Cloud Security Engineer

Ygo

Deutschland

Hybrid

EUR 85.000 - 125.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Eine vollständige Bewerbung in einer Minute — maßgeschneiderter Lebenslauf und Anschreiben, fertig zum Versenden.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

YGO.ai is a VC‑funded AI tourism platform hiring a Cloud Security Engineer to own the security of our cloud platform, APIs and enterprise client integrations. The role combines hands‑on security engineering with building the security function as we grow, staying close to the work and the clients.

You will review code, investigate alerts, and help design a new authentication flow while prioritizing high‑risk issues. The position emphasizes practical security work over reporting.

Qualifikationen

  • 5+ years of hands‑on security work spanning more than one discipline.
  • Application security depth. You know how modern web applications and APIs are attacked and can validate issues through code review or targeted penetration tests.
  • A strong grasp of authentication and authorization including OAuth and OIDC.
  • Cloud security fundamentals, including identity, networks, and pipelines on a modern cloud platform.
  • Defensive experience alongside the offensive, with incident investigation and improved detection/alerting.
  • Threat modelling and secure architecture for cloud, container and API systems.
  • An engineering background; comfortable reviewing code and building as needed.
  • Comfort in resource‑constrained environments and prioritizing on risk and business impact.

Aufgaben

  • Application security: code and architecture reviews across APIs and backends, targeted pentests, and fixes with engineers.
  • Detection and response: alerting, intrusion detection, incident processes, and on‑call readiness.
  • Cloud and platform hardening: access control, networks, secrets, containers, CI/CD pipelines.
  • Security of APIs: authentication, tenant isolation, token scopes, SSO, audit trails.
  • Security of AI systems: prompt injection, tool permissions, data residency rules.
  • Identity and company security: SSO, MFA, onboarding/offboarding, privileged access.
  • Secure design across pods: threat modelling and design reviews that enable engineers.

Kenntnisse

Security engineering
Application security
Auth & OAuth
Cloud security
Threat modelling
Pen testing
Incident response
SOC2 / ISO27001
Claude Code
Engineering background
Go knowledge
Team leadership
English proficiency
Time zone CET

Jobbeschreibung

YGO.ai is a VC-funded AI tourism platform. We are hiring a Cloud Security Engineer to own the security of our cloud platform, the APIs our enterprise clients run on and the company itself.


About this role. The role carries two things at once. You own security engineering directly and hands‑on. You build the security function around it as we grow. At YGO a pod lead is a squad leader and a spokesperson, close to the work and close to the client, rather than a full‑time manager. You will not stop being an engineer.

The work is broad. You might review source code in the morning, investigate an endpoint alert after lunch and help design a new authentication flow the next day. You identify the highest‑risk problems, decide what happens first and execute.

We serve major travel enterprises and we have enterprise commitments going live from the start of 2027. Security is a condition of that business, not a layer added afterwards.

What you’ll own
  • Application security. Hands‑on code and architecture review across our APIs, backend services and internal tooling. Targeted penetration testing to validate issues yourself. Working with engineers on root causes and practical fixes rather than handing over reports. Vulnerability management and the external penetration tests we commission

  • Detection and response. Knowing we are under attack while it is happening and what happens next. Alerting, intrusion detection, incident process and the on‑call path

  • Cloud and platform hardening. Access control, network boundaries, secrets management, containers and the deployment pipeline. Security through the SDLC: CI/CD, repositories and dependencies

  • The security of our APIs. Authentication and authorization, tenant isolation, token scoping and lifecycle, abuse prevention, enterprise SSO and the audit trail our clients and our own accountability depend on

  • The security of our AI systems. Prompt injection, tool and agent permissions, our MCP server, retrieval and data ingestion. The data‑residency rules we are held to contractually

  • Identity and company security. SSO, MFA and privileged access for employees, onboarding and offboarding, access reviews, MDM, endpoint security and SaaS access. The practical IT security a company our size needs done, not discussed

  • Secure design across the pods. Threat modelling and design review that enables engineers rather than gatekeeping them and raises the standard of what they ship

  • The security function itself. Set the priorities and the roadmap from actual risk, not security theatre. Decide what we build, buy, automate or leave for later. Grow the team and hire into it, represent security to enterprise clients and carry our SOC 2 programme on Drata. Compliance is part of the job and it is not the centre of it

What you’ll secure
  • An AI search and recommendation engine for major travel enterprises: enterprise integration, SSO, client security reviews, GDS integrations

  • A content enrichment API sold as SaaS: high scale, public facing, data and AI heavy

  • The platform underneath: a client console with organisations, projects and API tokens, supplier and business‑client integrations, data ingestion, an MCP server, and several LLM providers behind a single internal library

Our stack
  • Backend: Go monorepo (no framework, 3+ services)

  • Data: PostgreSQL, Redis, Redis Asynq queue

  • Hosting: PaaS‑managed containers, Cloudflare in front

  • Observability: Jaeger tracing, BetterStack for logging, alerting and on‑call

  • Compliance: Drata, SOC 2 in progress

  • AI tooling: Claude Code, used across the whole team

You must have
  • 5+ years of hands‑on security work spanning more than one discipline. Not five years of engineering with some security in it. This role sets the standard for the company, so it needs someone who has seen enough to have judgement rather than opinions

