Skip to main content
Careers at Q-SEC

Build cybersecurity Europe can trust

We defend European organisations against real-world threats. Join a team of pentesters, SOC analysts and engineers who take security personally.

Open roles

Open positions

Find yours below and apply in a couple of clicks.

  • Security Engineer Own and evolve our security platforms by building integrations, automating workflows, and enabling all cybersecurity functions.
    Hybrid in Valencia / remote worldwide Cybersecurity Full-time Middle+

    Working Conditions

    • Cooperation model: B2B contract
    • Contract type: Permanent cooperation
    • Probation period: 3 months
    • Work location: Hybrid in Valencia / remote worldwide
    • Working hours: Standard business hours
    • Stable long-term cooperation within a structured ICT environment
    • Competitive compensation aligned with experience and qualifications

    Key Responsibilities

    • Administer and maintain the SIEM platform, log pipeline, and data ingestion infrastructure
    • Create, tune and optimize SIEM detection rules based on requirements from the SOC Team and Red Team findings
    • Onboard new log sources and maintain existing log integrations across the environment
    • Administrate the AV/EDR platform including policy management, exception handling and reporting
    • Administrate the DLP platform at a technical level — platform configuration, policy enforcement rules and integration maintenance (policy ownership remains with the IS Team)
    • Manage vulnerability scanning infrastructure, track findings, automate reporting workflows and optimize the remediation coordination process with IT to reduce mean time to patch
    • Develop security automation scripts and custom integrations between security tools
    • Resolve integration and tooling challenges across SOC, Red Team, and IS teams
    • Provide technical support and troubleshooting for all security tooling across the team
    • Administer Cloud Security Posture Management (CSPM) tooling and maintain cloud security configurations
    • Maintain inventory and lifecycle management of all security tools
    • Enforce endpoint security baseline and coordinate patch management with IT 

    Required Skills and Experience

    • 3+ years in security engineering, security operations, or a hybrid DevSecOps/SecOps role
    • Solid hands-on SIEM administration experience with strong KQL proficiency — Microsoft Sentinel experience is preferred, but candidates with deep KQL skills and experience on other platforms (Splunk SPL, Elastic EQL) will be considered
    • Experience writing and tuning detection rules covering lateral movement, persistence, exfiltration and command and control scenarios
    • Practical experience with AV/EDR platform administration at policy and configuration level
    • Experience with DLP platform administration at the technical level (Microsoft Purview, Forcepoint or similar)
    • Hands-on vulnerability management experience (Tenable Nessus, Qualys or similar) including automation of scan scheduling and finding workflows
    • Scripting proficiency in Python, PowerShell or Bash for automation and integration tasks
    • Understanding of log formats, syslog, API-based log ingestion
    • Solid Windows and Linux system administration fundamentals
    • English — working proficiency for technical documentation

    Nice to Have

    • Experience with Fortinet stack (FortiGate, FortiMail, FortiAnalyzer, FortiEMS) — directly relevant to our environment
    • Experience with Cloudflare WAF configuration and custom rule writing
    • Cloud Security Posture Management (CSPM) experience (Microsoft Defender for Cloud, Wiz or Prisma Cloud)
    • Experience integrating security tools via REST API
    • Familiarity with SOAR platforms and automation playbook development
    • Knowledge of Azure or AWS environments from a security administration perspective
    • Certifications: SC-200, GCIA, CompTIA CySA+ or equivalent
    • Ukrainian or Russian language is a plus
     
  • SOC Analyst L1/L2 Lead and develop our Cybersecurity practice, driving security operations, technologies, and strategy across Q-Sec.
    Hybrid in Valencia / remote worldwide Cybersecurity Full-time Middle

    Working Conditions

    • Cooperation model: B2B contract
    • Contract type: Permanent cooperation
    • Probation period: 3 months
    • Work location: Hybrid in Valencia / remote worldwide
    • Working hours:
      • Initial period – standard business hours
      • After onboarding – possibility of shift-based schedule
    • Stable long-term cooperation within a structured ICT environment
    • Competitive compensation aligned with experience and qualifications

    Key Responsibilities

    • Monitor and triage security alerts from SIEM, AV/EDR and other security tooling
    • Classify alerts as True Positive or False Positive with documented justification
    • Perform deep incident investigations including multi-source event correlation
    • Execute containment and eradication actions for confirmed incidents
    • Conduct root cause analysis and produce post-incident reports
    • Write, update and maintain SOC playbooks based on investigation findings
    • Coordinate with IT and engineering teams for remediation
    • Provide actionable feedback to Security Engineer for SIEM rule tuning
    • Escalate complex and high-severity cases with full investigation context
    • Mentor L1 analysts through guidance and knowledge sharing
    • Participate in Red Team debrief sessions to improve detection based on exercise findings
    • Analyze and triage web application and API security alerts from WAF, proxy and application logs — including injection attempts, path traversal, authentication abuse, credential stuffing and API abuse patterns
     Required Skills and Experience
    • 2+ years of hands-on SOC or incident response experience
    • Proficient with at least one SIEM platform (Microsoft Sentinel, Splunk, QRadar or similar)
    • Experience correlating events across multiple log sources: endpoint, network, email, identity
    • Solid understanding of Windows and Linux system internals from a forensic perspective
    • Familiarity with AV/EDR platforms and endpoint investigation techniques
    • Knowledge of common attack techniques and Tactics, Techniques and Procedures (TTPs) mapped to MITRE ATT&CK
    • Experience with network traffic analysis (Wireshark, Zeek or similar)
    • Ability to recognize web application attack patterns in WAF and proxy logs (OWASP Top 10, API abuse, authentication attacks)
    • Ability to write clear incident reports and root cause analyses
    • English — professional working proficiency for reports and documentation

