DevSecOps Engineer
<div class="show-more-less-html__markup show-more-less-html__markup--clamp-after-5 relative overflow-hidden"> <p><strong>Senior Security / DevSecOps Engineer </strong></p><p>We are building a fast-moving product engineering team focused on shipping secure, scalable systems in a high-velocity environment. Security is not a support function here, it is a core part of the product architecture and delivery lifecycle.</p><p><br/></p><p>We are currently looking for a <strong>Senior Security / DevSecOps Engineer</strong> to take ownership of designing and scaling security across backend systems, infrastructure, and deployment pipelines.</p><p>This is a high-impact role with significant autonomy, working closely with engineering leadership to shape how security is implemented across the entire stack.</p><p><br/></p><p>What you will work on</p><p>You will take ownership of security across modern cloud-based systems, including:</p><ul><li>Designing and implementing secure backend and cloud architecture</li><li>Strengthening IAM, authentication, authorization, and access control systems</li><li>Building and improving CI/CD security and deployment safety</li><li>Leading threat modeling and secure design reviews for new features</li><li>Embedding security into the SDLC (not bolted on afterwards)</li><li>Working with containerised infrastructure (Docker/Kubernetes environments)</li><li>Implementing secrets management and encryption strategies</li><li>Reducing vulnerabilities through proactive security engineering</li><li>Supporting secure and rapid product shipping at scale</li></ul><p><br/></p><p>What we are looking for</p><p>You are likely a strong fit if you have:</p><ul><li>5+ years in software engineering, infrastructure, or security-focused roles</li><li>Deep experience in cloud environments (AWS preferred)</li><li>Strong understanding of IAM, network security, and access control systems</li><li>Hands-on experience with secure backend/API design</li><li>Familiarity with OWASP Top 10, threat modeling, and secure SDLC practices</li></ul><p>Experience with security tooling, such as:</p><ul><li>Semgrep / CodeQL / Snyk / Burp Suite (or similar)</li><li>Experience securing CI/CD pipelines and containerised systems</li><li>Strong backend engineering skills (Python, Go, Java, or similar)</li><li>A mindset for ownership, autonomy, and driving initiatives end-to-end</li></ul><p><br/></p><p>What makes this role different</p><ul><li>You will own security decisions, not just execute tickets</li><li>Security is embedded into product development, not a downstream function</li><li>You will help shape how a modern engineering organisation builds securely from the ground up</li><li>High autonomy, fast execution, and real product impact</li><li>Opportunity to influence architecture, tooling, and engineering culture</li></ul><p><br/></p><p>Ideal mindset</p><p>We are especially interested in people who:</p><ul><li>Take full ownership of systems end-to-end</li><li>Enjoy building structure in fast-moving environments</li><li>Can balance security rigor with shipping velocity</li><li>Think in systems, not just vulnerabilities</li><li>Prefer impact over process-heavy environments</li></ul><p><br/></p><p>Location & working model</p><ul><li>Ideally based in Berlin (hybrid)</li><li>Remote work within Germany is also considered</li><li>Hybrid expectation: occasional in-person time every few weeks (travel supported)</li></ul><p><br/></p><p>Interview process</p><ul><li>Intro call (role + technical alignment)</li><li>Hands-on coding exercise (practical engineering problem-solving)</li><li>Technical design discussion (security + system design focus)</li><li>Culture & collaboration interview</li><li>Final product/project deep dive with engineering leadership</li><li>Founder-level conversation on vision and long-term scope</li></ul><p><br/></p> </div>