
Cloud Security Engineer
YGO.ai is a VC-funded AI tourism platform. We are hiring a Cloud Security Engineer to own the security of our cloud platform, the APIs our enterprise clients run on and the company itself.
🛡️ About this role. The role carries two things at once. You own security engineering directly and hands-on. You build the security function around it as we grow. At YGO a pod lead is a squad leader and a spokesperson, close to the work and close to the client, rather than a full-time manager. You will not stop being an engineer.
The work is broad. You might review source code in the morning, investigate an endpoint alert after lunch and help design a new authentication flow the next day. You identify the highest-risk problems, decide what happens first and execute.
We serve major travel enterprises and we have enterprise commitments going live from the start of 2027. Security is a condition of that business, not a layer added afterwards.
🧑💻 What you'll own
Application security. Hands-on code and architecture review across our APIs, backend services and internal tooling. Targeted penetration testing to validate issues yourself. Working with engineers on root causes and practical fixes rather than handing over reports. Vulnerability management and the external penetration tests we commission
Detection and response. Knowing we are under attack while it is happening and what happens next. Alerting, intrusion detection, incident process and the on-call path
Cloud and platform hardening. Access control, network boundaries, secrets management, containers and the deployment pipeline. Security through the SDLC: CI/CD, repositories and dependencies
The security of our APIs. Authentication and authorization, tenant isolation, token scoping and lifecycle, abuse prevention, enterprise SSO and the audit trail our clients and our own accountability depend on
The security of our AI systems. Prompt injection, tool and agent permissions, our MCP server, retrieval and data ingestion. The data-residency rules we are held to contractually
Identity and company security. SSO, MFA and privileged access for employees, onboarding and offboarding, access reviews, MDM, endpoint security and SaaS access. The practical IT security a company our size needs done, not discussed
Secure design across the pods. Threat modelling and design review that enables engineers rather than gatekeeping them and raises the standard of what they ship
The security function itself. Set the priorities and the roadmap from actual risk, not security theatre. Decide what we build, buy, automate or leave for later. Grow the team and hire into it, represent security to enterprise clients and carry our SOC 2 programme on Drata. Compliance is part of the job and it is not the centre of it
🚢 What you'll secure
An AI search and recommendation engine for major travel enterprises: enterprise integration, SSO, client security reviews, GDS integrations
A content enrichment API sold as SaaS: high scale, public facing, data and AI heavy
The platform underneath: a client console with organisations, projects and API tokens, supplier and business-client integrations, data ingestion, an MCP server, and several LLM providers behind a single internal library
📚 Our stack
Backend: Go monorepo (no framework, 3+ services)
Data: PostgreSQL, Redis, Redis Asynq queue
Hosting: PaaS-managed containers, Cloudflare in front
Observability: Jaeger tracing, BetterStack for logging, alerting and on-call
Compliance: Drata, SOC 2 in progress
AI tooling: Claude Code, used across the whole team
✅ You must have
5+ years of hands-on security work spanning more than one discipline. Not five years of engineering with some security in it. This role sets the standard for the company, so it needs someone who has seen enough to have judgement rather than opinions
Application security depth. You know how modern web applications and APIs are attacked. You can validate an issue yourself through code review or a targeted penetration test and work with the engineer on the fix
A strong grasp of authentication and authorization. OAuth and OIDC, sessions, token handling, access control and the failure modes behind most API breaches
Cloud security fundamentals, properly. Identity, network, workload and pipeline security on a modern cloud platform, applied to production systems you were responsible for
Defensive experience alongside the offensive. You have investigated real incidents. You have built or improved the detection and alerting that catches them
Threat modelling and secure architecture for cloud, container and API systems
An engineering background. You are comfortable in a codebase, you can review what our engineers and our AI tools produce and you can build what you need yourself. Our backend is Go. Prior Go experience is a plus and not a requirement
Comfort in resource-constrained environments. Startups, small security teams or consultancies taught you to prioritize on risk, business impact and available resources and to execute yourself
The appetite to build a team. You want to grow this function and eventually lead it. Prior leadership experience is a plus and not a requirement. We would rather have depth and develop the leadership than the reverse
Working proficiency with Claude Code. Share specific examples
Judgement about pace. You secure a company that ships daily without becoming the reason it stops. Guardrails over gates
Experience of SOC 2, ISO 27001 or demanding enterprise security reviews
Excellent spoken and written English. You will talk to auditors, client security teams and our own engineers, often in the same week
⚠️ European or African time zones (±3 hours from CET)
Available full-time (40 hours per week)
🌟 Nice to have
AI and LLM security: prompt injection, agent and tool permissions, model security, retrieval pipelines. Very few security roles let you both use AI as your main tool and secure it as your subject. This one does
Early security hire experience. You have been the first or one of the first security hires at a startup or scale-up
Experience leading or mentoring security engineers
Go
Security tooling or automation you built yourself
MDM, endpoint protection and identity provider administration (Google Workspace or similar)
Compliance automation tooling (Drata, Vanta, Secureframe or similar)
Security certifications. Valued as a signal, never required
GDPR depth. Travel or GDS exposure
German
❤️ You are a great fit if you
See security as an engineering discipline. You ship fixes and guardrails, not slide decks
Can explain a vulnerability to an engineer and its business risk to a client's security lead in the same afternoon
Have done offensive work as a penetration tester or consultant and wanted broader ownership than producing reports
Want to build something and own it, rather than advise on someone else's
Are comfortable challenging unnecessary security bureaucracy and genuinely risky engineering decisions alike
Get frustrated when a security fix takes weeks instead of days
Find more English Speaking Jobs in Germany on Arbeitnow
Skills
- Product Engineering
Similar roles

