Skip to content

Open nowPosted 102 days ago

Platform Security Engineer

Causa Prima6 open roles

Where
Madrid
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPlatform Security EngineerCausa Prima · Madrid
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Causa Prima's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Causa Prima postings stay open a median of 12 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.1%30 days
This job: posted 102 days ago

Causa Prima median: 12 days open

The posting

In this role, you will design and build the System Integrity Layer, establishing the foundational platform primitives that guarantee every agent action is isolated and attributable, every execution is traceable, every state transition is verifiable, and every software release satisfies strict security constraints by construction. This is a hands-on backend security engineering role where security, threat resilience, and compliance are natural outcomes of brilliant system architecture, not separate, bureaucratic processes. We are looking for a builder, not a governance operator—someone who treats trust guarantees as core system properties designed directly into the database and application layers from day one. Architecture or technical-leadership experience is fine, even welcome, as long as it comes with real hands-on depth you can point to—specific systems you designed and built—rather than process, documentation, or audit-standardization work alone.

What you'll do:

- System Integrity Layer & Threat Modeling — Design the core execution model that governs how autonomous agents run, interact, and modify system state.

- Proactive Threat Modeling — Conduct continuous, code-level threat modeling across our distributed networks to identify structural vectors, memory leakage, prompt manipulation, and authorization bypasses before a single line hits staging.

- Auditability as a Native Property — Build append-only, tamper-resistant event systems that make every action reconstructable without relying on external logging frameworks or reactive "audit tooling."

- Isolation, Trust Boundaries, & Adversarial Testing — Engineer strict execution and data isolation layers between agents, users, and workflows in a multi-tenant infrastructure.

- Continuous Offensive Testing — Run active internal pentesting, adversarial chaos testing, and targeted red teaming exercises against our own infrastructure to aggressively expose flaws in isolation barriers and cryptographic verification boundaries.

- Agent Execution Guarantees — Ensure all automated, agentic accounting processes are strictly attributable, deterministic where required, verifiable in hindsight, and unalterably constrained by explicit system rules.

- Robust Engineering & Pipeline Security — Architect and refine our internal software delivery pipeline to guarantee absolute integrity from code commit to production deployment.

- Build deterministic verification mechanisms into the CI/CD pipeline, ensuring that all third-party dependencies, agent libraries, and compiled services are cryptographically signed, scanned, and secure by default.

- Compliance Through Architecture — Translate complex regulatory and audit requirements directly into low-level system constraints, completely eliminating the need for reactive operational processes or manual review workflows.

What we're looking for

- Experience: 5+ years designing production backend platforms and distributed systems design.

- Database experience: Deep schema design, RLS, and event-sourcing database expertise.

- Security Architecture: Practical application-level security, encryption models, key management, and auth patterns.

- Adversarial Mindset: You naturally think like an attacker to uncover race conditions, logic flaws, and vulnerabilities.

- Policy-as-Code: Hands-on experience with Cerbos, OPA, Cedar, or similar.

- Domain knowledge: You've owned real breadth of the security stack, not one narrow slice of it. You understand what securing mission-critical enterprise software at large scale demands. Regulated industries (fintech, banking, insurance) are a plus, but end-to-end ownership counts for more than time spent inside a large org.

Nice to have:

- Cryptographic primitives

- Event streaming (Kafka/Redpanda)

- Kubernetes and cloud-native architecture knowledge

- LLM/agentic system security exposure (prompt injection defense, guardrails, agent threat modeling)—relevant to our product surface, but a plus on top of the backend and security fundamentals above, not a substitute for them.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Causa Prima's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Causa Prima's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Causa Prima's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.