SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Spendesk is building a leading spend management platform for modern businesses, processing billions of euros across Europe. They are creating a dedicated Security Engineering function and seeking the first senior hire to shape how the platform is protected, threats are responded to, and a security-aware engineering culture is built.
This is a pure technical engineering role focused on security, not governance or compliance. You will be an individual contributor on a technical depth track with high influence. You will mentor an Associate Security Engineer, shape security practices across engineering squads, and serve as the go-to person when engineering teams need security guidance. As the team grows, you will transition from day-to-day operations toward architecture, strategy, and mentoring.
Key responsibilities include:
**Vulnerability & Incident Management:** Own and operate the bug bounty program, manage the platform and escalation thresholds, act as escalation point for vulnerability triage on complex or high-severity findings, and lead security incident response including qualification, forensics, fraud investigations, fix coordination, post-mortems, and resolution tracking.
**Detection & SIEM:** Own the SIEM platform (ElasticSearch, multi-node Linux) including architecture, detection rules, and indicators of compromise. Build and evolve detection coverage focusing on signal quality, and maintain security runbooks and operational documentation.
**Identity & Access Management:** Own IAM implementation and operations for product and infrastructure systems, including SSO/MFA configuration, role and access-rights implementation, periodic permission reviews, and secrets rotation. Work within authentication standards set by the security governance team.
**Secure Development & Audits:** Embed security into the development lifecycle through threat modeling and secure code patterns. Conduct technical security reviews of code (TypeScript, Node.js, Python), infrastructure-as-code (Terraform), and multi-tenant AWS environments. Design and own the automated CI/CD gate suite (SAST, SCA, container scanning, AI-generated code risk detection). Assess and govern AI tooling adoption across engineering. Coordinate and execute penetration tests and security audits.
**Education & Influence:** Coach engineers on secure development through workshops and design reviews. Surface security risks and recommendations to engineering leadership. Partner with Infrastructure on secure-by-default solutions.
**Requirements:**
Must-haves:
- Track record of owning security outcomes end-to-end with hands-on experience across at least three of: code auditing, infrastructure security (AWS/Linux), penetration testing, SIEM operations, incident response
- Ability to own a roadmap: identify priorities, build a plan, execute autonomously, and communicate progress to non-specialists
- Deep understanding of modern web architectures (microservices, cloud-native, PaaS/SaaS) and their security implications
- Strong scripting and automation ability (Python, Bash, or similar)
- Experience mentoring other engineers or security practitioners
- Excellent communication skills, able to explain technical security concepts to non-technical stakeholders
Nice-to-haves:
- Experience with ElasticSearch / ELK stack in production
- Familiarity with AWS, GCP, Snowflake, Datadog, Okta
- Knowledge of security standards and frameworks (ISO 27001, OWASP, SOC 2, PCI-DSS)
- Experience in a regulated fintech or payments environment
- Reverse engineering and analysis of minified/obfuscated code