Lead Security Engineer
Recare
NEW
Seniority
Senior
Model
Remote
Sector
Salary
Undisclosed
Contract
Full-Time
```html
About the role
You'll be the first dedicated security engineer: a senior IC with no team at the start. You join as Deputy CISO, report to the Director of Technology (currently acting CISO), and build security engineering from scratch. You build and own the security program, the tooling, and the security story we tell customers.
What you'll do
- Vulnerability management – scanners and dependency updates across repos, plus the process that gets findings closed.
- Partner to Platform – review security-sensitive infrastructure decisions and explore options like customer-managed keys or HSMs.
- Certifications, technical side – control design and assessments for ISO 27001 and C5 setup, security case for a potential upcoming Class IIa medical device (MDR), and pentest scoping and follow-up.
- Customer security – reusable docs, evidence, and AI-assisted questionnaires for enterprise deals. You join calls when a hospital CISO asks about our AI architecture.
- Incident response – process, runbooks, and escalation. You design on-call that fits the company size and lead when it's real.
- Company-wide security – watch the threat landscape, turn this week's supply-chain issues into concrete actions, and set baselines IT applies to devices and accounts.
What you'll need
- 6+ years across software and security engineering, with a security program (or major part of one) you've owned.
- Technical counterpart through at least one ISO 27001, C5, or SOC 2 certification cycle – you've designed controls, faced an auditor, and written the technical side of a Statement of Applicability.
- Run vulnerability management somewhere real: scanners, dependency bots, triage, and follow-through that gets things fixed.
- Follow the security scene closely and usually have an opinion on this week's incident before it reaches the news.
- Genuinely curious about AI security – both securing AI systems and using AI tooling to work at leverage.
- Can talk to engineers, auditors, and hospital security teams in English without a slide deck translating for you.
Nice to have
- German language skills, since customers and the C5 world are German-speaking.
- Experience in healthcare or another regulated domain.
- Offensive security experience.
- Security certifications such as OSCP, CISSP, or similar.
What they offer
- Remote-friendly company with flexible working hours and workations by arrangement.
- Edenred card for flexible use.
- Extra vacation day to celebrate your birthday.
- Flat hierarchies promoting high performance and strong team dynamics.

