Product & AI Security Engineer

Talon.One

Berlin

Hybrid

EUR 90.000 - 130.000

Vollzeit

Vor 2 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

€1,000 annual learning budget
30 days annual leave
Home office setup budget
Berlin office with hybrid flexibility

Zusammenfassung

Talon.One is seeking a Security Engineer in Berlin to own the security of all shipped features. You will work hands-on with engineers and product managers to secure multi-tenant SaaS features, including API authorization, AI components, and real-time detection across the platform.

You will model threats, define secure CI processes, and drive cross-squad security improvements while collaborating with business teams in a dynamic, hybrid Berlin setting.

Qualifikationen

  • Experience shipping production code in a software or security role.
  • Experience with multi-tenant SaaS authorization and tenant isolation.
  • Design API security end-to-end: authentication, credential lifecycle, rate limiting, webhook security.
  • Hands-on threat modelling using STRIDE; translate identified threats into actionable engineering requirements.
  • Practical experience implementing and tuning SAST and DAST tools in CI/CD pipelines.
  • Understanding how AI features are built, retrieval, context assembly, tool calling, and prompt injection risks.
  • Hands-on experience with Google Cloud security, Kubernetes, Wiz and Datadog.
  • Strong knowledge of OWASP security guidance, including Top 10 and API Top 10.
  • Ability to influence engineers in early-stage teams.

Aufgaben

  • Threat-model new product features before they're built and translate findings into engineering work.
  • Own tenant isolation and API security across core components and integrations.
  • Act as security design authority for AI features and related tools.
  • Build automated cross-tenant and adversarial testing in CI to ensure isolation on every build.
  • Develop automated secure CI workflows and runbooks for developers.
  • Lead vulnerability management and coordinate patch responses across squads.
  • Build and own security monitoring with observability tooling and real-time alerts.

Kenntnisse

Production code shipping
Tenant isolation & API security
Threat modelling STRIDE
CI/CD SAST/DAST integration
AI security design
Google Cloud security
Kubernetes
OWASP Top 10 & API Top 10
Security monitoring / SIEM
Influencing engineers

Tools

Google Cloud
Kubernetes
Wiz
Datadog
SIEM tooling

Jobbeschreibung

Talon.One is the most powerful incentives engine that unifies loyalty, promotions and gamification into one holistic platform.Backed by enterprise-grade security and scalability, Talon.One empowers companies to build personalized, profitable promotions and loyalty programs using any data.

Today, over 250 of the world’s most-loved brands including Adidas, Sephora and Carlsberg work with Talon.One to drive deeper engagement and lasting loyalty with their customers.

ABOUT THE ROLE:

You'll be one of Talon.One's first two security engineering hires, owning the security of everything we ship to our customers and third-party partners, from API authorization to the AI features going into our platform and their real-time observability and detections. You'll work hands-on, pairing directly with engineers and product managers rather than filing tickets, across a multi-tenant platform that powers promotions and loyalty for some of Europe's largest retail and travel brands. Based in Berlin, hybrid.

ONCE YOU ARE HERE YOU WILL:
  • Threat-model new product features before they're built, including AI-embedded ones, and turn what you find into real engineering work
  • Own tenant isolation and API security across our Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP and third‑party integrations
  • Act as the security design authority for our AI features, working closely with the team behind UCP and Predict
  • Build automated cross‑tenant and adversarial testing that runs in CI, so isolation gets checked on every build, not only during our external yearly Pentest iterations
  • Build standard, frictionless and automated golden paths for code security checks in CI workflows that developers can adopt by default without slowing down delivery
  • Run vulnerability and coordinate efficient patch response across every squad outside Platform, from automated dependency updates to drilled emergency response
  • Build and own application and AI security monitoring with our observability tools and build real‑time security detection rules and alerts, and security events runbooks
  • Design the security of the API integration between Talon.One and Adyen as our products come together
  • Run a security champions programme so all our tribes build real security capability, not just the security team
  • Experiment with AI, leverage innovative ways and build new workflows to identify, prioritize, and remediate product security risks at scale.
WHAT WE NEED YOU TO BRING TO THE TABLE:
  • Experience with shipping production code, whether you come from software engineering or from security work that includes coding
  • Experience with a multi‑tenant SaaS platform's authorization and tenant isolation model, and strong knowledge of how to test for broken object‑level authorization automatically
  • Design API security end‑to‑end: authentication, credential lifecycle, rate limiting, abuse resistance and webhook security
  • Hands‑on experience with threat‑modelling methodologies such as STRIDE, translating identified threats into actionable engineering requirements and security tests
  • Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows, with a focus on useful developer feedback and effective vulnerability remediation
  • Understanding how AI features actually get built, retrieval, context assembly, tool calling, agent loops, and know where indirect prompt injection breaks multi‑tenant isolation
  • Hands‑on experience with Google Cloud security, Kubernetes, and tools like Wiz and Datadog
  • Know how to build security monitoring and detections in‑house tools (SIEM) yourself, from designing the signal through tuning it and writing the runbook
  • Strong knowledge of OWASP security guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications
  • Ability to influence engineers who don't report to you, and feel comfortable being early in a function with no existing playbook
ABOUT TALON.ONE:

Talon.One is the most powerful incentives engine that unifies loyalty, promotions and gamification into one holistic platform.Backed by enterprise-grade security and scalability, Talon.One empowers companies to build personalized, profitable promotions and loyalty programs using any data.

Today, over 250 of the world’s most-loved brands including Adidas, Sephora and Carlsberg work with Talon.One to drive deeper engagement and lasting loyalty with their customers.

