As a Senior Security & Compliance Engineer at Codesphere, you will own the security posture of a platform that enterprises and governments across Europe depend on to achieve digital sovereignty – without sacrificing modern cloud capability. Your work directly enables a future where critical infrastructure no longer has to choose between innovation and independence. Security here is not a checkbox – it's the foundation that makes that vision possible.
Activities
- You conduct security assessments, penetration testing, and vulnerability scanning – and drive remediation with development teams
- You manage security scanning tooling (DAST/SAST) and perform security code reviews
- You design and implement security controls across our full technology stack, defining and enforcing standards for development, infrastructure, and data
- You integrate security into our CI/CD pipelines and development processes – Shift Left and DevSecOps in practice, not just on paper
- You develop and maintain our Security Incident Response Plan, monitor security logs via SIEM, and lead forensic analysis when needed
- You ensure compliance with relevant standards and regulations – including GDPR and ISO 27001
- You manage IAM systems with a least privilege approach
- You develop and deliver security awareness training for the whole company – and specialised secure coding training for engineering teams
Requirements
- 5+ years in a security engineering or similar role, ideally in a cloud or SaaS environment
- Hands-on experience with penetration testing, vulnerability management, and DAST/SAST tooling
- Solid understanding of DevSecOps principles and CI/CD security integration
- Familiarity with SIEM tools, incident response, and forensic analysis
- Knowledge of relevant compliance frameworks – GDPR, ISO 27001, and ideally BSI IT-Grundschutz
- Strong communicator – able to translate security risks into clear guidance for both technical and non-technical audiences
- Fluent in English; German is a strong plus given the nature of our compliance landscape
Team
You'll be our second dedicated security hire – working closely with one colleague (based in MUC) to build the function together. That means tight collaboration, real ownership from day one, and a direct hand in shaping how security at Codesphere looks as we scale.
Application Process
- Get-to-know Interview (30 minutes)
- Technical Deep Dive (60-120 minutes)
- Final Exchange (on-site)