Distinguiti per questa posizione — genera un curriculum e una lettera di presentazione personalizzati in circa un minuto.
YGO.ai is hiring a Cloud Security Engineer to own the security of our cloud platform, the APIs our enterprise clients run on and the company itself.
You will build the security function while remaining hands-on as an engineer, reviewing code, testing, and improving security across the stack. You will lead the security roadmap and work closely with engineering to mitigate risks daily.
YGO.ai is a VC-funded AI tourism platform. We are hiring a Cloud Security Engineer to own the security of our cloud platform, the APIs our enterprise clients run on and the company itself.
The role carries two things at once. You own security engineering directly and hands-on. You build the security function around it as we grow. At YGO a pod lead is a squad leader and a spokesperson, close to the work and close to the client, rather than a full-time manager. You will not stop being an engineer.
The work is broad. You might review source code in the morning, investigate an endpoint alert after lunch and help design a new authentication flow the next day. You identify the highest-risk problems, decide what happens first and execute.
We serve major travel enterprises and we have enterprise commitments going live from the start of 2027. Security is a condition of that business, not a layer added afterwards.
Application security. Hands-on code and architecture review across our APIs, backend services and internal tooling. Targeted penetration testing to validate issues yourself. Working with engineers on root causes and practical fixes rather than handing over reports. Vulnerability management and the external penetration tests we commission.
Detection and response. Knowing we are under attack while it is happening and what happens next. Alerting, intrusion detection, incident process and the on-call path.
Cloud and platform hardening. Access control, network boundaries, secrets management, containers and the deployment pipeline. Security through the SDLC: CI/CD, repositories and dependencies.
The security of our APIs. Authentication and authorization, tenant isolation, token scoping and lifecycle, abuse prevention, enterprise SSO and the audit trail our clients and our own accountability depend on.
The security of our AI systems. Prompt injection, tool and agent permissions, our MCP server, retrieval and data ingestion. The data-residency rules we are held to contractually.
Identity and company security. SSO, MFA and privileged access for employees, onboarding and offboarding, access reviews, MDM, endpoint security and SaaS access.
Secure design across the pods. Threat modelling and design review that enables engineers rather than gatekeeping them and raises the standard of what they ship.
The security function itself. Set the priorities and the roadmap from actual risk, not security theatre. Decide what we build, buy, automate or leave for later. Grow the team and hire into it, represent security to enterprise clients and carry our SOC 2 programme on Drata.
An AI search and recommendation engine for major travel enterprises: enterprise integration, SSO, client security reviews, GDS integrations.
A content enrichment API sold as SaaS: high scale, public facing, data and AI heavy.
The platform underneath: a client console with organisations, projects and API tokens, supplier and business-client integrations, data ingestion, an MCP server, and several LLM providers behind a single internal library.
Hosting: PaaS-managed containers, Cloudflare in front
Observability: Jaeger tracing, BetterStack for logging, alerting and on-call
Compliance: Drata, SOC 2 in progress
AI tooling: Claude Code, used across the whole team