SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead Security Engineer

Catawiki - Amsterdam, North Holland, Netherlands - Hybrid - posted 2026-10-01

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Catawiki is a curated marketplace for special objects, auctioning over 100,000 unique items weekly across 80+ categories. The company has sold over 25 million objects and operates at scale serving millions of customers globally. As Lead Security Engineer, you will provide hands-on technical leadership within the Security team, part of Platform Engineering. You'll shape the security engineering roadmap and own delivery of complex security initiatives, working with Product and Platform Engineering to protect the marketplace, customers, and their data. The platform runs on Google Cloud and Kubernetes. Your focus areas include application and cloud security, secure software delivery, and risks in internal and AI-enabled systems. You'll combine deep technical work with influence across engineering, turning security risks into controls and practices that teams can use daily. This is an individual contributor role with potential to move into people management as the team evolves, based on demonstrated readiness and business needs. Key responsibilities: - Shape the security engineering roadmap and lead complex initiatives from assessment and design through implementation, rollout and ongoing operation - Design and build security controls and automation across applications, cloud infrastructure, identity and access, CI/CD and infrastructure as code - Lead threat modelling and secure code and design reviews; work with engineering teams early to identify risks before production - Investigate vulnerabilities and recurring security weaknesses; prioritize findings and build reusable controls - Improve security checks in engineering workflows, including dependency and secret scanning - Contribute to security incident investigations and response; improve detection and response tooling - Mentor security engineers and help product engineers build security skills - Work with Legal, IT and Trust & Safety on technical security controls, policies and audit evidence - Measure effectiveness and adoption of controls; communicate progress and risks to stakeholders Requirements: - Substantial hands-on security engineering experience in software or cloud environments with a track record of delivering security improvements across multiple teams - Strong knowledge of application and cloud security, including identity and access management, secrets management and secure software development - Experience leading threat modelling, secure code and design reviews, and complex remediation work - Ability to develop or automate in Ruby, Python, Go or similar language; comfortable reviewing backend code; experience building and operating security tooling in production - Experience integrating security into CI/CD, cloud infrastructure or infrastructure as code; ability to make sound trade-offs between risk reduction and engineering effort - Contributed to security incident investigations or responses; can work effectively under pressure - Led technical initiatives and mentored engineers; interested in developing leadership skills including potential people management - Influence through technical credibility and collaboration; ability to explain risks to different audiences; responsibility for seeing complex work through to completion Helpful experience: - Google Cloud, Kubernetes and Terraform or similar infrastructure tooling - Marketplace, e-commerce or software product business experience, including account and API security - Securing AI-enabled applications, agents or data pipelines, or using AI to improve security engineering workflows

Similar roles