
Lead Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Germany.
• Function as the primary dedicated security engineer and a senior individual contributor.
• Serve as Deputy CISO, reporting to the Director of Technology, and establish security engineering from the ground up.
• Develop and manage the security program, tools, and customer-facing security narrative.
• Oversee vulnerabilities across repositories, which includes scanning, dependency updates, remediation processes, and closing findings.
• Collaborate with the Platform team on security-sensitive infrastructure decisions, including customer-managed keys and HSM options.
• Design controls and assist in assessments for ISO 27001 and C5.
• Create the security case for a potential Class IIa medical device under MDR.
• Define scope and monitor penetration tests.
• Address regulatory obligations such as the EU Cyber Resilience Act.
• Generate reusable customer security documentation, evidence, and AI-assisted questionnaires.
• Take part in hospital CISO discussions regarding AI architecture.
• Establish incident response protocols, runbooks, escalation procedures, and manage appropriately sized on-call arrangements.
• Track the threat landscape and convert emerging threats into actionable security measures across the company.
• Set security baselines for devices and accounts as implemented by IT.
• Tackle AI security challenges including agent sandboxing, prompt injection, voice data, and computer-use automation in hospitals.
• 6+ years of experience in software and security engineering.
• Proven track record of owning a security program or a significant portion of one.
• Served as a technical counterpart through at least one ISO 27001, C5, or SOC 2 certification cycle.
• Experience in designing controls, engaging with auditors, and drafting the technical aspects of a Statement of Applicability.
• Background in managing vulnerabilities, including the use of scanners, dependency bots, triage, and follow-through on remediation.
• Strong familiarity with the security landscape, encompassing advisories and incident reports.
• Interest in AI security, particularly agents, sandboxing, and data flows.
• Proficient in communicating with engineers, auditors, and hospital security teams in English.
• Knowledge of German is a plus.
• Experience in healthcare or other regulated sectors is advantageous.
• Experience in offensive security is a plus.
• Security certifications such as OSCP or CISSP are beneficial.
• Legal authorization to work in Germany/the EU is required.
• Meaningful work that positively impacts patients, their families, and healthcare professionals.
• Flat organizational structure and strong team dynamics.
• Flexible working hours.
• Remote-friendly work arrangements.
• Opportunities for workations by arrangement.
• Edenred card.
• Additional vacation day for the employee's birthday.
• Opportunities for professional growth.
Cloudiax
Cisco
Cisco
Skylight
Get handpicked remote jobs straight to your inbox weekly.