
- Ensuring SLA-driven response and structured troubleshooting.
Monitoring improvement & development
- Onboarding new systems and services into monitoring platforms.
- Continuous improvement of monitoring configurations, alert logic, and dashboards.
- Supporting monitoring in virtualized environments.
- Participation in the optimization of monitoring processes and observability practices.
Required skills & experience
- 3+ years of experience in ICT, infrastructure, or monitoring-related roles.
- Hands-on experience with at least one monitoring platform: SCOM, Zabbix, or Grafana.
- Solid experience in Windows Server administration.
- Practical experience with Linux (Ubuntu) systems.
- VMware experience (VM creation, configuration, and management).
- Good understanding of networking fundamentals (TCP/IP, DNS, DHCP, VLANs, firewall basics).
- Experience working with ticketing systems and structured incident management.
- Ability to perform root cause analysis and independently resolve infrastructure issues.
Nice to have
- Experience with VMware Aria Operations.
- Experience with APM tools (Dynatrace, New Relic, Datadog, AppDynamics).
- Experience with SCCM / MECM or Microsoft Intune.
- Basic to intermediate knowledge of AWS or Microsoft Azure.
- Scripting skills (PowerShell, Bash).
- Experience in automation of administrative or monitoring tasks.
- ITIL knowledge.
- Ukrainian or Russian language is a plus
Apply now
Tell us who you are and which position you're interested in.
Applying for: