Staff Security Engineer
1 нед. назад
DenmarkEuropeLeadOnsite
awsgcpnetwork securitysecurity architecturegpu computing
Senior security engineer owning platform security, identity, and network security, enabling teams to build secure systems across complex multi-cloud and on-prem infrastructure.
О компании
- is a global leader in AI-based sports camera technology. Our innovative, fully automatic camera solution enables sports teams to record matches and training sessions without a camera operator. We’re democratizing the world of sports by granting video analysis for teams on all levels—a privilege that used to be only for the few. More than 40,000 clubs in 90+ countries record their games every week. But what truly sets us apart? Our people . We’re a diverse group of innovative thinkers, creators, and problem-solvers who believe in delivering an incredible product—and having fun while doing it. The Opportunity 's security surface is unusual. We train models on-premise on dedicated GPU infrastructure, run the product across AWS and GCP, and operate a fleet of tens of thousands of camera
Обязанности
- Design and build the paved roads for image scanning, SBOM generation, and CVE response, running inside the pipelines teams already use, with findings routed to the owners who can fix them under tracked SLAs
- Lead the design, reviews, and tooling for a unified internal network and VPN across GCP, AWS, and our Miami, Berlin, and Copenhagen offices, while the team that owns the network keeps running it
- Work with the auth service maintainers on identity and access, including MFA rollouts, removal of shared accounts, and cleanup of long-lived tokens, so the patterns stay theirs to own
- Make workload identity the paved road for CI/CD, using OIDC between GitHub Actions and AWS or GCP, packaged so teams can migrate themselves
- Build audit logging as a shared capability that teams plug into rather than reinvent
- Turn GRC controls into technical implementations, with evidence pipelines that produce auditable output without manual follow-up
- Own the contracting cycle for external penetration tests and build the intake, classification, and tracking system that routes findings to named owners, while the owning teams remediate
- Hand each capability off cleanly, with a runbook, a named owner, and an escalation path, and run office hours where product and platform teams can get a security review or a paved-road question answered
- Mentor the rest of the team and raise the security bar across Builders
Другое
- Platform security: you have run vulnerability scanning, CVE management, and image scanning at scale, and you know the operational reality of getting CVEs fixed, beyond standing up the tooling
- Identity and auth: you have worked hands-on inside an auth codebase, rolled out MFA on live systems, and managed token lifecycles in CI/CD with OIDC and workload identity
- Network security at scale: you have designed and run a unified internal network across multiple cloud providers and offices, with a VPN approach that holds up
- Platform-as-product mindset: you have built internal security tooling that other teams chose to adopt, with guard rails built into the tools developers already use and manual review as a last resort, and you gathered feedback and measured the impact
- Infrastructure as Code: strong experience with Terraform, Crossplane, or similar
- You'll join a Copenhagen-based Security Enablement Team of three engineers plus a manager. We operate as an enablement function: we build shared tooling and golden paths, and we step in for focused, high-leverage missions where no other team is positioned to deliver. We do not run a SOC and we do not carry a security pager. You'll collaborate regularly with the Platform, Product, IT, Firmware, and GRC teams. We work pragmatically and iterate quickly. This role sets the technical direction for the team's quarterly missions. We document decisions, favor simple solutions where possible, and focus on tooling and platform patterns that help teams move faster with confidence. If you read that list and matched on three or four items but not all of them, apply anyway. The "deep in one, ready to gr