SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Engineer - AppSec (d/f/m)

Vivenu - Remote - Remote - posted 2026-09-04

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Vivenu is a global leader in event ticketing technology, serving major brands like the Grammys, Golden Globes, and Stanford University. The company has raised over $65 million and operates six offices worldwide, processing over 1 billion API requests monthly for more than 10 million end users. This is a blank-canvas opportunity to build and scale an Application Security (AppSec) program from the ground up across the entire global engineering organization. You will drive the complete AppSec lifecycle: offensive red teaming, threat modeling, risk-based vulnerability management, and pioneering a shift-left security culture. Key responsibilities include: - Partner with engineering teams as a trusted security advisor to champion security-by-design and elevate overall security posture - Coordinate and execute threat modeling and advanced security testing across the product and underlying infrastructure - Lead next-generation vulnerability management using risk-based principles (EPSS) and AI technologies to accelerate security testing at scale - Design, implement, and automate security checks and guardrails (SAST, DAST, secret scanning) directly into CI/CD pipelines - Perform deep-dive code and configuration reviews, advocating for secure coding practices that support proactive shift-left strategy The technical environment includes a TypeScript monolith with Go supporting services, a sophisticated multi-tenant, multi-region architecture spanning Kubernetes, GCP (primary compute), and separate database services. You'll secure both the web application and underlying API structure, and work with a next-generation Kubernetes "satellite architecture" utilizing hardened private compute nodes, VPC peering, and Argo CD for GitOps. Vivenu is backed by over $65 million in funding and is consistently ranked among Europe's fastest-growing scale-ups. The team includes 160+ professionals with leaders from Google, Slack, and Salesforce. Requirements: - 5+ years of dedicated Security Engineering experience, ideally in high-growth SaaS, E-commerce, or Fintech environments - Deep ability to dive into complex SaaS application business logic to uncover and verify elusive attack vectors - Deep understanding of web/API attack vectors, scalable security best practices, and secure workload operation in cloud environments (Kubernetes, AWS/GCP/Azure) - Proven track record of autonomously driving security initiatives from conception to completion - Proficiency in at least one programming language for scripting and security tool development - Bachelor's or Master's degree in Computer Science, Cybersecurity, IT, or related technical field (or equivalent practical experience) Preferred qualifications: - Experience with PCI DSS script security - Background in Red/Purple Team operations and advanced penetration testing with strong collaboration skills - Hands-on experience with Terraform for securing infrastructure-as-code - Familiarity with GCP, Golang, and TypeScript

Similar roles