Overview
You join Spendesk as the first senior Security Engineer, building a security engineering function from the ground up. You own the technical security roadmap, partner with infrastructure and compliance, and foster a security-aware engineering culture. This is hands-on, with leadership influence and a clear path toward architecture and mentoring as the team grows. You will shape secure-by-default practices and drive incident response, threat modelling, and secure development across squads.
Pay / Benefits
- flexible on-site and remote policy
- latest Apple equipment
- Moka.care for wellbeing
- office snacks
- location-specific benefits (health insurance, wellness allowances, commuter support, meal vouchers, gym memberships)
Responsibilities
- Own and operate the bug bounty program and drive strategic improvements
- Act as escalation point for vulnerability triage and high-severity findings
- Lead security incident response, forensics, fix coordination, post-mortems and remediation tracking
- Own the SIEM platform (ElasticSearch) architecture, detections, and IOCs
- Develop and maintain security runbooks and operational documentation
- Own IAM implementation and operations for product and infra systems including SSO/MFA and secrets rotation
- Embed security into the development lifecycle with threat modelling, secure code patterns, and CI/CD hardening
- Drive security tooling in CI/CD (SAST, SCA, container scanning, AI-risk detection) and scale coverage with growth
- Coordinate penetration tests and security audits, manage auditor relationships and remediation plans
- Coach engineers on secure development, surface risks to leadership, and own the security backlog and roadmap
- Partner with Infrastructure on secure-by-default solutions
Key requirements
- Track record of owning security outcomes end-to-end across at least three areas (code auditing, infrastructure security, pentesting, SIEM, incident response)
- Ability to own a roadmap, prioritize, execute autonomously, and communicate progress to non-specialists
- Deep understanding of modern web architectures (microservices, cloud-native, PaaS/SaaS)
- Strong scripting and automation (Python, Bash, or similar)
- Experience mentoring other engineers or security practitioners
- Excellent communication, able to explain CVSS 9.8 to a PM and drive prioritisation
- mentoring
- clear communication
- cross-functional collaboration
- code auditing
- infrastructure security (AWS/Linux)
- penetration testing
…
