Product & AI Security Engineer

RxREVU, Inc.

Berlin

Vor Ort

EUR 90.000 - 130.000

Vollzeit

Vor 3 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine zielgenaue Bewerbung für diesen Job — ein maßgeschneiderter Lebenslauf und ein Anschreiben, die genau zur Stellenanzeige passen.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

30 days annual leave
Home office setup budget
Work abroad up to 90 days
Mental health support
Pension contributions subsidy
BVG public transport subsidy
Dog-friendly Berlin office
Bike through BusinessBike

Zusammenfassung

Talon.One is hiring one of its first two security engineers to own the security of all product features, from API authorization to AI-driven components. Based in Berlin and operating in a hybrid model, you’ll collaborate directly with engineers and product managers across a multi-tenant platform serving major brands.

You’ll drive threat modelling, API security design, and automated testing in CI, while building in-house monitoring and runbooks.

Qualifikationen

  • Experience shipping production code in either software or security domains.
  • Experience with a multi-tenant SaaS platform's authorization and tenant isolation models.
  • Design API security end-to-end: authentication, credential lifecycle, rate limiting, and webhook security.
  • Knowledge of threat-modelling methodologies (e.g., STRIDE) and turning threats into tests.
  • Experience with SAST/DAST in CI/CD with actionable developer feedback.
  • Understanding AI feature build processes (retrieval, context assembly, tool calling, agent loops).
  • Hands-on with Google Cloud, Kubernetes, Wiz, and Datadog.

Aufgaben

  • Threat-model new product features and translate findings into engineering work.
  • Own tenant isolation and API security across core components and integrations.
  • Act as security design authority for AI features and cross-team coordination.
  • Build automated cross-tenant and adversarial tests in CI to ensure isolation.
  • Create frictionless automation for security checks within CI workflows.
  • Run vulnerability coordination and patch response across squads.
  • Build and own in-house security monitoring and real-time detections.
  • Design security for API integrations between Talon.One and partners.
  • Run a security champions program to spread capability across tribes.
  • Experiment with AI to identify and remediate security risks at scale.

Kenntnisse

Production code
Multi-tenant SaaS security
API security
Threat modelling
CI/CD security checks
Security monitoring
AI security
Cloud security (GCP)
Kubernetes
Wiz / Datadog

Tools

Google Cloud Security (GCP)
Kubernetes
Wiz
Datadog

Jobbeschreibung

ABOUT THE ROLE:

You'll be one of Talon.One's first two security engineering hires, owning the security of everything we ship to our customers and third-party partners, from API authorization to the AI features going into our platform and their real-time observability and detections. You'll work hands-on, pairing directly with engineers and product managers rather than filing tickets, across a multi-tenant platform that powers promotions and loyalty for some of Europe's largest retail and travel brands. Based in Berlin, hybrid.

