Eine vollständige Bewerbung in einer Minute — Lebenslauf und Anschreiben, maßgeschneidert und versandbereit.
nebenan.de is seeking an experienced security engineer to design and implement safeguards for our API and backend, focusing on abuse detection, rate limiting, verification checks, and safer defaults. You will lead threat modeling for new features and shape frontend safety improvements for a trusted user experience.
You will own moderation tooling and platform signals, guiding the moderation team to move high-risk cases first while maintaining user safety and privacy in a fast-growing
If you are not full-stack yet, you want to move into that direction and learn other stacksA plus: experience selecting and integrating vendor tooling in a safety or security stackA user- and product-centric view: you care how safety feels in the interface, and you are comfortable shaping frontend features that help users stay safeA plus: hands-on experience of a fraud, scam or impersonation wave at scaleJudgment under pressure: you keep users’ safety and freedom in balance, and you decide quickly when someone may be at riskA plus: a security background in threat modelling, incident response or offensive securityWorks well with non-engineers: moderators, product, legal. You can explain a technical risk in plain language and take a moderation insight back into codeUses AI deliberately as leverage: directs and reviews generated code to production qualityInfrastructure fluency: AWS, logging, observability, queues. You can reason about a system under attack, not only under loadA plus: German language and German-market moderation contextA security-first mindset: you threat-model by instinct, probe how features can be abused, and stay current on attack vectors against social networksSolid Ruby on Rails experience in productionStrong SQL and a real understanding of how databases behave; you can find an abuse pattern in the data yourselfExcellent English skills for working in our international teamA firm grasp of client–server architecture: what the client can and can’t be trusted with, where the risk actually lives, and how an API fails under attack