Staff Engineer
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
Senior / Staff DevSecOps Engineer - Fully Remote within Europe
Security used to be something this team built into the product. Now it needs an owner.
edenity. have partnered with one of Europe's most exciting infrastructure companies, building the identity layer that businesses use to understand exactly who they're doing business with.
After two years quietly building, they've moved quickly: €40m raised from CapitalG and Index Ventures, alongside founders and executives from Stripe, Adyen, Notion, Remote, Qonto, Framer, Anthropic, Mollie, OpenAI and Goldman Sachs.
Now the customer profile is changing.
They're moving upstream into some of the most demanding financial institutions in Europe. Real banks. Serious security teams. Procurement processes that involve considerably more than someone ticking "SOC 2 compliant" on a spreadsheet.
And that's created a genuinely interesting engineering problem.
They're hiring their first dedicated security engineer.
Not a GRC person. Not someone to write policies from the sidelines. And definitely not someone whose answer to every problem is another enterprise security platform.
They need a builder who happens to be obsessed with security.
The problem you'll own
The infrastructure underneath the product is already deliberately simple and extremely scalable: Kubernetes, Postgres and Redis on AWS, built around open-source technology rather than layers of proprietary cloud magic.
The engineering team has done a good job of security so far.
But "good" stops being enough when global financial institutions start asking difficult questions.
Vulnerabilities need owners and SLAs.
Third-party dependencies need systematic review.
Security Hub alerts need proper investigation.
Responsible disclosures need triage rather than a ticket graveyard.
Auditors need evidence.
And when a bank's security team asks why something works the way it does, someone needs to be able to sit across the table, understand the concern, explain the architecture and occasionally tell them, intelligently, no.
That's you.
What you'll actually build
You'll own the security surface end-to-end, with the freedom to decide what good looks like.
That means:
- Building vulnerability management across open-source packages, infrastructure and third parties, from detection through remediation.
- Creating the automation and evidence trail that makes SOC 2 / ISO 27001 audits pleasantly uneventful.
- Designing vendor security management that engineers will actually use.
- Owning security alerting, investigation and responsible disclosure.
- Working directly with engineering to turn security requirements into shipped changes rather than PDFs.
- Joining customer security conversations, RFPs and audits with increasingly sophisticated banks and fintechs.
- Threat modelling new systems and spotting the things nobody else is worrying about yet.
- Remaining hands-on with infrastructure and DevOps alongside the platform team.
There is no security department to hide inside.
There is also no security department telling you how this has always been done.
Who we're looking for
Probably someone who's spent time somewhere where startup engineering meets serious regulation.
You might have built security inside a fintech, payments company, bank infrastructure provider or another environment where enterprise customers expect evidence, not reassurance.
You'll likely have:
- A strong DevOps / platform engineering foundation, with security layered deeply on top.
- Hands-on experience with Kubernetes, cloud infrastructure and CI/CD.
- Worked with frameworks such as SOC 2, ISO 27001 and GDPR, without becoming institutionalised by them.
- Experience building vulnerability, dependency, vendor or security monitoring processes.
- Enough technical depth to challenge engineers and enough commercial judgement to handle a bank's security team.
- The seniority to operate independently and decide what deserves fixing now, later, or never.
Most importantly, you're pragmatic.
You understand that perfect security doesn't exist. Good security is knowing where the real risks are, building the right controls around them, and making the secure path the easiest path for engineers.
Why this one is different
This isn't joining security engineer #14 and inheriting somebody else's playbook.
You're arriving at the exact moment security becomes strategically important to the company.
You'll define the tooling.
You'll define the standards.
You'll influence architecture.
You'll work directly with som