Catawiki logo

Lead Security Engineer

Catawiki

Amsterdam
Full-time
10+ years experience
On-site

Key Skills

Application Security
Cloud Security
Google Cloud
Kubernetes
Identity and Access Management
Secrets Management
Secure Software Development
Threat Modeling
Secure Code Reviews
CI/CD Security
Infrastructure as Code
Security Automation
Vulnerability Management
Incident Response
Ruby
Python

Job Description

About the role and team As our Lead Security Engineer, you’ll provide hands-on technical leadership in our small Security team within Platform Engineering. You’ll shape the security engineering roadmap and own the delivery of complex security initiatives, working with Product and Platform Engineering to protect our marketplace, our customers and their data. Our platform runs on Google Cloud and Kubernetes. You’ll focus on application and cloud security, secure software delivery and risks in internal and AI-enabled systems. You’ll combine deep technical work with influence across engineering, turning security risks into controls and practices that teams can use in their everyday workflows. This is an individual contributor role. As the team evolves, there may be an opportunity to move into people management, based on demonstrated readiness and business needs. What you will do Shape the security engineering roadmap and lead complex initiatives from assessment and design through implementation, rollout and ongoing operation. Design and build security controls and automation across applications, cloud infrastructure, identity and access, CI/CD and infrastructure as code. Lead threat modelling and secure code and design reviews. Work with engineering teams early to identify risks and agree practical changes before systems reach production. Investigate vulnerabilities and recurring security weaknesses. Prioritise findings based on exposure and business impact, work with system owners on remediation and build reusable controls that prevent recurrence. Improve security checks in engineering workflows, including dependency and secret scanning. Reduce false positives and make findings easier for developers to understand and resolve. Contribute to security incident investigations and response. Improve detection and response tooling and use lessons from incidents to strengthen preventive controls. Mentor security engineers and help product engineers build security skills through technical guidance, documentation and practical training. Work with Legal, IT and Trust & Safety on technical security controls, policies and audit evidence where responsibilities overlap. Measure the effectiveness and adoption of the controls you deliver. Communicate progress, technical decisions and remaining risks clearly to engineering and business stakeholders. Who you are You have substantial hands-on security engineering experience in a software or cloud environment and a track record of delivering security improvements across multiple teams. You have strong knowledge of application and cloud security, including identity and access management, secrets management and secure software development. You have led threat modelling, secure code and design reviews and complex remediation work, turning findings into solutions that engineers adopt. You can develop or automate in Ruby, Python, Go or a similar language and are comfortable reviewing backend code. You have built and operated security tooling or controls in production. You have integrated security into CI/CD, cloud infrastructure or infrastructure as code and can make sound trade-offs between risk reduction and engineering effort. You have contributed to security incident investigations or responses and can work effectively with others under pressure. You have led technical initiatives and mentored engineers. You’re interested in developing your leadership skills, including potentially taking on people management in the future. You influence through technical credibility and collaboration, explain risks clearly to different audiences and take responsibility for seeing complex work through to completion.

Core Responsibilities

Lead the security engineering roadmap and deliver security controls and initiatives across applications, cloud infrastructure, identity, CI/CD, and infrastructure as code. Guide threat modeling, vulnerability remediation, incident response, developer security practices, and cross-functional security work while measuring control effectiveness and communicating risks.

Requirements

Requires substantial hands-on security engineering experience in software or cloud environments, with a track record of delivering improvements across teams and operating production security controls. Candidates should have strong application and cloud security expertise, be able to automate or develop in Ruby, Python, Go, or a similar language, and have experience leading technical initiatives, incident response, and mentoring engineers.

About Catawiki

Industry: Internet Marketplace Platforms

Company size: 501-1,000 employees

Catawiki is the leading online marketplace for special objects. Over 100,000 objects are offered in auction every week - each reviewed and selected by one of Catawiki’s hundreds of in-house experts specialised in Art, Design, Jewellery, Fashion, Classic Cars, Collectables and much more. Catawiki is headquartered in Amsterdam with over 750 employees across the world.

Added 2 days ago