As the inaugural Senior Security Engineer, you’ll play a pivotal role in establishing security as a core engineering function. Rather than focusing on policy or audits, you'll take a hands-on approach to strengthen cloud environments, protect AI-driven systems, and integrate security deeply into the development process.
What You’ll Do
- Lead security evaluations across infrastructure and services, identifying risks and defining clear remediation paths.
- Strengthen AWS and Kubernetes deployments by improving IAM policies, network segmentation, workload isolation, and secrets handling.
- Protect AI-specific workflows by mitigating prompt injection risks, securing PII in LLM pipelines, and preventing unintended data exposure through model interactions.
- Integrate automated security checks into CI/CD pipelines, including code analysis, dependency scanning, container inspection, and secrets detection.
- Design secure-by-default architectures for APIs, service-to-service communication, authentication, and data flow.
- Develop detection and alerting systems, define incident response procedures, and lead post-mortem reviews.
- Collaborate closely with development teams to enable secure delivery without slowing innovation.
What We’re Looking For
- 6–10+ years of hands-on security engineering in production-scale environments.
- Proven expertise in cloud security, particularly with AWS, and securing containerized systems using Kubernetes.
- Strong background in application security, including microservices, APIs, authentication, and data pipeline protection.
- Experience deploying and managing automated security tools within CI/CD—SAST, DAST, container scanning, and dependency checks.
- A mindset oriented toward offensive security: thinking like an attacker to uncover subtle flaws and test defenses effectively.
- Track record of building or significantly advancing security programs from early stages.
Nice-to-Have
- Experience securing AI/LLM systems, including prompt integrity, model access, and PII handling.
- Participation in CTFs, bug bounty programs, or formal red team operations.
- Certifications such as OSCP, OSWE, or CRTP.
- Background in incident response and digital forensics.
- Experience implementing SOC2 or ISO27001 controls beyond audit preparation.
Environment & Culture
The role is open to remote work anywhere in the EU or hybrid from Athens. The team operates with minimal meetings, prioritizes asynchronous communication, and values deep work. You’ll be the first dedicated security hire, giving you full ownership to define standards and evolve practices. The organization is engineering-first, with a focus on quality, innovation, and sustainable client relationships. There’s a dedicated budget for certifications, conferences, and training, with a clear path toward leadership.


