Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Talon.One provides an incentives engine that unifies loyalty, promotions, and gamification into one platform. The platform uses enterprise-grade security and scalability to help companies create personalized promotions and loyalty programs from their data, serving brands such as Adidas, Sephora, and Carlsberg.
задачи
Threat-model new product features, including AI-embedded features, and turn findings into engineering work;
Own tenant isolation and API security across the Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP, and third-party integrations;
Act as the security design authority for AI features in collaboration with the UCP and Predict team;
Build automated cross-tenant and adversarial testing in CI;
Build automated golden paths for code security checks in CI workflows;
Run vulnerability management and coordinate patch response across squads outside Platform;
Build and own application and AI security monitoring, real-time detection rules, alerts, and security event runbooks;
Design the API integration security between Talon.One and Adyen;
Run a security champions programme across all tribes;
Experiment with AI and build workflows to identify, prioritize, and remediate product security risks at scale.
требования
Experience shipping production code through software engineering or coding-focused security work;
Experience with authorization and tenant isolation models in multi-tenant SaaS platforms;
Strong knowledge of automatically testing for broken object-level authorization;
Ability to design API security end-to-end, including authentication, credential lifecycle, rate limiting, abuse resistance, and webhook security;
Hands-on experience with threat-modeling methodologies such as STRIDE;
Experience translating identified threats into actionable engineering requirements and security tests;
Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows;
Understanding of how AI features are built, including retrieval, context assembly, tool calling, agent loops, and indirect prompt injection risks to multi-tenant isolation;
Hands-on experience with Google Cloud security, Kubernetes, Wiz, and Datadog;
Ability to build security monitoring and detections in-house, from signal design and tuning to runbook creation;
Strong knowledge of OWASP guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications;
Ability to influence engineers without direct reporting lines and work early in a function with no existing playbook.
условия
€1,000 Annual learning budget;
Free German language courses;
30 Days of annual leave, plus extra paid days for a birthday and moving day;
Home office setup budget and monthly home office allowance;
Freedom to work from abroad for up to 90 days worldwide;
Mental health support with nilo.health and a discounted Urban Sports Club membership;