SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Talon.One is hiring one of its first two security engineering roles to own the security posture of its promotions and loyalty platform serving major European retail and travel brands. You'll work hands-on across a multi-tenant SaaS environment, pairing directly with engineers and product managers rather than working in isolation.
Key responsibilities include threat-modeling new product features (especially AI-embedded ones) before they're built and translating findings into engineering work. You'll own tenant isolation and API security across the Rule Engine, Integration API, Management API, and third-party integrations. As the security design authority for AI features, you'll guide the team building UCP and Predict capabilities.
You'll build automated cross-tenant and adversarial testing in CI/CD pipelines to catch isolation issues on every build, not just during annual pentests. You'll establish frictionless golden paths for code security checks that developers adopt by default without slowing delivery. You'll run vulnerability management and coordinate patch response across all squads, manage application and AI security monitoring with observability tools, and design real-time detection rules and alerts.
Additional responsibilities include designing API security for Talon.One's integration with Adyen, running a security champions program to build security capability across tribes, and experimenting with AI-driven approaches to identify and remediate product security risks at scale.
You should bring production shipping experience (software engineering or security with coding), deep knowledge of multi-tenant SaaS authorization and tenant isolation models, and end-to-end API security design expertise. You need hands-on threat-modeling experience (STRIDE methodology), practical CI/CD security tooling implementation (SAST/DAST), and understanding of how AI features are built—retrieval, context assembly, tool calling, agent loops, and indirect prompt injection risks. Google Cloud, Kubernetes, Wiz, and Datadog experience is expected. You should be comfortable building security monitoring and detection systems in-house, know OWASP guidance deeply, and be able to influence engineers outside your reporting chain while operating early in a function with no existing playbook.