Verified from career page · Posted 1mo ago
- Posted
- 1mo ago
- Workplace
- Not specified
- Salary
- Not disclosed
- Visa sponsorship
- Not specified
Posted on 21 August 2026
Work model not stated
Salary range not shared by the company
Visa sponsorship details unknown
ABOUT THE ROLE:
You'll be one of Talon.One's first two security engineering hires, owning the security of everything we ship to our customers and third-party partners, from API authorization to the AI features going into our platform and their real-time observability and detections. You'll work hands-on, pairing directly with engineers and product managers rather than filing tickets, across a multi-tenant platform that powers promotions and loyalty for some of Europe's largest retail and travel brands. Based in Berlin, hybrid.
ONCE YOU ARE HERE YOU WILL:
Threat-model new product features before they're built, including AI-embedded ones, and turn what you find into real engineering work
Own tenant isolation and API security across our Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP and third-party integrations
Act as the security design authority for our AI features, working closely with the team behind UCP and Predict
Build automated cross-tenant and adversarial testing that runs in CI, so isolation gets checked on every build, not only during our external yearly Pentest iterations
Build standard, frictionless and automated golden paths for code security checks in CI workflows that developers can adopt by default without slowing down delivery
Run vulnerability and coordinate efficient patch response across every squad outside Platform, from automated dependency updates to drilled emergency response
Build and own application and AI security monitoring with our observability tools and build real-time security detection rules and alerts, and security events runbooks
Design the security of the API integration between Talon.One and Adyen as our products come together
Run a security champions programme so all our tribes build real security capability, not just the security team
Experiment with AI, leverage innovative ways and build new workflows to identify, prioritize, and remediate product security risks at scale.
WHAT WE NEED YOU TO BRING TO THE TABLE:
Experience with shipping production code, whether you come from software engineering or from security work that includes coding
Experience with a multi-tenant SaaS platform's authorization and tenant isolation model, and strong knowledge of how to test for broken object-level authorization automatically
Design API security end-to-end: authentication, credential lifecycle, rate limiting, abuse resistance and webhook security
Hands-on experience with threat-modelling methodologies such as STRIDE, translating identified threats into actionable engineering requirements and security tests
Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows, with a focus on useful developer feedback and effective vulnerability remediation
Understanding how AI features actually get built, retrieval, context assembly, tool calling, agent loops, and know where indirect prompt injection breaks multi-tenant isolation
Hands-on experience with Google Cloud security, Kubernetes, and tools like Wiz and Datadog
Know how to build security monitoring and detections in-house tools (SIEM) yourself, from designing the signal through tuning it and writing the runbook
Strong knowledge of OWASP security guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications
Ability to influence engineers who don't report to you, and feel comfortable being early in a function with no existing playbook
WHAT'S IN IT FOR YOU:
90+ team of engineers, product managers and product designers in Berlin
Leaders with 8+ years of experience building our promotions engine
€1,000 annual learning budget and free German language courses to boost your skills
30 days of annual leave, plus extra paid days for your birthday and moving day
Home office setup budget, a monthly home office allowance
Freedom to work from abroad for up to 90 days worldwide!
Mental health support with nilo.health and a discounted Urban Sports Club membership
20% company subsidy on your pension contributions
Subsidised BVG public transport ticket and a dog-friendly Berlin office where your furry friend is welcome
Lease your ideal bike through BusinessBike
WHY YOU SHOULD WORK FOR US:
The right attitude: modern methods and a diverse, creative workspace with an open and international culture
Everyone for the product: Together we create a flexible, highly scalable product with state-of-the-art technologies. We can only succeed if everyone works as a team
Healthy Growth: Growing our company means growing everyone in the team. We love to share knowledge and learn
A great environment: Flexible and family-friendly environment, bright and easily accessible offices, modern software and hardware
High flexibility degree: Prefer to work early or late at night? Do you have to pick up your children from kindergarten? Do you prefer working abroad? We believe in results and motivated employees
Do you want this job?
We’d love to hear from you! Apply directly via the form below.
Talon.One is an Equal Employment Opportunity employer that proudly pursues and hires a diverse workforce. We do not make employment decisions on the basis of race, color, religious belief, ethnic origin, nationality, sex, gender identity, sexual orientation, disability, age, military or veteran status, or any other basis protected by applicable local, state, or federal laws or prohibited by company policy. As an employer we strive for a healthy and safe workplace and strictly prohibit harassment of any kind.
Find out more about our Candidate Privacy Policy.
About Talon.One
Talon.One builds a promotions and loyalty engine — an API rather than an app — from Berlin, where its hiring sits. A deep technical product with a small engineering org behind it.