Remote job
Security Engineer
Job details
About this role
Role overview
This is a hands-on security engineering position focused on building preventive controls for a cloud-based hospitality technology platform handling payments, customer records, and third-party integrations. You will design and implement security capabilities within engineering workflows, helping product and platform teams make secure decisions without slowing delivery. The role is centered on engineering and enablement rather than alert monitoring, with immediate priorities across application security, cloud policy, and software supply-chain protection.
Responsibilities
- Build and maintain SAST and software composition analysis capabilities directly within developer workflows. - Lead threat-modeling sessions with product and platform teams before systems and features are implemented. - Own Azure cloud-security controls, including policy-as-code enforcement and secure-by-default configuration standards. - Strengthen supply-chain security across third-party dependencies and delivery pipelines. - Use AI to accelerate threat analysis, scale vulnerability triage, and create repeatable security-review workflows for engineering teams. - Evaluate AI-generated code and analysis for security weaknesses, incorrect assumptions, and other failures before operational use.
Requirements
- At least two to five years of hands-on security engineering experience in a software company or cloud-native environment, with a focus on building security capabilities rather than only operating them. - Practical experience embedding application-security checks into software delivery processes and managing vulnerability findings at scale. - Experience supporting cloud or platform security, preferably including Azure configuration governance and automated policy enforcement. - Strong knowledge of application, cloud, and dependency-related security risks, demonstrated through tooling, threat modeling, reviews, or comparable engineering work. - Advanced practical AI fluency: redesign a security workflow using AI, make the result reusable by others, and consistently verify generated outputs instead of accepting them automatically.
Nice to have
- Familiarity with threat-modeling frameworks such as STRIDE or PASTA. - Experience with software bills of materials, dependency pinning, pipeline integrity verification, or similar supply-chain controls. - Technical exposure to European cybersecurity compliance frameworks rather than experience limited to auditing.
Benefits and work setup
- Remote-first working with substantial autonomy, global collaboration, and an expectation of ownership and consistent delivery. - Work-from-anywhere flexibility, including the option to work abroad for several weeks each year; relocation support may be available after one year. - Flexible and hybrid working options, plus a home-office setup budget and a monthly work-from-home allowance. - Additional benefits vary by location and may include healthcare, retirement planning, team events, and social activities. - Listed salary ranges are €57,000–€70,000 EUR in Spain and CZK 1,191,500–1,598,000 in Czechia. Final compensation may reflect market conditions, budgets, or exceptional qualifications while remaining reasonably close to the stated range.