4 часа назад
Senior Security Engineer (SaaS)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer (SaaS): Owning product, cloud, internal IT, detection, response, and compliance security for a production B2B SaaS platform with an accent on AWS hardening, secure development, and vulnerability management. Focus on building detection and response capabilities, leading incident containment, encoding infrastructure baselines as policy-as-code, and driving remediation with product teams.
Location: Munich or Berlin, Germany. Hybrid work with 3 days on-site in the office and 2 days flexible.
Company
provides a B2B SaaS platform that helps construction professionals collaborate and manage construction projects efficiently.
What you will do
- Own product and cloud security end to end, including threat modeling, security reviews, secure-by-default patterns, and CI/CD security tooling.
- Harden AWS infrastructure through IAM architecture, network segmentation, encryption, logging, workload security, and policy-as-code.
- Build detection and response capabilities and lead technical incident response from detection through post-incident review.
- Own vulnerability disclosure and penetration testing programs and drive remediation with product teams.
- Secure internal IT, including endpoint fleets, identity systems, office networks, SSO, MFA, and least privilege.
- Support ISO 27001, SOC 2, and GDPR compliance with technical controls and evidence, as well as customer security reviews.
Requirements
- 7+ years of hands-on security engineering experience, including ownership of application and cloud security for a production SaaS platform.
- Experience building security programs covering the SDLC, vulnerability management, detection, and incident response.
- Expert knowledge of vulnerability classes, attack techniques, threat modeling, and authorization flaws beyond the OWASP Top 10.
- Deep cloud infrastructure security experience at scale, ideally with AWS, including IAM, network segmentation, container security, and security-as-code.
- Strong software engineering skills with experience writing production-quality code and building automation.
- Excellent English and willingness to work on-site 3 days per week in Munich or Berlin.
Nice to have
- Experience building a security function in a scale-up.
- Detection engineering experience.
- ISO 27001 or SOC 2 certification experience.
- OSCP, CISSP, or similar certifications.
- German language skills.
Culture & Benefits
- Employee stock option program.
- €1,000 annual development budget and two Development Days.
- EGYM Wellpass access, lunch subsidy, or mobility budget.
- 20% contribution to the company pension plan in Germany.
- Hybrid work model with three office days and two flexible work-location days.
- Culture Day Off and a diverse, growth-oriented team.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Head of Product Security Engineer (Cybersecurity)
8 часов назад
Application Security Engineer (AWS/Kubernetes)
65 000 - 75 000€
6 дней назад
Staff Security Engineer (GRC)
65 000 - 87 000€
Finoa
6 дней назад
VP Information Security (Cybersecurity)
66 000 - 79 000$
4 дня назад
Deputy CISO - Operational Delivery (Telecom Security)
6 дней назад