Security Engineering Lead (m/f/d)

Upvest

Berlin

Vor Ort

EUR 80.000 - 110.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

30 days of annual leave
Remote work flexibility for up to 183 days a year
Sabbatical after 4 years

Zusammenfassung

Upvest in Berlin is looking for a Security Engineering Lead to spearhead their security initiatives across application and cloud environments. This role requires 6–10 years in security engineering, focusing on product security, and involves leading a talented team while collaborating on security practices integrated into the development lifecycle. The position offers a dynamic work environment with a focus on innovation and regulatory compliance. Flexible working and comprehensive benefits are provided, making it an ideal opportunity for security professionals aiming to make a meaningful impact.

Qualifikationen

  • 6–10 years in security engineering with 4+ years focused on product/cloud security.
  • Hands-on experience with threat modeling and secure coding practices.
  • Experience leading security initiatives in a regulated environment.

Aufgaben

  • Set multi-quarter strategy for application and cloud security.
  • Lead and grow the Security Engineering team.
  • Own application security end-to-end including threat modeling and vulnerability management.
  • Drive cloud security improvements across GCP.

Kenntnisse

Security Engineering
Cloud Security
Product Security
Technical Communication

Ausbildung

Bachelor's or Master's degree in Computer Science or related field

Tools

GCP
Terraform
Kubernetes

Jobbeschreibung

Why this role exists

Upvest is at the inflection point where security needs to scale and remain a foundational discipline of the company. We're hiring a Security Engineering Lead to step into our lean and efficient Security team, set its multi‑quarter direction, work cross‑functionally and scale Security Engineering into a team that continues to own Upvest's entire application security and cloud security posture in a highly regulated environment as it scales.

This role sits alongside our Security Operations and GRC teams, which own detection, response, and compliance operations. Where SecOps keeps watch over what's happening now, Security Engineering shapes what we build and how we build it, embedding security into the SDLC, hardening our cloud environment, and building the platforms that make security teams more effective.

You will own the secure paved roads every Upvest engineer relies on: automated SAST/DAST/SCA in our GitHub Actions pipelines, SSDLC adherence, IAM and network controls, and the technical implementation of DORA's (and other regulations') ICT risk framework for our platform.

Our mission for the team is simple: make the secure way the easy way for everyone at Upvest.

What you’ll do:
  • Set the multi‑quarter strategy for application and cloud security across Upvest's Investment API platform — aligned with our product roadmap, our tenant commitments, and our regulatory obligations under DORA, MiFID II, and BaFin's MaRisk / BAIT requirements.
  • Lead, mentor, and grow our Security Engineering and Upvest's security culture. You'll inherit a small, talented team and own hiring, onboarding, growth, and retention as we scale. And you'll create initiatives to build security into the development and product life cycle.
  • Build paved roads. Own how Upvest performs encryption, authN/authZ, CI/CD, data, and network surfaces. We want fewer security review queues and more security baked into the templates.
  • Own application security end‑to‑end. Threat modeling, secure code review, SAST/DAST/SCA tooling integration in our GitHub Actions CI/CD, and vulnerability management.
  • Drive better cloud security posture across our GCP environment — IAM, VPC Service Controls, Cloud KMS, CSPM (Wiz), Binary Authorization for GKE, Terraform‑driven infrastructure security baselines, and our Linkerd service mesh posture.
  • Mature Upvest's DORA technical implementation. Partner with our risk and compliance functions to translate DORA's ICT risk framework (Art. 5–9), secure development testing requirements (Art. 16), and threat‑led penetration testing (Art. 24–27) into engineering work programmes — and into evidence we can show auditors and regulators.
  • Embed security in every product design. Partner deeply with product and engineering teams. Architecture reviews, design partnerships, security champions across product squads, collaboration beats gatekeeping.
  • Stay current on emerging threats. AI / LLM security, agentic identities, and the secure use of AI tooling in our own engineering workflow are an active concern.
  • Represent Upvest's security posture clearly to everyone.
What you bring:
  • 6–10 years in security engineering, with 4+ years focused on product security or cloud security, and you work well in a regulated environment. You don't need to check every box, but we're asking for evidence that you've taken security from "owned by one team in a queue" to "embedded in how an engineering org ships."
  • Hands‑on, technically credible. You earn the trust of engineers by going deep, so you're comfortable reading code, threat modeling designs, debating architectures, and writing tooling when it's valuable.
  • Cloud‑native security depth. GCP preferred; AWS or Azure transferable. You know IAM, network segmentation, KMS, IaC security (Terraform), and Kubernetes hardening (RBAC, network policies, Pod Security Standards) as a craft.
  • Product/Application security foundations. OWASP Top 10 / ASVS, secure code review, SAST/DAST/SCA tooling integration, supply‑chain security (SLSA, signing).
  • Lead through influence, not gatekeeping. You drive security outcomes through partnership with engineering teams. You can navigate ambiguity, set direction, and make sound risk‑based decisions that scale with the organisation. People want to work with you, because you don't just say "no", you say "yeah, and this is how".
  • Hire and grow people. You've built or grown a small team. You set a high bar in interviews, invest on‑boarding, give real‑time feedback, and address performance issues quickly and fairly.

Communicate cleanly across audiences e.g. a security incident write‑up to engineering, a control narrative to an auditor, and a risk briefing to executives are three different documents, and you can write all three.

