PRODUCT & AI SECURITY ENGINEER
linkedinjobs·Berlin, Berlin
senior
Sign in to applyFree account, takes a minute.
Job description
<div class="content-intro"><p><strong>ABOUT TALON.ONE:</strong></p>
<p> </p>
<p>Talon.One is the most powerful incentives engine that unifies loyalty, promotions and gamification into one holistic platform. Backed by enterprise-grade security and scalability, Talon.One empowers companies to build personalized, profitable promotions and loyalty programs using any data.</p>
<p>Today, over 250 of the world’s most-loved brands including Adidas, Sephora and Carlsberg work with Talon.One to drive deeper engagement and lasting loyalty with their customers.</p>
<p> </p></div><p> </p>
<p><strong>ABOUT THE ROLE:</strong></p>
<p>You'll be one of Talon.One's first two security engineering hires, owning the security of everything we ship to our customers and third-party partners, from API authorization to the AI features going into our platform and their real-time observability and detections. You'll work hands-on, pairing directly with engineers and product managers rather than filing tickets, across a multi-tenant platform that powers promotions and loyalty for some of Europe's largest retail and travel brands. Based in Berlin, hybrid.</p>
<p> </p>
<p> </p>
<p><strong>ONCE YOU ARE HERE YOU WILL:</strong></p>
<ul>
<li>Threat-model new product features before they're built, including AI-embedded ones, and turn what you find into real engineering work</li>
<li>Own tenant isolation and API security across our Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP and third-party integrations</li>
<li>Act as the security design authority for our AI features, working closely with the team behind UCP and Predict</li>
<li>Build automated cross-tenant and adversarial testing that runs in CI, so isolation gets checked on every build, not only during our external yearly Pentest iterations </li>
<li>Build standard, frictionless and automated golden paths for code security checks in CI workflows that developers can adopt by default without slowing down delivery</li>
<li>Run vulnerability and coordinate efficient patch response across every squad outside Platform, from automated dependency updates to drilled emergency response</li>
<li>Build and own application and AI security monitoring with our observability tools and build real-time security detection rules and alerts, and security events runbooks </li>
<li>Design the security of the API integration between Talon.One and Adyen as our products come together</li>
<li>Run a security champions programme so all our tribes build real security capability, not just the security team</li>
<li>Experiment with AI, leverage innovative ways and build new workflows to identify, prioritize, and remediate product security risks at scale.</li>
</ul>
<p> </p>
<p><strong>WHAT WE NEED YOU TO BRING TO THE TABLE:</strong></p>
<ul>
<li>Experience with shipping production code, whether you come from software engineering or from security work that includes coding</li>
<li>Experience with a multi-tenant SaaS platform's authorization and tenant isolation model, and strong knowledge of how to test for broken object-level authorization automatically</li>
<li>Design API security end-to-end: authentication, credential lifecycle, rate limiting, abuse resistance and webhook security</li>
<li>Hands-on experience with threat-modelling methodologies such as STRIDE, translating identified threats into actionable engineering requirements and security tests</li>
<li>Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows, with a focus on useful developer feedback and effective vulnerability remediation</li>
<li>Understanding how AI features actually get built, retrieval, context assembly, tool calling, agent loops, and know where indirect prompt injection breaks multi-tenant isolation</li>
<li>Hands-on experience with Google Cloud security, Kubernetes, and tools like Wiz and Datadog</li>
<li>Know how to build security monitoring and detections in-house tools (SIEM) yourself, from designing the signal through tuning it and writing the runbook</li>
<li>Strong knowledge of OWASP security guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications</li>
<li>Ability to influence engineers who don't report to you, and feel comfortable being early in a function with no existing playbook</li>
</ul>
<p> </p>
<div class="p-rich_text_section"><strong>WHAT'S IN IT FOR YOU:</strong></div>
<ul class="p-rich_text_list p-rich_text_list__bullet" data-stringify-type="unordered-list" data-indent="0" data-border="0">
<li>90+ team of engineers, product managers and product designers in Berlin</li>
<li>Leaders with 8+ years of experience building our promotions engine</li>
<li>€1,000 annual learning budget and free German language courses to boost your skills</li>
<li>30 days of annual leave, plus extra paid days for your birthday and moving day</li>
<li>Home office setup budget, a monthly home office allowance</li>
<li>Freedom to work from abroad for up to 90 days worldwide!</li>
<li>Mental health support with nilo.health and a discounted Urban Sports Club membership</li>
<li>20% company subsidy on your pension contributions</li>
<li>Subsidised BVG public transport ticket and a dog-friendly Berlin office where your furry friend is welcome</li>
<li>Lease your ideal bike through BusinessBike</li>
</ul>