Security Lead
Langdock
30+ DAYS
Seniority
Senior
Model
In-Office
Sector
Salary
€90,000 – €140,000
Contract
Full-Time
A hands-on Security Lead to strengthen the security of Langdock's product, infrastructure, and internal systems. Your primary focus will be application and infrastructure security, working closely with the CTO and engineering teams to identify risks, assess defenses, and drive practical improvements. You'll also own the security of internal IT environment, including identity, access, and device security.
What you'll do
- Coordinate penetration tests end to end. Define scope with engineering and external testing partners, support testing, assess findings, and follow remediation through to verification.
- Own vulnerability intake and triage. Monitor security inbox and responsible disclosure program, assess reported issues, and work with engineering to prioritize and resolve them.
- Help engineering build securely. Review security-sensitive designs and changes, identify weaknesses in authentication, authorization, and data isolation, and recommend practical improvements.
- Assess and improve security posture. Work with engineering to evaluate how production infrastructure and internal systems are protected, identify gaps, and drive improvements.
- Strengthen network and access controls. Review network separation, service exposure, privileged access, and permissions so systems and data are accessible only where needed.
- Own identity and device security. Ensure effective MFA, appropriate access policies, and properly managed, encrypted, and patched devices.
- Automate the employee lifecycle. Build dependable processes for account provisioning, access changes, offboarding, and access reviews across Entra ID and internal tools.
- Support customer security assessments and contribute to ISO 27001 and SOC 2 Type II compliance programs.
What you'll need
- Hands-on application and infrastructure security experience. Understanding of how modern SaaS applications and cloud environments are built, where they can fail, and how to protect them.
- Technical depth and sound judgment. Ability to investigate vulnerabilities, assess practical impact, discuss remediation with engineers, and distinguish urgent risks from lower-priority findings.
- Experience taking findings through to resolution. Work with penetration testers or vulnerability disclosure programs and help teams turn reports into verified fixes.
- Confidence with identity and endpoint security. Comfortable configuring identity providers, MFA, access policies, and device management.
- An automation mindset. Build scripts, workflows, and integrations to reduce recurring work, and use AI tooling thoughtfully.
- Clear communication. Explain technical risks and controls to engineers, colleagues, and customers.
Nice to have
- Experience with ISO 27001, SOC 2, and customer security assessments.
- German language skills.
What they offer
- Transparent, level-based salary with equity.
- In-person work in Berlin office with team lunches and dinners.
- Health and wellness integrated into work culture.

