Security Engineer
New
Q
QdrantAI Infrastructure
Location: Germany. Secondary Locations: France, Netherlands, SpainFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 3+ years in a hands-on security engineering, product security, or vulnerability management role.
- Required Skills
- AWSPythonKubernetesGoRustCI/CDGitHub
Requirements
- 3+ years in a hands-on security engineering, product security, or vulnerability management role.
- Ability to read and navigate unfamiliar codebases (Rust, Go, Python) to validate vulnerability reports and trace impact.
- Experience maintaining automation and security tooling.
- Experience triaging vulnerability reports or working with a bug bounty program or product security team.
- Practical knowledge of cloud and container security, particularly AWS and Kubernetes.
- Familiarity with GitHub security features and securing CI/CD pipelines.
- Ability to investigate alerts and vulnerabilities methodically to recommend proportionate remediation.
- Clear written communication skills.
- Self-directed approach with comfort managing a security queue.
- Nice to have: Offensive security background (penetration testing, CTF, vulnerability research, or exploit analysis).
- Nice to have: Experience in an open-source company or contributing security improvements to open-source projects.
- Nice to have: Familiarity with cloud-native incident response.
Responsibilities
- Run our public bug bounty program: triage reports, reproduce and validate findings, communicate clearly with security researchers, and drive remediation through to closure.
- Investigate reported vulnerabilities at the code level, including our Rust core, Go and Python tooling.
- Enable engineers to build secure systems by providing tooling, paved-road defaults, documentation, and practical guidance.
- Partner with engineering teams to design, review, and verify fixes and set clear security requirements.
- Harden and maintain GitHub security posture including secret scanning, push protection, branch protection, dependency alerts, and code scanning.
- Monitor, investigate, and respond to security alerts across AWS, Kubernetes, CI/CD, and related infrastructure.
- Track and report security metrics and maintain records of vulnerability and incident work.
- Implement, configure, and maintain security tooling across development and cloud environments.
- Build security automation and guardrails that scale across the development lifecycle, including CI/CD security checks and policy-as-code.
View Full Description & ApplyYou'll be redirected to the employer's site