Senior Product Security Engineer

OneTrust · Madrid, Spain · Engineering

Posted 2026-07-22

Apply for this role →

The Challenge

OneTrust is seeking a Senior Product Security Engineer to lead hands-on product and application security work including penetration testing, remediation guidance, customer-facing security engagements, bug bounty operations, and vendor coordination, while helping expand coverage for AI-enabled features and agentic integrations.

Your Mission

Conduct application-level penetration testing across product surfaces, including web and mobile applications, to identify vulnerabilities and help drive remediation.

Partner with customers to coordinate penetration tests, communicate findings clearly, and provide practical remediation guidance to engineering teams.

Manage bug bounty workflows, work with external researchers, and track issues through closure.

Coordinate with product security vendors and internal stakeholders to improve the effectiveness and consistency of security testing.

Build and improve security automation and internal tooling, including AI-assisted workflows that support testing, triage, and validation across product security programs.

Assess AI-enabled product features, agentic workflows, retrieval pipelines, and tool integrations for risks such as prompt injection, tool misuse, tool poisoning, excessive permissions, and data exfiltration.

Test MCP servers and integrations through direct protocol testing, trusted-client testing, and multi-server adversarial scenarios, including validation of tool descriptions, schemas, permissions, and runtime behavior.

Partner with engineering teams to embed secure development practices for MCP and AI-connected components.

You Are

Proven experience in penetration testing and software security, with strong knowledge of security protocols, cryptography, and network security.

Experience working collaboratively with customers, developers, and vendors, along with strong written and verbal communication skills.

Scripting and automation experience for scaling security testing and remediation workflows.

Fluency in English.

Bachelor’s degree in Computer Science, Information Security, or a related field preferred; equivalent experience may be substituted.

Preferred Qualifications

Proficiency in Spanish.

Hands-on experience with Burp Suite and deep application security testing experience.

Relevant offensive security certifications such as OSCP or GWAPT.

Familiarity with AI security frameworks and practices, including OWASP guidance for GenAI and agentic systems and adversarial testing approaches aligned to recognized industry frameworks.

Apply for this role →

← Back to all jobs