Live Technical Support Representative — Full-Time — $40,000/year + Benefits (Sat-Sun required) (Location: Remote, U.S.-based)
Porkbun·Worldwide
Live Technical Support Representative — Full-Time — $40,000/year + Benefits (Sat-Sun required) (Location: Remote, U.S.-based) It's time to hire another amazing individual again. You could be the pick of the litter! Are you a resourceful problem solver who loves delivering top-notch customer service? Can you provide amazing and personalized phone support? If you’re good at diagnosing technical issues, enjoy helping…
- Remote
- Full-time
Senior Data Analyst (m/w/d)
shopware AG·Worldwide
Shopware ist ein führendes E-Commerce-System, das es Unternehmen weltweit ermöglicht, im digitalen Handel schnell und effizient zu skalieren. Als zukunftsweisende Open-Source-Lösung wird Shopware bereits von einigen der größten europäischen Marken, Einzelhändlern und Herstellern im B2C- und B2B-Bereich eingesetzt. ARR, Umsatz, GMV. Das sind die Kennzahlen, an denen sich unser Management und unsere Shareholder orientieren. Jemand muss die Verantwortung dafür übernehmen,…
- Remote
- Full-time
Software Engineer – Developer Experience / Tooling (Golang/PHP) (m/w/d)
shopware AG·Worldwide
Shopware ist eine international führende Open‑Commerce‑Plattform für ambitionierte Unternehmen im digitalen Handel. Mit einem API‑First‑Ansatz, maximaler Flexibilität und einer starken Community schaffen wir zukunftsorientierte E‑Commerce‑Lösungen. Unsere 450 Mitarbeitenden in ganz Europa teilen eine Leidenschaft für Innovation, Offenheit und Teamgeist. In dieser Rolle arbeitest du an Tools wie der shopware-cli, die viele Entwickler täglich nutzen, um Shopware zu entwickeln, zu testen,…
- Remote
- Full-time
Teamleiter Export / Zoll & Außenwirtschaft (m/w/d)
Hypertrics GmbH·Worldwide
TEAMLEITER EXPORT / ZOLL & AUSSENWIRTSCHAFT (M/W/D) Standort: München | Vollzeit | Unbefristet Für unseren Mandanten, ein inhabergeführtes, europaweit tätiges Familienunternehmen mit Sitz in München und Spezialisierung auf professionelle Reinigungsprodukte, Dosiertechnologie und ganzheitliche Hygienelösungen für Objektreinigung, Gesundheitswesen, Textil- und Küchenhygiene sowie Verkehrsmittelreinigung, suchen wir im exklusiven Auftrag zum nächstmöglichen Zeitpunkt einen Teamleiter Export / Zoll & Außenwirtschaft (m/w/d). Das Unternehmen…
- Remote
- Full-time

Lead Developer — Rebuild, Modernize, & Scale (Social Good SaaS, Remote)
Track it Forward·Worldwide
We are looking for a lead developer to do a greenfield rebuild of our legacy SaaS app, modernize our mobile apps, and lead the tech effort to scale our app. You will help choose the language, build the technical foundation, work with our product manager to rebuild the app, and migrate all customers over. About Track it Forward Track it…
- Remote
- Full-time
ML Engineer
Deeter Analytics·Worldwide
Small private investment firm trading its own capital. One junior ML engineer to work directly with our senior technical lead on an AI system for our own trading. No finance background needed — we hire on fundamentals and side projects you actually shipped. Apply at https://jobs.ashbyhq.com/deeter-analytics/2c12339b-d302-427c...
- Remote
- Full-time
Illustrator/Cartoonist
The Junior Times·Worldwide
Illustrator/Cartoonist Wanted! Help bring a real newspaper for kids to life Freelance · Remote · Monthly printed newspaper · Approximately 10 illustrations per issue The Junior Times is a new monthly printed newspaper for curious kids ages 7-11. We are looking for a freelance illustrator to help give real reporting warmth, personality and visual surprise without making it feel like…
- Remote
- Contract

Head of Sales and Customer Success
secret·Worldwide
THE MISSION Build and lead Secret's B2B business unit: sales and customer success. Create a repeatable revenue engine by selling it yourself first, then build the team that scales it. WHAT YOU'LL OWN Go-to-market - Pck the B2B segments with the highest revenue potential and drive execution. Sales - Discovery, demo, proposal, negotiation, close. You carry the number personally from…
- Remote
- Full-time