SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Staffbase is an AI-native Employee Experience Platform helping organizations unlock inspirational communication through industry-leading agentic AI communications channels (intranet, employee app, email solutions). The company is a unicorn (valued at $1B+) with 550+ employees across offices in Chemnitz, New York, Berlin, London, Sydney, Tokyo, Prague, and Minneapolis–St. Paul, serving 1,500+ customers and reaching over 14 million employees.
The Product Security team is at the heart of Staffbase's mission to keep products and customer data secure while enabling engineering teams. This role is part of an enablement-focused team that provides tools, guidance, and insights allowing developers to integrate security early in the development process. Security is positioned as a trusted partner and foundation for better products, not a blocker.
You will take ownership of tasks that improve security automation and strengthen product security pipelines. Key responsibilities include proactively exploring AI for vulnerability detection and remediation, continuously learning and sharing knowledge about vulnerabilities in the product context, and supporting the team by enhancing services with software engineering solutions. You'll collaborate closely with stakeholders across the product department, gaining broad exposure to how a growing SaaS company operates.
Specific technical areas include maintaining outbound email security by reviewing related metrics, maintaining the Web Application Firewall ruleset, Kubernetes security, CI/CD pipeline security, and maintaining the central HTML sanitization service written in TypeScript. The team works with curiosity, humility, and a growth mindset, supporting each other and celebrating progress.
Benefits include competitive compensation with LTIP (unit-based Long Term Incentive Plan), flexible working time models with hybrid work options and a yearly flex work allowance of €1,560, 31 vacation days annually plus pro rata fully paid Fridays off during August, company pension scheme, and one volunteer day per year.
REQUIREMENTS:
- Practical knowledge of security topics (penetration testing, secure software development, vulnerability management, SAST, DAST)
- Strong programming skills in one or more of: TypeScript, JavaScript, Kotlin, Java, Go, or Python
- Practical knowledge of Unix and Kubernetes infrastructure, preferably managed via Terraform and Kustomize
- Strong English communication skills (German is a plus)