
Security Lead
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Germany.
• Take ownership of cloud and application security, encompassing AWS security architecture, IAM, network security, and secure configuration management.
• Propel and enhance application security practices, which include secure coding guidance, support for threat modeling, and automated security testing throughout the SDLC.
• Oversee the incident response program, which includes playbook development, on-call readiness, threat detection, and coordination of responses.
• Manage vulnerability management processes to ensure that risks are identified, triaged, and effectively remediated in collaboration with engineering teams.
• Maintain and evolve security tools, including monitoring, logging, SIEM/alerting, and secrets management.
• Work closely with engineering and platform teams to integrate security considerations into design and architectural decisions.
• Contribute to the unified control framework to ensure robust security foundations for ISO 27001 and SOC 2 compliance.
• Oversee corporate and IT security, including endpoint management (e.g., MDM), identity and access management, and supervision of the external IT provider.
• Lead security reviews conducted by our customers, acting as a reliable and trusted partner to enterprise clients during their evaluation process.
• Remain proactive regarding emerging threats, technologies, and best practices to continuously enhance Apheris’ security posture.
• A degree in computer science, engineering, or equivalent practical experience in technical roles.
• 5+ years of experience in security engineering, cloud security, application security, or other related technical security roles.
• Hands-on expertise in AWS security architecture, identity and access management, network security, and contemporary DevOps practices.
• Experience in implementing or supporting secure development lifecycle (SDLC) practices, closely collaborating with engineering teams.
• Strong understanding of modern authentication, authorization, secrets management, and security in infrastructure-as-code.
• Proven experience in managing security incidents, vulnerability management, or threat detection.
• Demonstrated experience with security and compliance expectations in large enterprises, including insights into how major corporations conduct security reviews and vendor due diligence processes.
• Experience in maintaining compliance programs such as ISO 27001 or SOC 2.
• Ability to foster strong relationships within engineering and influence secure design decisions.
• A practical, solution-oriented mindset that balances security, usability, and efficiency.
• Experience in mentoring team members and assisting them in developing their security skills.
• Industry-competitive compensation, including early-stage virtual share options.
• Remote-first working environment – work where you are most productive.
• Wellbeing budget, mental health support, work-from-home budget, co-working stipend, and learning budget.
• Generous holiday allowance.
• Office Days at our Berlin HQ or an alternate European location (three times a year).
• A high-caliber, execution-focused team with experience from top organizations.
Quisitive
Cisco
Highmark Health
BlackStone eIT
Get handpicked remote jobs straight to your inbox weekly.