    Nice to Have

    • Experience with Microsoft Sentinel specifically — KQL proficiency is a strong plus
    • Exposure to Fortinet stack (FortiGate, FortiMail, FortiAnalyzer)
    • Familiarity with Cloudflare WAF and WAF log interpretation
    • Basic scripting for log parsing or alert enrichment (Python or PowerShell)
    • Experience with threat intelligence platforms or IOC enrichment workflows
    • Exposure to email security investigation (header analysis, DMARC/SPF/DKIM)
    • CEH, CompTIA CySA+, GCIH or equivalent certification
    • Ukrainian or Russian language is a plus

     

  • Penetration Tester Identify security weaknesses through penetration testing and adversary simulations while helping strengthen our detection and response capabilities.
    Hybrid in Valencia / remote worldwide Cybersecurity Full-time Middle+

    Working Conditions

    • Cooperation model: B2B contract
    • Contract type: Permanent cooperation
    • Probation period: 3 months
    • Work location: Hybrid in Valencia / remote worldwide
    • Working hours: Standard business hours
    • Stable long-term cooperation within a structured ICT environment
    • Competitive compensation aligned with experience and qualifications

    Key Responsibilities

    • Plan and execute web application penetration tests across black box, grey box, and white box engagements
    • Conduct API security testing including authentication, authorization, injection and business logic flaws
    • Execute network and infrastructure penetration tests
    • Plan and run Red Team exercises including full adversary simulation campaigns and attack scenario design
    • Execute social engineering simulations at the technical level including phishing campaigns
    • Identify and report business logic flaws with a focus on financial impact — fraud scenarios, unauthorized transactions, privilege abuse and data exposure
    • Conduct SOC detection gap analysis — attack in a controlled manner and assess whether the SOC detects and responds correctly
    • Validate SIEM rule effectiveness through controlled adversarial Tactics, Techniques and Procedures (TTPs) in coordination with Security Engineer
    • Debrief SOC L1/L2 analysts after exercises explaining attacker Tactics, Techniques and Procedures (TTPs), tools used, and indicators that should have triggered detection
    • Hand off detection gap findings to the SOC Team for use case development
    • Produce clear, structured pentest reports with severity ratings, proof of concept, and remediation guidance
    • Coordinate and execute retesting after remediation to verify fixes
    • Stay current on CVEs, exploit techniques, and threat actor Tactics, Techniques and Procedures (TTPs) relevant to fintech
     

    Required Skills and Experience

    • 3+ years of hands-on penetration testing experience across web applications and infrastructure
    • Proficiency in web application testing — OWASP Top 10, authentication flaws, injection, IDOR, business logic vulnerabilities
    • Experience with API security testing (REST, GraphQL, OAuth flows)
    • Solid understanding of network protocols and common infrastructure attack vectors
    • Proficiency with standard offensive tooling: Burp Suite Pro, Metasploit, Nmap, Nuclei, SQLmap, Gobuster
    • Ability to map findings to MITRE ATT&CK Tactics, Techniques and Procedures (TTPs)
    • Experience producing professional pentest reports readable by both technical and non-technical audiences
    • Understanding of how defensive tooling works — SIEM detection logic, AV/EDR behavioral rules, WAF signatures — to conduct realistic and evasion-aware testing
    • English — professional proficiency for report writing and client communication

    Nice to Have

    • Experience running formal Red Team engagements beyond standard pentests
    • Mobile application security testing (iOS and Android) using Frida, Objection or MobSF
    • Active Directory attack techniques — Kerberoasting, DCSync, Pass-the-Hash, ADCS abuse
    • Cloud environment testing (AWS, Azure or GCP)
    • Custom script or tool development for specific attack scenarios (Python or Go)
    • Familiarity with TIBER-EU or CBEST frameworks relevant to fintech regulatory context
    • Experience in purple team exercises working alongside a defensive team
    • OSCP, OSEP, BSCP, CRTE or equivalent certification
     
     
  • SOC Analyst L1/L2 (Junior) Monitor security events, perform initial incident triage, and grow your cybersecurity skills as part of our Security Operations Center.
    Hybrid in Valencia / remote worldwide Cybersecurity Full-time Junior

