Product & AI Security Engineer
Talon.One
Seniority
Midweight
Model
Hybrid
Sector
Salary
Undisclosed
Contract
Full-Time
You'll be one of Talon.One's first two security engineering hires, owning the security of everything we ship to our customers and third-party partners, from API authorization to the AI features going into our platform and their real-time observability and detections. You'll work hands-on, pairing directly with engineers and product managers rather than filing tickets, across a multi-tenant platform that powers promotions and loyalty for some of Europe's largest retail and travel brands.
What you'll do
- Threat-model new product features before they're built, including AI-embedded ones, and turn what you find into real engineering work
- Own tenant isolation and API security across our Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP and third-party integrations
- Act as the security design authority for our AI features, working closely with the team behind UCP and Predict
- Build automated cross-tenant and adversarial testing that runs in CI, so isolation gets checked on every build
- Build standard, frictionless and automated golden paths for code security checks in CI workflows that developers can adopt by default
- Run vulnerability and coordinate efficient patch response across every squad outside Platform
- Build and own application and AI security monitoring with our observability tools and build real-time security detection rules and alerts
- Run a security champions programme so all our tribes build real security capability
What you'll need
- Experience with shipping production code, whether you come from software engineering or from security work that includes coding
- Experience with a multi-tenant SaaS platform's authorization and tenant isolation model, and strong knowledge of how to test for broken object-level authorization automatically
- Design API security end-to-end: authentication, credential lifecycle, rate limiting, abuse resistance and webhook security
- Hands-on experience with threat-modelling methodologies such as STRIDE, translating identified threats into actionable engineering requirements and security tests
- Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows
- Understanding how AI features actually get built, retrieval, context assembly, tool calling, agent loops, and know where indirect prompt injection breaks multi-tenant isolation
- Hands-on experience with Google Cloud security, Kubernetes, and tools like Wiz and Datadog
- Ability to influence engineers who don't report to you, and feel comfortable being early in a function with no existing playbook
What they offer
- €1,000 annual learning budget and free German language courses
- 30 days of annual leave, plus extra paid days for your birthday and moving day
- Home office setup budget and monthly home office allowance
- Mental health support with nilo.health and discounted Urban Sports Club membership
- 20% company subsidy on pension contributions
- Subsidised BVG public transport ticket and dog-friendly Berlin office

