Senior Product Security Engineer
Software Engineering, Product
Madrid, Spain
Posted on Jul 23, 2026
Strength in Trust
OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society.The Challenge
OneTrust is seeking a Senior Product Security Engineer to lead hands-on product and application security work including penetration testing, remediation guidance, customer-facing security engagements, bug bounty operations, and vendor coordination, while helping expand coverage for AI-enabled features and agentic integrations.Your Mission
- Conduct application-level penetration testing across product surfaces, including web and mobile applications, to identify vulnerabilities and help drive remediation.
- Partner with customers to coordinate penetration tests, communicate findings clearly, and provide practical remediation guidance to engineering teams.
- Manage bug bounty workflows, work with external researchers, and track issues through closure.
- Coordinate with product security vendors and internal stakeholders to improve the effectiveness and consistency of security testing.
- Build and improve security automation and internal tooling, including AI-assisted workflows that support testing, triage, and validation across product security programs.
- Assess AI-enabled product features, agentic workflows, retrieval pipelines, and tool integrations for risks such as prompt injection, tool misuse, tool poisoning, excessive permissions, and data exfiltration.
- Test MCP servers and integrations through direct protocol testing, trusted-client testing, and multi-server adversarial scenarios, including validation of tool descriptions, schemas, permissions, and runtime behavior.
- Partner with engineering teams to embed secure development practices for MCP and AI-connected components.
You Are
- Proven experience in penetration testing and software security, with strong knowledge of security protocols, cryptography, and network security.
- Experience working collaboratively with customers, developers, and vendors, along with strong written and verbal communication skills.
- Scripting and automation experience for scaling security testing and remediation workflows.
- Fluency in English.
- Bachelor’s degree in Computer Science, Information Security, or a related field preferred; equivalent experience may be substituted.
- Proficiency in Spanish.
- Hands-on experience with Burp Suite and deep application security testing experience.
- Relevant offensive security certifications such as OSCP or GWAPT.
- Familiarity with AI security frameworks and practices, including OWASP guidance for GenAI and agentic systems and adversarial testing approaches aligned to recognized industry frameworks.