    Working Conditions

    • Cooperation model: B2B contract
    • Contract type: Permanent cooperation
    • Probation period: 3 months
    • Work location: Hybrid in Valencia / remote worldwide
    • Working hours:
      • Initial period – standard business hours
      • After onboarding – possibility of shift-based schedule
    • Stable long-term cooperation within a structured ICT environment
    • Competitive compensation aligned with experience and qualifications

    Key Responsibilities

    • Monitor security alerts from SIEM and AV/EDR during assigned shifts
    • Triage and classify alerts as True Positive or False Positive following playbooks
    • Create and document incident tickets with accurate and complete information
    • Execute basic host isolation steps when required by playbook
    • Escalate confirmed or unclear incidents to L2 analyst with documented context
    • Record observations and suggestions for detection rule improvement
    • Participate in handover briefings between shifts
    • Support L2 analysts during incident investigations
    • Recognize and triage web application and API security alerts from WAF and proxy logs including common attack patterns such as injection, path traversal and authentication abuse

    Required Skills and Experience

    • 0–1 year of experience in IT security, IT operations or a related field
    • Basic understanding of TCP/IP, DNS and HTTP protocols
    • Familiarity with Windows and Linux operating systems at user level
    • Ability to read and interpret basic log formats (Windows Event Log, syslog)
    • Understanding of core security concepts: malware types, phishing, brute force, DoS
    • Basic awareness of web application attack patterns (OWASP Top 10 at a conceptual level)
    • Ability to follow structured processes and document findings clearly
    • English — ability to read technical documentation and write basic ticket entries
     

    Nice to Have

    • Any exposure to SIEM platforms (even lab or home lab experience)
    • Familiarity with MITRE ATT&CK framework at a conceptual level
    • CompTIA Security+, Google Cybersecurity Certificate or equivalent entry-level certification
    • Experience with Wireshark or basic packet analysis
    • Participation in CTF (Capture The Flag) competitions or cybersecurity coursework
    • Exposure to WAF logs or web proxy logs
    • Ukrainian or Russian language is a plus
  • L2 Engineer Administer hybrid Windows/Linux/VMware infrastructure and operate enterprise monitoring (SCOM, Zabbix, Grafana).
    Warsaw (office-based) Infrastructure & Monitoring Full-time Mid–Senior

    Working conditions

    • Cooperation model: B2B contract
    • Contract type: Permanent cooperation
    • Probation period: 3 months
    • Work location: Office-based position in Warsaw
    • Working hours: standard business hours during the initial period; after onboarding, the possibility of a shift-based schedule (no night shifts)
    • Stable long-term cooperation within a structured ICT environment
    • Exposure to hybrid infrastructure (on-prem + virtualization + cloud integrations)
    • Opportunity to work with enterprise monitoring and infrastructure tools
    • Competitive compensation aligned with experience and qualifications

    Key responsibilities

    Infrastructure & systems administration

    • Administration and maintenance of Windows Server and Linux (Ubuntu) environments.
    • Day-to-day server administration: patching, performance troubleshooting, and system health checks.
    • Basic administration of Office 365, Apache, and Nginx services.
    • Creation, configuration, and lifecycle management of virtual machines within VMware environments.
    • Resolution of infrastructure-related incidents and technical issues in cooperation with internal teams.

    Monitoring operations & incident handling

    • Administration and daily operation of monitoring systems (SCOM, Zabbix, Grafana).
    • Monitoring infrastructure health, availability, and performance.
    • Handling and resolving monitoring alerts, incidents, and events.
    • Root cause analysis and reduction of false positives.
    • Working within ticketing systems (incident tracking, documentation, escalation).
    • Ensuring SLA-driven response and structured troubleshooting.

    Monitoring improvement & development

    • Onboarding new systems and services into monitoring platforms.
    • Continuous improvement of monitoring configurations, alert logic, and dashboards.
    • Supporting monitoring in virtualized environments.
    • Participation in the optimization of monitoring processes and observability practices.

    Required skills & experience

    • 3+ years of experience in ICT, infrastructure, or monitoring-related roles.
    • Hands-on experience with at least one monitoring platform: SCOM, Zabbix, or Grafana.
    • Solid experience in Windows Server administration.
    • Practical experience with Linux (Ubuntu) systems.
    • VMware experience (VM creation, configuration, and management).
    • Good understanding of networking fundamentals (TCP/IP, DNS, DHCP, VLANs, firewall basics).
    • Experience working with ticketing systems and structured incident management.
    • Ability to perform root cause analysis and independently resolve infrastructure issues.

    Nice to have

    • Experience with VMware Aria Operations.
    • Experience with APM tools (Dynatrace, New Relic, Datadog, AppDynamics).
    • Experience with SCCM / MECM or Microsoft Intune.
    • Basic to intermediate knowledge of AWS or Microsoft Azure.
    • Scripting skills (PowerShell, Bash).
    • Experience in automation of administrative or monitoring tasks.
    • ITIL knowledge.
    • Ukrainian or Russian language is a plus

Apply now

Tell us who you are and which position you're interested in.