TU PRÓXIMO CAPÍTULO
Senior Security Engineer
Sobre el puesto
• Own infrastructure vulnerability management, including a central register, risk-based SLAs, exception handling, closure tracking, and reporting
• Prioritize infrastructure remediation using contextual risk signals such as KEV, EPSS, exposure, asset criticality, and compensating controls
• Automate scanner integrations, finding pipelines, normalization, ticket routing, and reporting
• Contribute to shared security finding workflows
• Build security logging coverage and retention across production, cloud, and identity systems
• Select and operate a managed detection and response partner
• Lead cloud security posture management with the platform team, including account guardrails, hardening baselines, CSPM triage, internet-facing surface inventory, and image/container security
• Coordinate security incident response, runbooks, tabletop exercises, and post-incident corrective actions
• Partner with Product Security on product-security vulnerabilities and customer-facing product risk
• Partner with product, platform engineering, and IT on remediation
• Provide technical evidence for SOC 2, PCI DSS, and customer due diligence obligations
• Collaborate with Product & Platform teams and support customer-facing security discussions
• Help maintain and operationalize the Internal AI Use Policy and application
• Secure internal AI tooling and agentic workflows, including data access, identity, credentials, tool permissions, logging, and detection of inappropriate behavior
• Make agentic workflows auditable
• 8+ years in security engineering, with depth in vulnerability management, cloud security posture, detection, or incident response
• Experience with AWS and Kubernetes
• Ability to reason about infrastructure as code
• Expertise with security logging and SIEM-class tooling
• Experience working through a managed detection provider
• Hands-on experience running infrastructure vulnerability management at scale across fleets, images, containers, and dependencies
• Experience prioritizing remediation using KEV, EPSS, exposure, asset criticality, and compensating controls
• Experience driving remediation through system-owning teams
• Experience with SOC 2 and/or PCI DSS technical controls
• Experience securing payments or regulated fintech systems
• Detection engineering, threat modeling, or DFIR experience
• Exposure to EU regulatory obligations including GDPR Art. 33/34 and the Cyber Resilience Act, and ISO27001
• Experience in a product company scaling from mid-market to enterprise customers
• Competitive salary
• Generous "Time to Recharge" policy with unlimited paid time off
• Work From Anywhere perk: up to four weeks per calendar year to work temporarily from another approved location
• 2-week cross-functional onboarding program
• Annual team off-site
• Cycle-to-work scheme (Swapfiets subscription) or commuting reimbursement
• Extensive paid family leave
• Three paid volunteer days per year
• Cutting-edge equipment and tools
• International, travel-loving team