Catawiki logo

Security Tech Lead Manager

Catawiki

Amsterdam
Full-time
5-10 years experience
On-site

Key Skills

Security Engineering
People Management
Application Security
Cloud Security
Google Cloud
Kubernetes
Identity and Access Management
Secrets Management
Threat Modeling
Secure Code Review
Vulnerability Management
Incident Response
CI/CD Security
Infrastructure as Code
Security Automation
Ruby, Python, or Go

Job Description

About the role and team As our Security Tech Lead Manager, you’ll manage a team of 2–3 security engineers within Platform Engineering and remain hands-on. You’ll own the security engineering roadmap and take responsibility for the team’s delivery, performance and development. Working with Product and Platform Engineering, you’ll help protect our marketplace, our customers and their data. Our platform runs on Google Cloud and Kubernetes. You’ll focus on application and cloud security, secure software delivery and risks in internal and AI-enabled systems. You’ll turn security priorities into engineering work, make clear trade-offs and help teams adopt controls that fit their everyday workflows. What you will do Manage and develop the security team through regular one-to-ones, timely feedback, performance reviews and career development. Address underperformance and support hiring and onboarding. Own the security engineering roadmap. Prioritise work based on risk, business needs and team capacity, delegate effectively and remove blockers to delivery. Stay hands-on by building security controls and automation, reviewing code and guiding technical decisions across applications, cloud infrastructure and software delivery. Partner with Product and Platform Engineering early in design. Lead threat modelling and security reviews, and help teams choose secure approaches that are practical to implement. Improve vulnerability management. Assess findings in the context of exposure and business impact, agree remediation priorities with system owners and track issues through resolution. Improve security checks in CI/CD and infrastructure as code, including dependency and secret scanning. Reduce false positives and help engineers act on findings. Coordinate the security team’s technical contribution to incident response and investigations. Turn lessons from incidents into improvements to detection, response and preventive controls. Work with Legal, IT and Trust & Safety on security controls, policies and audit evidence where responsibilities overlap. Measure and communicate progress through remediation times, control coverage and adoption. Explain remaining risks, delivery progress and trade-offs to technical and business stakeholders. Who you are You have substantial hands-on security engineering experience in a software or cloud environment and have implemented and operated security capabilities in production. You have previously managed engineers as direct reports, including performance reviews, career development and difficult feedback. You can balance people management with technical contribution. You have owned a security roadmap or programme, translated priorities into deliverable work and coordinated implementation across engineering teams. You have strong knowledge of application and cloud security, including identity and access management, secrets management and secure software development. You are experienced in threat modelling, secure code and design reviews, vulnerability prioritisation and practical incident response. You can develop or automate in Ruby, Python, Go or a similar language, are comfortable reviewing backend code and have integrated security controls into engineering workflows. You communicate clearly with engineers and non-technical partners, explain risk in business terms and gain support for decisions when priorities compete.

Core Responsibilities

Manage and develop a team of security engineers while remaining hands-on, owning the security engineering roadmap and delivering security controls across applications, cloud infrastructure, and software delivery. Partner with engineering and business teams on threat modeling, vulnerability remediation, incident response, audit evidence, and communicating security risks and progress.

Requirements

Requires substantial hands-on security engineering experience in software or cloud environments, prior direct management of engineers, and experience owning a security roadmap. Candidates should have strong application and cloud security expertise, practical incident response and threat modeling experience, programming or automation skills, and the ability to communicate risk to technical and non-technical stakeholders.

About Catawiki

Industry: Internet Marketplace Platforms

Company size: 501-1,000 employees

Catawiki is the leading online marketplace for special objects. Over 100,000 objects are offered in auction every week - each reviewed and selected by one of Catawiki’s hundreds of in-house experts specialised in Art, Design, Jewellery, Fashion, Classic Cars, Collectables and much more. Catawiki is headquartered in Amsterdam with over 750 employees across the world.

Added 2 days ago