Назад
Company hidden
4 часа назад

Senior Security Engineer (SaaS)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Germany
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer (SaaS): Owning product, cloud, internal IT, detection, response, and compliance security for a production B2B SaaS platform with an accent on AWS hardening, secure development, and vulnerability management. Focus on building detection and response capabilities, leading incident containment, encoding infrastructure baselines as policy-as-code, and driving remediation with product teams.

Location: Munich or Berlin, Germany. Hybrid work with 3 days on-site in the office and 2 days flexible.

Company

hirify.global provides a B2B SaaS platform that helps construction professionals collaborate and manage construction projects efficiently.

What you will do

  • Own product and cloud security end to end, including threat modeling, security reviews, secure-by-default patterns, and CI/CD security tooling.
  • Harden AWS infrastructure through IAM architecture, network segmentation, encryption, logging, workload security, and policy-as-code.
  • Build detection and response capabilities and lead technical incident response from detection through post-incident review.
  • Own vulnerability disclosure and penetration testing programs and drive remediation with product teams.
  • Secure internal IT, including endpoint fleets, identity systems, office networks, SSO, MFA, and least privilege.
  • Support ISO 27001, SOC 2, and GDPR compliance with technical controls and evidence, as well as customer security reviews.

Requirements

  • 7+ years of hands-on security engineering experience, including ownership of application and cloud security for a production SaaS platform.
  • Experience building security programs covering the SDLC, vulnerability management, detection, and incident response.
  • Expert knowledge of vulnerability classes, attack techniques, threat modeling, and authorization flaws beyond the OWASP Top 10.
  • Deep cloud infrastructure security experience at scale, ideally with AWS, including IAM, network segmentation, container security, and security-as-code.
  • Strong software engineering skills with experience writing production-quality code and building automation.
  • Excellent English and willingness to work on-site 3 days per week in Munich or Berlin.

Nice to have

  • Experience building a security function in a scale-up.
  • Detection engineering experience.
  • ISO 27001 or SOC 2 certification experience.
  • OSCP, CISSP, or similar certifications.
  • German language skills.

Culture & Benefits

  • Employee stock option program.
  • €1,000 annual development budget and two Development Days.
  • EGYM Wellpass access, lunch subsidy, or mobility budget.
  • 20% contribution to the company pension plan in Germany.
  • Hybrid work model with three office days and two flexible work-location days.
  • Culture Day Off and a diverse, growth-oriented team.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →