Senior Security Engineer (Europe, Remote)

<p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">Company Overview</span></p> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt">Intel 471 empowers enterprises, government agencies, and other organizations to win the cybersecurity war using the real-time insights about adversaries, their relationships, threat patterns, and imminent attacks relevant to their businesses. The company’s platform collects, interprets, structures, and validates human-led, automation-enhanced intelligence, which fuels our external attack surface and advanced behavioral threat hunting solutions. Customers utilize this operationalized intelligence to drive a proactive response to neutralize threats and mitigate risk. Organizations across the globe leverage Intel 471’s world-class intelligence, our trusted practitioner engagement and enablement, and globally-dispersed ground expertise as their frontline guardian against the ever-evolving landscape of cyber threats to fight the adversary — and win. </span></p> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">The Role</span></p> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt">As a Senior Security Engineer you will own and improve the security of our platform, products and engineering delivery process, with a strong focus on application security, secure SDLC, cloud security and customer-facing compliance. This is a hands-on, build-it-yourself role. You will implement controls, fixes, tooling and detections directly - we are looking for a builder who does the work, not an advisor who hands it to others and waits. You will work closely with Engineering, DevOps, Product and QA, and you will manage one internal Security Engineer who owns corporate, identity and endpoint security and supports you on day-to-day compliance. You will report to the Director, Infrastructure & Security.</span></p> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">Key Duties and Responsibilities:</span></p> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">Product and application security</span></p> <ul> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Application security:</span> Lead application security across the product portfolio - threat modeling, secure design reviews, code-review support, and hands-on remediation work alongside developers.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Secure SDLC and tooling:</span> Embed security into the SDLC and CI/CD without creating unnecessary delivery friction. Build, own and tune security tooling (SAST, DAST, dependency and container scanning, secrets detection) and implement policy-as-code and pre-merge gates in our Terraform and Terragrunt pipelines yourself.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Vulnerability management:</span> Identify, validate, prioritize and remediate vulnerabilities in applications, APIs, infrastructure and third-party integrations, working hands-on with engineering and advising pragmatically on risk trade-offs.</span></li> </ul> <p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">Cloud infrastructure and detection</span></p> <ul> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Cloud security:</span> Own the security posture across AWS and Kubernetes - IAM and network design, encryption, logging baselines, configuration drift and cloud security posture management.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Detection and response:</span> Build and tune cloud detections (CloudTrail, GuardDuty, Security Hub), write runbooks, and act as the technical security lead for product and cloud incidents, partnering with DevOps for investigation and containment. This role is the security escalation point for incidents; there is no primary tier-1 pager rotation.</span></li> </ul> <p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">Compliance and customer trust</span></p> <ul> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Audit ownership:</span> Own and drive our SOC 2 and ISO 27001 programs end to end - control design, evidence automation and primary auditor liaison - and maintain policies and control documentation in Confluence. The internal Security Engineer runs the day-to-day evidence pipeline and supports you.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Customer assurance:</span> Support sales and customer trust by completing security questionnaires, explaining our technical controls, and handling follow-up from customer audits and assessments.</span></li> </ul> <p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">Architecture and leadership</span></p> <ul> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Security review:</span> Drive the security review of new features, architecture decisions, integrations and platform changes, especially where customer data, authentication, authorization or data-processing risks are involved.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Manage and mentor the Security Engineer:</span> Manage, mentor and develop our internal Security Engineer, including 1:1s, performance reviews, leave approvals and day-to-day delegation. Corporate IT, identity and endpoint security are owned by them, not by you, so you can focus on product and cloud security.</span></li> </ul> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">Education, Experience & Qualifications</span></p> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">Ideal Profile</span><br></p> <ul> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Hands-on builder, not an advisor:</span> You implement security yourself - controls, fixes, tooling and detections - rather than handing work to others and waiting for it to happen. This is a doing role.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Product and cloud security depth:</span> Strong hands-on background in application security and secure software development in cloud-native environments (AWS, Kubernetes, CI/CD, containers, infrastructure-as-code).</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Comfortable in code:</span> Comfortable reading code, reviewing APIs and architecture, and working directly with developers on remediation.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Compliance driver:</span> Proven ability to drive SOC 2 and ISO 27001 workstreams, from control design to auditor interaction, not only evidence collection.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">People leadership:</span> Able to manage and develop one engineer, including delegation, 1:1s and performance.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Pragmatic communicator:</span> Balances hands-on technical work with the process discipline of enterprise B2B SaaS, and explains risk clearly to engineers, leadership, auditors and occasionally customers.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">AI-forward:</span> Comfortable using AI and LLM tools day to day and genuinely open to adopting them further. Deep AI-security expertise is not required, but a fundamental willingness to engage with AI is expected; an unwillingness to work with AI is not a fit.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt"><span style="font-weight: bold">Atlassian native:</span> Works day to day in the Atlassian stack (Jira, Confluence) as our primary documentation and workflow systems.</span></li> </ul> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">Nice to Have</span><br></p> <ul> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">Experience securing AI/LLM or agent-based features (prompt injection, tool and agent permissions, model-access controls).</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">Hands-on familiarity with the security and observability platforms we use, such as Snyk, Rapid7 and Grafana Cloud, and with Microsoft Sentinel for cross-team investigations.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">Experience in cyber threat intelligence, attack surface management, threat hunting or other security-product environments.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">Prior experience in a PE-backed or scale-up software company where security, compliance and delivery speed all matter.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">Prior experience working as a software engineer or in a DevOps role.</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">Certifications such as CISSP, CSSLP, OSCP, AWS Security Specialty, CKS, ISO 27001 Lead Implementer or similar, helpful but not required.</span></li> </ul> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">Benefits</span></p> <p><br></p> <ul> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">Competitive compensation</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">Remote-friendly culture</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">Wellness programs</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">Employee recognition program</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">A variety of professional development opportunities</span></li> <li><span style="font-family: Inter, sans-serif; font-size: 12pt">Inclusive culture focused on people, customers and innovation</span></li> </ul> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt; font-weight: bold">Our Culture</span></p> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt">The Intel 471 team is constantly growing and is always on the lookout for talented professionals who seek to operate on the forefront of the fight against threat actors impacting our customers and partners. Our culture of humility and quiet professionalism is a core attribute of Intel 471 and everyone within it. Our culture is collaborative, supportive and fast-paced. We are a mission-driven company looking for talented, can-do minded people with a passion for always doing the right thing.</span></p> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt">We believe in supporting a progressive culture that allows all our people to be themselves, enjoy exciting opportunities and grow with us. That's why our culture is founded on our core values of openness, inclusion, integrity and client focus, which set the tone for how we work together and treat each other in order to empower us all – and foster a unique team spirit. View our <a href="https://intel471.com/company/careers" target="_blank" rel="noopener noreferrer">Culture Guide</a> to find out more about us and what it’s like to work for Intel 471!</span></p> <p><br></p> <p><span style="font-family: Inter, sans-serif; font-size: 12pt">By applying to this role, you confirm that you're willing to show your ID on a video call to confirm your identity.</span></p>

Back to blog