  • Application security depth. You know how modern web applications and APIs are attacked. You can validate an issue yourself through code review or a targeted penetration test and work with the engineer on the fix

  • A strong grasp of authentication and authorization. OAuth and OIDC, sessions, token handling, access control and the failure modes behind most API breaches

  • Cloud security fundamentals, properly. Identity, network, workload and pipeline security on a modern cloud platform, applied to production systems you were responsible for

  • Defensive experience alongside the offensive. You have investigated real incidents. You have built or improved the detection and alerting that catches them

  • Threat modelling and secure architecture for cloud, container and API systems

  • An engineering background. You are comfortable in a codebase, you can review what our engineers and our AI tools produce and you can build what you need yourself. Our backend is Go. Prior Go experience is a plus and not a requirement

  • Comfort in resource‑constrained environments. Startups, small security teams or consultancies taught you to prioritize on risk, business impact and available resources and to execute yourself

  • The appetite to build a team. You want to grow this function and eventually lead it. Prior leadership experience is a plus and not a requirement. We would rather have depth and develop the leadership than the reverse

  • Working proficiency with Claude Code. Share specific examples

  • Judgement about pace. You secure a company that ships daily without becoming the reason it stops. Guardrails over gates

  • Experience of SOC 2, ISO 27001 or demanding enterprise security reviews

  • Excellent spoken and written English. You will talk to auditors, client security teams and our own engineers, often in the same week

  • European or African time zones (±3 hours from CET)

  • Available full‑time (40 hours per week)

Nice to have
  • AI and LLM security: prompt injection, agent and tool permissions, model security, retrieval pipelines. Very few security roles let you both use AI as your main tool and secure it as your subject. This one does

  • Early security hire experience. You have been the first or one of the first security hires at a startup or scale‑up

  • Experience leading or mentoring security engineers

  • Go

  • Security tooling or automation you built yourself

  • MDM, endpoint protection and identity provider administration (Google Workspace or similar)

  • Compliance automation tooling (Drata, Vanta, Secureframe or similar)

  • Security certifications. Valued as a signal, never required

  • GDPR depth. Travel or GDS exposure

  • German

You are a great fit if you
  • See security as an engineering discipline. You ship fixes and guardrails, not slide decks

  • Can explain a vulnerability to an engineer and its business risk to a client's security lead in the same afternoon

  • Have done offensive work as a penetration tester or consultant and wanted broader ownership than producing reports

  • Want to build something and own it, rather than advise on someone else’s

  • Are comfortable challenging unnecessary security bureaucracy and genuinely risky engineering decisions alike

  • Get frustrated when a security fix takes weeks instead of days

Find Jobs in Germany on Arbeitnow

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cloud Security Engineer at YGO GmbH
Cloud Security Engineer at YGO GmbH

YGO GmbH • Deutschland

Vor Ort
EUR 90.000 - 120.000
Lead Security Engineer (m/w/d)
Lead Security Engineer (m/w/d)

Recare Deutschland GmbH • Berlin

Hybrid
EUR 90.000 - 130.000
Remote-friendly
Flexible hours
Edenred card
+2
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

Yoummday GmbH • München

Hybrid
EUR 90.000 - 130.000
30 days vacation
Job lunch allowance (€69/mo)
Givve card (€50/mo)
+5
DevOps Engineer
DevOps Engineer

Eurobase People • Berlin

Hybrid
EUR 70.000 - 90.000
Security Engineer (m/f/d)
Security Engineer (m/f/d)

Security Research Labs • Berlin

Hybrid
EUR 55.000 - 90.000
Gym discounts
Public transport pass
German lessons
+5
Founding Engineering Team Lead (HandsOn) arbeitnow TechBiz Global GmbH Berlin, Berlin, Germany · 9/22/2026
Founding Engineering Team Lead (HandsOn) arbeitnow TechBiz Global GmbH Berlin, Berlin, Germany · 9/22/2026

Primetime • Berlin

Hybrid
EUR 110.000 - 180.000
Founding Team Member Equity
Competitive Compensation
Founding Team Member Status
+5
Senior Security Engineer (all genders)
Senior Security Engineer (all genders)

Capmo • München

Vor Ort
EUR 120.000 - 160.000
Employee stock option program (VSOP)
Annual development budget
Wellness/mobility budget with EGYMWell
+3
Senior Security Engineer
Senior Security Engineer

United States Digital Space LLC • Berlin, München

Vor Ort
EUR 90.000 - 125.000
Relocation support
Learning allowance
Health & wellness
+3
Founding Engineering Team Lead (HandsOn)
Founding Engineering Team Lead (HandsOn)

Cygrid • Berlin

Hybrid
EUR 120.000 - 180.000
Founding equity
Competitive compensation
Founding team status
+1
Founding Engineering Team Lead (HandsOn)
Founding Engineering Team Lead (HandsOn)

Cygrid GmbH • Berlin

Hybrid
Confidential
Founding Team Member Equity
Competitive Compensation
High Autonomy
+1