ABOUT THE ROLE:

You'll be one of Talon.One's first two security engineering hires, owning the security of everything we ship to our customers and third-party partners, from API authorization to the AI features going into our platform and their real‑time observability and detections. You'll work hands‑on, pairing directly with engineers and product managers rather than filing tickets, across a multi‑tenant platform that powers promotions and loyalty for some of Europe's largest retail and travel brands. Based in Berlin, hybrid.

ONCE YOU ARE HERE YOU WILL:
  • Threat-model new product features before they're built, including AI-embedded ones, and turn what you find into real engineering work
  • Own tenant isolation and API security across our Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP and third‑party integrations
  • Act as the security design authority for our AI features, working closely with the team behind UCP and Predict
  • Build automated cross‑tenant and adversarial testing that runs in CI, so isolation gets checked on every build, not only during our external yearly Pentest iterations
  • Build standard, frictionless and automated golden paths for code security checks in CI workflows that developers can adopt by default without slowing down delivery
  • Run vulnerability and coordinate efficient patch response across every squad outside Platform, from automated dependency updates to drilled emergency response
  • Build and own application and AI security monitoring with our observability tools and build real‑time security detection rules and alerts, and security events runbooks
  • Design the security of the API integration between Talon.One and Adyen as our products come together
  • Run a security champions programme so all our tribes build real security capability, not just the security team
  • Experiment with AI, leverage innovative ways and build new workflows to identify, prioritize, and remediate product security risks at scale.
WHAT WE NEED YOU TO BRING TO THE TABLE:
  • Experience with shipping production code, whether you come from software engineering or from security work that includes coding
  • Experience with a multi‑tenant SaaS platform's authorization and tenant isolation model, and strong knowledge of how to test for broken object‑level authorization automatically
  • Design API security end‑to‑end: authentication, credential lifecycle, rate limiting, abuse resistance and webhook security
  • Hands‑on experience with threat‑modelling methodologies such as STRIDE, translating identified threats into actionable engineering requirements and security tests
  • Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows, with a focus on useful developer feedback and effective vulnerability remediation
  • Understanding how AI features actually get built, retrieval, context assembly, tool calling, agent loops, and know where indirect prompt injection breaks multi‑tenant isolation
  • Hands‑on experience with Google Cloud security, Kubernetes, and tools like Wiz and Datadog
  • Know how to build security monitoring and detections in‑house tools (SIEM) yourself, from designing the signal through tuning it and writing the runbook
  • Strong knowledge of OWASP security guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications
  • Ability to influence engineers who don't report to you, and feel comfortable being early in a function with no existing playbook
WHAT'S IN IT FOR YOU:
  • 90+ team of engineers, product managers and product designers in Berlin
  • Leaders with 8+ years of experience building our promotions engine
  • €1,000 annual learning budget and free German language courses to boost your skills
  • 30 days of annual leave, plus extra paid days for your birthday and moving day
  • Home office setup budget, a monthly home office allowance
  • Freedom to work from abroad for up to 90 days worldwide!
  • Mental health support with nilo.health and a discounted Urban Sports Club membership
  • 20% company subsidy on your pension contributions
  • Subsidised BVG public transport ticket and a dog‑friendly Berlin office where your furry friend is welcome
  • Lease your ideal bike through BusinessBike
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Product & AI Security Engineer
Product & AI Security Engineer

linkedinjobs • Berlin

Hybrid
EUR 90.000 - 140.000
Annual learning budget
Language courses
30 days annual leave
+3
Product & AI Security Engineer
Product & AI Security Engineer

Talon.One LinkedIn Jobs • Berlin

Hybrid
EUR 90.000 - 130.000
Annual learning budget €1,000
German language courses
30 days annual leave
+8
Product & AI Security Engineer
Product & AI Security Engineer

DUDE CHEM • Berlin

Hybrid
EUR 90.000 - 130.000
Learning budget
Language courses
30 days vacation
+9
Senior MLOps Engineer
Senior MLOps Engineer

Talon.One • Berlin

Vor Ort
EUR 70.000 - 90.000
€1,000 annual learning budget
30 days of annual leave
Home office setup budget
+3
Senior Backend Engineer - Go
Senior Backend Engineer - Go

Talon.One • Berlin

Vor Ort
EUR 60.000 - 80.000
€1,000 annual learning budget
30 days of annual leave
Home office setup budget
+5
Documentation Engineer
Documentation Engineer

Talon.One • Berlin

Hybrid
EUR 70.000 - 90.000
Learning budget €1,000 annually
30 days annual leave
Home office setup budget
+3
Enterprise Technical Account Manager, EMEA
Enterprise Technical Account Manager, EMEA

Talon.One • Berlin

Hybrid
EUR 60.000 - 80.000
€1,000 annual learning budget
30 days annual leave plus extra
Home office setup budget
+3
Sales Training & Enablement Manager
Sales Training & Enablement Manager

Talon.One • Berlin

Vor Ort
EUR 60.000 - 90.000
€1,000 annual learning budget
30 days of annual leave
Home office setup budget
+5
Campaign Manager
Campaign Manager

Talon.One • Berlin

Vor Ort
EUR 50.000 - 80.000
€1,000 annual learning budget
30 days of annual leave
Home office setup budget
+5
Technical Product Manager, Production Engineering
Technical Product Manager, Production Engineering

DUDE CHEM • Berlin

Hybrid
EUR 90.000 - 140.000
Annual learning budget
30 days annual leave
Home office budget
+1