About the role:This is a senior, hands-on engineering role. You will join a small, agile team in a hybrid work model (office in central Berlin). As a senior specialist, you will have the opportunity to set the standard for our security culture and practices. You will report directly to the Head of Infrastructure & Security and work cross-functionally to make security a cornerstone of our product and operations.
🗃️ What you will be doing:
- Design and implement secure cloud architectures in AWS (EKS, IAM, VPC, S3, Lake Formation, etc.)
- Harden our Kubernetes environments, containers, and networks using best practices
- Automate security policies using Terraform, ArgoCD, and Helm
- Secure the software development pipeline with GitHub Actions and ArgoCD
- Automate security scanning (SAST/DAST) and integrate secrets management (HCP Vault)
- Conduct threat modeling and security reviews for our web (Typescript/React/next.js web/Nest.js backend) and mobile (ReactNative) applications.
- Protect our data infrastructure (PostgreSQL, message brokers, Lake Formation)
- Monitor security logs, respond to incidents, and lead forensics investigations
- Develop security policies, IAM standards, and patching procedures
Support GDPR and SOC 2 compliance efforts and prepare for audits - Partner with IT, DevOps, and product teams to integrate security controls into all projects.
🎒 What you will bring:
- 5+ years securing cloud infrastructure, particularly on AWS
- Strong Kubernetes/EKS skills and experience with container security
- Extensive use of Terraform, GitHub Actions, ArgoCD (Apps of Apps pattern), Helm
- Solid Python scripting experience; familiarity with JavaScript/TypeScript or Kotlin/Java
- Hands-on experience with AWS security tools (GuardDuty, Security Hub), Datadog, and vulnerability scanners
- Understanding of OWASP Top 10, MITRE ATT&CK, NIST, and secure networking protocols
- Skilled in vulnerability management, pentesting concepts, and threat modeling
- Knowledge of TLS, firewalls, VPNs, and secure communication protocols
- Experience in Web3 security, blockchain, or crypto compliance
➕ Nice to have:
- Familiarity with GDPR, SOC 2, or ISO 27001