Security Engineer

New
Q
QdrantAI Infrastructure
Location: Germany. Secondary Locations: France, Netherlands, SpainFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
3+ years in a hands-on security engineering, product security, or vulnerability management role.
Required Skills
AWSPythonKubernetesGoRustCI/CDGitHub

Requirements

  • 3+ years in a hands-on security engineering, product security, or vulnerability management role.
  • Ability to read and navigate unfamiliar codebases (Rust, Go, Python) to validate vulnerability reports and trace impact.
  • Experience maintaining automation and security tooling.
  • Experience triaging vulnerability reports or working with a bug bounty program or product security team.
  • Practical knowledge of cloud and container security, particularly AWS and Kubernetes.
  • Familiarity with GitHub security features and securing CI/CD pipelines.
  • Ability to investigate alerts and vulnerabilities methodically to recommend proportionate remediation.
  • Clear written communication skills.
  • Self-directed approach with comfort managing a security queue.
  • Nice to have: Offensive security background (penetration testing, CTF, vulnerability research, or exploit analysis).
  • Nice to have: Experience in an open-source company or contributing security improvements to open-source projects.
  • Nice to have: Familiarity with cloud-native incident response.

Responsibilities

  • Run our public bug bounty program: triage reports, reproduce and validate findings, communicate clearly with security researchers, and drive remediation through to closure.
  • Investigate reported vulnerabilities at the code level, including our Rust core, Go and Python tooling.
  • Enable engineers to build secure systems by providing tooling, paved-road defaults, documentation, and practical guidance.
  • Partner with engineering teams to design, review, and verify fixes and set clear security requirements.
  • Harden and maintain GitHub security posture including secret scanning, push protection, branch protection, dependency alerts, and code scanning.
  • Monitor, investigate, and respond to security alerts across AWS, Kubernetes, CI/CD, and related infrastructure.
  • Track and report security metrics and maintain records of vulnerability and incident work.
  • Implement, configure, and maintain security tooling across development and cloud environments.
  • Build security automation and guardrails that scale across the development lifecycle, including CI/CD security checks and policy-as-code.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now