ONCE YOU ARE HERE YOU WILL:
  • Threat-model new product features before they're built, including AI-embedded ones, and turn what you find into real engineering work
  • Own tenant isolation and API security across our Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP and third-party integrations
  • Act as the security design authority for our AI features, working closely with the team behind UCP and Predict
  • Build automated cross-tenant and adversarial testing that runs in CI, so isolation gets checked on every build, not only during our external yearly Pentest iterations
  • Build standard, frictionless and automated golden paths for code security checks in CI workflows that developers can adopt by default without slowing down delivery
  • Run vulnerability and coordinate efficient patch response across every squad outside Platform, from automated dependency updates to drilled emergency response
  • Build and own application and AI security monitoring with our observability tools and build real-time security detection rules and alerts, and security events runbooks
  • Design the security of the API integration between Talon.One and Adyen as our products come together
  • Run a security champions programme so all our tribes build real security capability, not just the security team
  • Experiment with AI, leverage innovative ways and build new workflows to identify, prioritize, and remediate product security risks at scale.
WHAT WE NEED YOU TO BRING TO THE TABLE:
  • Experience with shipping production code, whether you come from software engineering or from security work that includes coding
  • Experience with a multi-tenant SaaS platform's authorization and tenant isolation model, and strong knowledge of how to test for broken object-level authorization automatically
  • Design API security end-to-end: authentication, credential lifecycle, rate limiting, abuse resistance and webhook security
  • Hands-on experience with threat-modelling methodologies such as STRIDE, translating identified threats into actionable engineering requirements and security tests
  • Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows, with a focus on useful developer feedback and effective vulnerability remediation
  • Understanding how AI features actually get built, retrieval, context assembly, tool calling, agent loops, and know where indirect prompt injection breaks multi-tenant isolation
  • Hands-on experience with Google Cloud security, Kubernetes, and tools like Wiz and Datadog
  • Know how to build security monitoring and detections in-house tools (SIEM) yourself, from designing the signal through tuning it and writing the runbook
  • Strong knowledge of OWASP security guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications
  • Ability to influence engineers who don't report to you, and feel comfortable being early in a function with no existing playbook
WHAT'S IN IT FOR YOU:
  • 90+ team of engineers, product managers and product designers in Berlin
  • Leaders with 8+ years of experience building our promotions engine
  • 1,000 annual learning budget and free German language courses to boost your skills
  • 30 days of annual leave, plus extra paid days for your birthday and moving day
  • Home office setup budget, a monthly home office allowance
  • Freedom to work from abroad for up to 90 days worldwide!
  • Mental health support with nilo.health and a discounted Urban Sports Club membership
  • 20% company subsidy on your pension contributions
  • Subsidised BVG public transport ticket and a dog-friendly Berlin office where your furry friend is welcome
  • Lease your ideal bike through BusinessBike
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Product & AI Security Engineer
Product & AI Security Engineer

Talon.One • Berlin

Hybrid
EUR 90.000 - 130.000
€1,000 annual learning budget
30 days annual leave
Home office setup budget
+1
Product & AI Security Engineer
Product & AI Security Engineer

DUDE CHEM • Berlin

Hybrid
EUR 90.000 - 130.000
Learning budget
Language courses
30 days vacation
+9
Senior MLOps Engineer
Senior MLOps Engineer

Talon.One • Berlin

Vor Ort
EUR 70.000 - 90.000
€1,000 annual learning budget
30 days of annual leave
Home office setup budget
+3
Senior Backend Engineer - Go
Senior Backend Engineer - Go

Talon.One • Berlin

Vor Ort
EUR 60.000 - 80.000
€1,000 annual learning budget
30 days of annual leave
Home office setup budget
+5
Senior Backend Engineer - Go
Senior Backend Engineer - Go

RxREVU, Inc. • Berlin

Vor Ort
EUR 90.000 - 130.000
Learning budget
Language courses
30 days annual leave
+4
QA Engineer (Mid/Senior)
QA Engineer (Mid/Senior)

Talon.One • Berlin

Vor Ort
EUR 60.000 - 90.000
Learning budget
Language courses
30 days annual leave
+8
Senior Backend Engineer
Senior Backend Engineer

RxREVU, Inc. • Berlin

Vor Ort
EUR 120.000 - 160.000
Annual learning budget
30 days annual leave
Home office setup budget
+3
Application Security Engineer (m/f/d)
Application Security Engineer (m/f/d)

EGYM | DACH • Berlin

Vor Ort
EUR 90.000 - 130.000
30 days vacation
Home office possibilities
Flexible working hours
+3
Enterprise Technical Account Manager, EMEA
Enterprise Technical Account Manager, EMEA

Talon.One • Berlin

Hybrid
EUR 60.000 - 80.000
€1,000 annual learning budget
30 days annual leave plus extra
Home office setup budget
+3
QA Engineer (Mid/Senior)
QA Engineer (Mid/Senior)

RxREVU, Inc. • Berlin

Vor Ort
EUR 65.000 - 90.000
Learning budget
Home office budget
Home office allowance
+7