Senior Security Engineer
Owns security architecture and enforcement across Linux, cloud, Kubernetes, CI/CD, and AI infrastructure. The role requires 5+ years of security engineering experience, strong identity and access expertise, and hands-on knowledge of Terraform, SIEM, containers, and cloud-native security.
About the job
Responsibilities
- Own security architecture and enforcement across infrastructure.
- Secure, harden, and monitor Linux infrastructure and container runtimes.
- Deploy, tune, and manage SIEM, file integrity monitoring, and host-based intrusion detection across the fleet.
- Design and enforce secure identity and access patterns, eliminating shared accounts, long-lived credentials, and excessive permissions.
- Own cloud security posture and implement secure infrastructure-as-code practices with Terraform and Terraform Workflow.
- Establish infrastructure-level security guardrails for AI and agentic systems, including tool permission boundaries, secrets-exposure prevention, data-egress controls, audit logging, approval workflows, and prompt-injection protections.
- Protect production deployment paths against supply-chain attacks.
- Build and maintain automated policy-as-code controls across Terraform, Terraform Workflow, Git repositories, and CI/CD workflows.
- Drive CVE response and vulnerability remediation across infrastructure.
- Own external security reports, responsible disclosures, incident response, and audits.
- Partner with Platform Engineering on Kubernetes, container, and runtime security, including image hardening, runtime detection, network policies, workload identity, and secure container build standards.
- Work with engineering teams to eliminate security threats.
Requirements
- Bachelor’s degree in Computer Science, Cyber Security, or a similar technical field, or equivalent practical experience.
- 5+ years of experience in a cyber security-focused Security Engineer role.
- Extensive experience securing, hardening, and operating Linux-based infrastructure and containerized environments.
- Experience securing Kubernetes or similar orchestration platforms, container images, runtime behavior, service mesh or network policies, and workload identity patterns.
- Strong understanding of SSO, MFA/passkeys, RBAC, just-in-time access, privileged access management, OIDC federation, and eliminating static credentials.
- Ability to translate security requirements into automated controls.
- Hands-on experience configuring and maintaining SIEM for centralized logging, vulnerability detection, and active response.
- Experience architecting security in mainstream cloud environments.
- Deep familiarity with Terraform, Ansible, and Git.
- Practical understanding of LLM and agentic AI risks, including prompt injection, excessive agency, tool abuse, data leakage, insecure plugin or tool integrations, and secure approval boundaries.
- Ability to define security metrics, drive remediation across teams, prioritize risk pragmatically, and communicate trade-offs to engineering leaders.
- Pragmatic focus on automated guardrails, robust monitoring, and secure default paths.
Benefits and Compensation
- Flexible working hours.
- 3–4 additional days off per year to celebrate company successes.
- Learning and development opportunities.
- Annual performance- and company-success-based bonuses.
- Choice of Mac or PC hardware.
- Competitive benefits package for Europe, including a competitive base salary, performance-based bonus, comprehensive medical insurance, flexible PTO, flexible work options, professional development reimbursement, and parental leave.
Skills
Linux, Kubernetes, Terraform, Terraform Workflow, Ansible, Git, SIEM, Hids, RBAC, OIDC, MFA, Cloud Security, Container Security, CI/CD, Policy As Code
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Build and automate technical security controls, compliance workflows, and audit evidence for enterprise readiness. The role requires strong scripting or programming skills, security fundamentals, and the ability to collaborate across engineering, security, legal, and customer-facing teams.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.