Shakers for expert talent

Work as a Security Engineer on real systems

Projects where the offence is yours: which system gets tested, what gets monitored and which report gets written. Shakers connects you with teams waiting for an incident to take security seriously.

What gets read about cybersecurity is either glossaries of terms or certification syllabi. Neither tells you how to start protecting a real company's systems project by project, report after report. Here is that.

  • Higher-paying projects
  • More continuity between projects
  • Greater recognition for your experience
Shakers panel showing four available profiles and their match percentage
Looking for cybersecurity projects
Allianz
BBVA
Bankinter
Microsoft
Qida
Accenture
Deloitte
Dcycle
HP
Línea Directa
Podo
Clicars
Sonosuite
Eroski
Civitatis
Alten
Vivla
Wayra
Cabify
Affinity
+3,000

Tech projects published on Shakers

+90

Tech, Product and Data specialisms are part of Shakers

6 months

Average length of a project with Shakers

4.7/5

Our AI Builders' satisfaction on Trustpilot

AI Builder careers powered by Shakers

See how other AI Builders access better projects, build their reputation and grow their careers.

Portrait of Álvaro, Data Scientist in the Shakers collective Ready to build

Álvaro

Data Scientist

“In a climate this uncertain, Shakers gives you a layer of reassurance and confidence. What I like most, without a doubt, is the flexibility and getting to work on top-tier projects.”

Join Shakers
Portrait of Amelia, AI Agent Developer in the Shakers collective Ready to build

Amelia

AI Agent Developer

“I have been building AI agents for years. Thanks to Shakers I stopped chasing clients and started genuinely choosing which projects I wanted to work on. I work with some of the best companies in Europe, at my own rate, and I focus on what I am good at and what I love: building.”

Join Shakers
Portrait of Luz, Backend Developer and Data Engineer in the Shakers collective Ready to build

Luz

Backend Developer & Data Engineer

“Shakers adds a lot of value because it connects you with sharper projects, already filtered and better defined. It saves you a big part of the upfront work of understanding the client, quoting and weighing up whether it is worth it, and that means that as a contractor you can go far more directly to the opportunities that genuinely fit you.”

Join Shakers
Portrait of Rubén, Software Developer in the Shakers collective Ready to build

Rubén

Software Developer

“Life as a contractor has a lot going on and it is not always easy. We like to focus on what we are good at, but you also have to manage clients, invoicing and go looking for work. For me, Shakers has been key because it does that prospecting for me, it gives the client confidence from the very first moment, and it lets us be part of a community with real enthusiasm.”

Join Shakers
Portrait of Alejandro, AI Developer in the Shakers collective Ready to build

Alejandro

AI Developer

“Shakers was key to getting my company off the ground: it gave me the flexibility to keep contracting while I built my next chapter. Without Shakers, I would have had to raise funding or push the project back.”

Join Shakers
Portrait of Toño, Product Designer in the Shakers collective Ready to build

Toño

Product Designer

“With Shakers I have landed recurring projects that give me peace of mind and room to grow professionally. It is not just about reaching quality clients: it is feeling that you have a network behind you, one that connects you with real opportunities and helps you move forward as a freelancer.”

Join Shakers

The decisions a Security Engineer owns every week

A Security Engineer protects systems with offence and defence: penetration testing to find the vulnerability before the attacker, SIEM and XDR to detect in real time, and sector compliance. Their most visible craft, the pentester, thinks like the attacker to close the path; their real job is that the attack, when it comes, finds nothing open.

You decide which system gets tested first and with what method, which alert deserves a threshold and which is noise, and which fix is demanded before deploying again. You also decide what does not get done: a pentest without written permission does not exist. The systems belong to the company; that nobody breaks in, also yours.

pentestingSIEMXDROWASPDevSecOpsPythonincident responsecomplianceCISSPOSCPcloudKubernetes PentestingSIEM and XDRDevSecOpsOWASPComplianceIncident response

Free to join, no hidden fees

How Shakers works for talent

Join Shakers

Create your profile

Tell us who you are, what you can do, the projects you want to work on and what your availability and rate are.

Get your certification

We certify your experience and your use of AI so companies understand and trust what you bring.

Match with projects

We connect you with well-paid projects that fit your expertise and your preferences.

Specialist sitting on a sofa with a tablet and a Ready_to_build label

DevOps and Cloud projects that live up to your expectations

Work on real projects, with teams that need your expertise, without wasting time looking for opportunities.

  • Projects that fit you

    Work with companies that need your stack and experience to take their projects to production.

  • Opportunities that come to you

    Our AI matching connects your profile with the projects that fit your preferences.

  • You build. Shakers handles the rest

    Set your own terms based on your seniority. We manage contracts, payments and paperwork.

What a Security Engineer delivers at Shakers

At Shakers

The brief arrives with the reason

Shakers is hiring infrastructure: the project arrives with the audit a client demands or the certification to pass, not with a list of technologies.

Delivery

Reproducible reports

You deliver every finding with its exploitation path and its fix, in the format board and auditor understand without translation.

Operations

What happens when you detect

You set each alert's threshold, the escalation and response times. Detection without a response plan is expensive noise.

What we ask

Real systems protected

Having pentested with permission on company systems and being able to tell the most uncomfortable finding you signed and how it was fixed.

Judgement

Test or monitor

Choosing by real risk, not tool catalogue. Sometimes the honest answer is patch three things and stop, and defending it.

Boundary

Where your brief ends

You protect the systems; you don't build or operate them. If the problem is pipeline or availability, you say so at kickoff.

Frequently asked questions

Any other questions? Write to us and we will reply.

What should you learn to work in cybersecurity?
The offensive method first: OWASP and pentesting practice in the lab. Then defence (SIEM, XDR) and sector compliance. Shakers certification looks at real reports.
Which tools do you use daily?
Pentesting tools (Burp, Nmap, Metasploit) for offence, the client's SIEM platform for defence and Python as glue. Certifications (OSCPP, CISSP) open doors.
Are pentester and ethical hacker the same?
Yes: two names for whoever attacks systems with permission to find the gap before the one without it. The Security Engineer widens that craft with defence and compliance.
How much do you earn as a freelance Security Engineer?
You invoice per project and scope sets the band: which systems the test covers and what monitoring remains. You agree the budget before accepting.
Is cybersecurity work something you can do remotely?
Almost everything: systems live in the cloud and tests are launched remotely. Only the odd physical audit asks for presence.
How do you join Shakers as a Security Engineer?
You create your profile, pass the certification process and enter the collective: only 4 percent make it. Then you choose your security projects.
The daily shape of the craft

The previous client's report nobody fixed, the alert that fires at 5 p.m. on a Friday and the auditor arriving next month. Fewer certificates accumulated, more systems left closed.

The craft with demand of its own

1,310 active tech job ads in Spain mention cybersecurity and pentester gathers 2,900 monthly searches, according to Shakers' market analysis (n=30,508, September 2026). The market asks for the craft by its name.

How people get here

Three frequent doors: the developer obsessed with breaking what they built, the sysadmin tired of patching, and the lab autodidact looking for their first real client.

What this role is not

Not the antivirus admin nor the paperwork signer. If the problem is the pipeline, the role is DevOps; availability, SRE. Here, you protect.

The roles a security project crosses

Four roles from the collective cross your path while you protect systems, from the one deploying to the one sustaining the platform.

Pipeline

DevOps Engineer

DevSecOps is built on their pipeline: the security of the software's path is worked shoulder to shoulder with them.

View profile →

On-call

Site Reliability Engineer

Incident response coordinates with whoever sustains the platform: availability and security are the same small hours.

View profile →

AWS cut

AWS DevOps Engineer

The security of the Amazon account (IAM, configuration) is audited alongside whoever builds and runs it daily.

View profile →

Code

Backend Developer

OWASP gets fixed in code: every application vulnerability is closed four-handed with whoever wrote it.

View profile →

Boundaries between these roles are agreed per project: the job title doesn't set them.

Take the next step with Shakers

Want systems nobody breaks into?

Pass Shakers certification and choose which security projects you take on.