Nice to have:
  • Experience securing multi‑tenant B2B platforms or financial‑API products: tenant isolation, API‑as‑product safety boundaries, and the specific operational shape of selling to regulated customers.
  • Experience with trading, custody, or securities settlement platforms, or curiosity about that domain.
  • Bug bounty / VDP programme management.
  • In a past life, you have shipped backend code in production, and you're comfortable in Go (preferred), Python, or another modern backend language.
  • Regulatory fluency. Working knowledge of DORA, MaRisk, BAIT, ISO 27001. You can change audit‑speak or regulation into actionable technical requirements other people understand. You can hold your own with auditors and regulators without losing engineering pragmatism.
  • Background in engineering and offensive security.
  • German skills are useful for some potential client interactions, but not required. Our working language is English.
  • Hands‑on experience with AI/LLM security, agentic identity, or securing AI tooling in an engineering workflow.
  • Familiarity with the operational side of security is a bonus, hands‑on experience with EDR and SIEM platforms, or a background in incident response. This matters in practice, you'll be part of the security on‑call rotation, so being comfortable picking up an active incident is real, not theoretical.
How we Upvest in you:
  • Impact‑driven work: We’re building the infrastructure that will power the future of investing in Europe. It’s complex, ambitious, and meaningful. You’ll work with modern technologies and create something entirely new. No legacy systems, no limits.
  • Wellbeing: Recharge with 30 days of annual leave and maintain a healthy lifestyle with sports benefits. Access confidential professional coaching and enjoy the flexibility to work remotely abroad for up to 183 days a year. Recharge with UpRest, a one‑month fully paid sabbatical after every 4 years of working at Upvest.
  • Development: Growth is in our DNA. Each Upvenger has access to a personal development budget and the freedom to decide how to use it.
  • Flexible work environment: Work from any of our hubs in Berlin, London or Tallinn hybrid or remotely across Europe, depending on the role. We give you the choice and budget to work where you’re most comfortable and productive, either at home or in the office. You choose.
  • Compensation and equity: We believe that all Upvengers contribute to our success and deserve a competitive, above‑market salary and a participation in our employee equity program.
  • Team celebrations: Participate in company‑wide events, such as UpFest, dinners, offsites and our Holiday party, to connect with colleagues and celebrate our achievements.
  • Inclusion: We’re committed to a culture where everyone belongs and thrives. Our Employee Resources Groups foster inclusion and connection, like Upfem for our female Upvengers, or UpVergent supporting neurodivergent Upvengers and allies.
Our Values:
  • Make it easy for others. We simplify the complex and act with the best intentions.
  • Own the outcome. We are proactive, fast and confident to get the job done, valuing progress over perfection.
  • Rise to the challenge. We aim high and push the boundaries. We stay curious, learn and celebrate our wins together.
  • Tell the story. We start with the Why to align on purpose. We are transparent and share knowledge to empower and inspire others.

Upvest is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Lead IT Risk Manager (f/m/d)
Lead IT Risk Manager (f/m/d)

Upvest GmbH • Deutschland

Hybrid
EUR 80.000 - 100.000
30 days annual leave
Personal development budget
Employee equity program
+1
AI Platform Engineer (f/m/d)
AI Platform Engineer (f/m/d)

DUDE CHEM • Berlin

Hybrid
EUR 90.000 - 130.000
€20,000 annual AI tools budget
Professional development budget €1,500
30 days annual leave
+2
Head of Engineering, Platform (f/m/d)
Head of Engineering, Platform (f/m/d)

Upvest • Berlin

Vor Ort
EUR 120.000 - 170.000
AI tools budget
30 days leave
Upvest sabbatical
+5
Senior IT & Automation Engineer (f/m/d)
Senior IT & Automation Engineer (f/m/d)

Upvest • Berlin

Vor Ort
EUR 100.000 - 140.000
€20,000 yearly AI tools budget
30 days annual leave
Remote work abroad up to 183 days per/
+5
Senior Liquidity Risk Manager (f/m/d)
Senior Liquidity Risk Manager (f/m/d)

Upvest • Berlin

Hybrid
EUR 70.000 - 90.000
30 days of annual leave
Flexible work environment
Personal development budget
+4
Senior Client Experience Manager (German Speaking) (f/m/d)
Senior Client Experience Manager (German Speaking) (f/m/d)

Upvest • Berlin

Hybrid
EUR 65.000 - 85.000
30 days of annual leave
Sports benefits
Personal development budget
+2
Senior Liquidity Risk Manager (f/m/d)
Senior Liquidity Risk Manager (f/m/d)

Upvest GmbH • Deutschland

Hybrid
EUR 80.000 - 110.000
30 days of annual leave
Fitness benefits
Personal development budget
+2
Head of Product - Clients (f/m/d)
Head of Product - Clients (f/m/d)

DUDE CHEM • Berlin

Hybrid
EUR 140.000 - 190.000
30 days annual leave
Remote work across Europe
Personal development budget
+2
(Senior) Legal Counsel - Investment Operations (f/m/d)
(Senior) Legal Counsel - Investment Operations (f/m/d)

Upvest • Berlin

Hybrid
EUR 80.000 - 90.000
30 days annual leave
Professional coaching
Flexibility to work remotely abroad
+4
Principal Launch Manager (f/m/d)
Principal Launch Manager (f/m/d)

DUDE CHEM • Berlin

Hybrid
EUR 120.000 - 190.000
30 days annual leave
Remote work abroad up to 183 days/year
Personal development budget
+1