Remote job
Lead Security Engineer (m/w/d)
Job details
About this role
Role overview
This is a founding security engineer role inside a healthcare technology organization, joining as Deputy CISO to build the security engineering function from the ground up as a senior individual contributor. The position blends hands-on engineering with end-to-end program ownership across compliance, incident response, customer-facing security work, and the emerging threat surface created by AI features in a regulated clinical setting. It suits someone who wants broad influence and visible impact without an immediate management layer.
Responsibilities
- Drive vulnerability management across code repositories, including scanner deployment, dependency update automation, and the triage workflow that actually closes findings. - Act as a security counterpart to the platform team, reviewing sensitive infrastructure decisions and evaluating options such as customer-managed keys or hardware security modules. - Lead the technical side of compliance work: control design and assessments for existing ISO 27001 and C5 Type II attestations, pentest scoping and follow-up, and preparing the security case for a potential upcoming Class IIa medical device under MDR, with regulations like the EU Cyber Resilience Act on the horizon. - Build the customer-facing security narrative, including reusable documentation, evidence packages, and AI-assisted questionnaire handling, occasionally joining live conversations with hospital security teams. - Define incident response process, runbooks, and an on-call rotation that fits a company without a dedicated SOC, and lead response when something is real. - Monitor the broader threat landscape, turn emerging supply-chain and AI risks into concrete actions, and set baselines that IT applies to endpoints and accounts.
Requirements
- Six or more years of combined software and security engineering experience, with a track record of owning a security program or a significant portion of one. - Direct experience as the technical counterpart through at least one ISO 27001, C5, or SOC 2 certification cycle, including control design, working with auditors, and contributing to the Statement of Applicability. - Practical vulnerability management experience in production, covering scanners, dependency tooling, triage, and remediation follow-through. - Active engagement with the security community, forming informed opinions on current incidents before they hit the news cycle. - Genuine curiosity about AI security, covering both defending AI systems (agents, sandboxing, data flows) and using AI tooling to work at leverage. - Ability to communicate directly in English with engineers, auditors, and healthcare customer security teams without translation support.
Nice to have
- German language skills, useful for German-speaking customers and C5 assessors. - Experience in healthcare or another regulated industry. - Offensive security background. - Certifications such as OSCP or CISSP.
Benefits and work setup
- Remote-friendly company with flexible working hours and the option to arrange workations. - Edenred card usable for personal needs. - An additional vacation day so the birthday can be spent with family. - Flat-hierarchy culture built on mutual respect, recognition, and team accountability.