Назад
Company hidden
2 месяца назад

Product & AI Security Engineer

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Germany
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product & AI Security Engineer (SaaS/API Security): Owning product and AI security for a multi-tenant promotions and loyalty platform with an accent on tenant isolation, API authorization, threat modeling, and real-time detection. Focus on building automated cross-tenant testing, CI security workflows, AI security controls, and monitoring for complex product integrations.

Location: Berlin, hybrid

Company

hirify.global builds a flexible, highly scalable promotions and loyalty platform for major retail and travel brands.

What you will do

  • Threat-model product and AI features before implementation and translate findings into engineering requirements and security tests.
  • Own tenant isolation and API security across the Rule Engine, Integration API, Management API, CAMA, UCP Predict, hirify.global MCP, and third-party integrations.
  • Build automated cross-tenant, adversarial, SAST, and DAST testing and establish secure CI/CD golden paths.
  • Coordinate vulnerability remediation and emergency patch response across engineering squads.
  • Build application and AI security monitoring, real-time detections, alerts, and security event runbooks.
  • Design the hirify.global–Adyen API integration security model and run the security champions programme.

Requirements

  • Experience shipping production code through software engineering or hands-on security engineering.
  • Experience securing multi-tenant SaaS authorization and tenant isolation, including automated testing for broken object-level authorization.
  • Strong knowledge of API authentication, credential lifecycle, rate limiting, abuse resistance, and webhook security.
  • Hands-on experience with STRIDE or similar threat-modeling methods, SAST and DAST in CI/CD, and vulnerability remediation.
  • Understanding of AI feature architecture, including retrieval, context assembly, tool calling, agent loops, and indirect prompt injection risks.
  • Experience with Google Cloud security, Kubernetes, Wiz, Datadog, in-house SIEM monitoring, OWASP guidance, and influencing engineers without direct authority.

Culture & Benefits

  • International, diverse, collaborative, and family-friendly working environment.
  • €1,000 annual learning budget and free German language courses.
  • 30 days of annual leave, plus paid birthday and moving days.
  • Home-office setup budget, monthly home-office allowance, and freedom to work abroad for up to 90 days worldwide.
  • Mental health support, discounted Urban Sports Club membership, and a 20% pension contribution subsidy.
  • Subsidised BVG ticket, dog-friendly Berlin office, and BusinessBike leasing.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →