
Langdock · Berlin
HELP US CHANGE THE WAY THE WORLD WORKS BUILD SOMETHING THAT MATTERS. Langdock exists to change the way the world works, bridging the gap between what techn...
Langdock exists to change the way the world works, bridging the gap between what technology can do and what people actually do
with it. We bring all leading AI models into one secure, model-agnostic platform and make them usable across entire organizations.
Over 10,000 companies use our platform every day, from fast-growing startups to some of Europe's largest enterprises. Their
employees open Langdock to draft strategies, analyze documents, or automate workflows - helping them to work smarter, think more
creatively, and reach their full potential.
We're hiring a hands-on Security Lead to own security at Langdock across all surfaces. Not just the management system, but the
actual security of our identities, devices, premises, and processes.
This is a broad ownership role, deliberately scoped for one ambitious person. We believe that with good automation and an AI-first
way of working, one person can run what traditionally takes a small team: the certified ISMS, identity and access management,
device management, security programs like bug bounty, and physical security. You'll use automation (and Langdock itself)
aggressively to keep the operational load low and the bar high.
You'll design technical and organizational controls that enable us to run our business securely and that actually make sense for
how we build and operate. You'll also make sure we can prove they work, quarter after quarter, audit after audit.
You'll work closely with engineering, operations, and sales by translating security and compliance requirements into controls
people can realistically implement and maintain, and explaining our security posture to customers who consider Langdock.
offboarding, and privilege provisioning so the right people have the right access at the right time, and nothing more.
with the tools our teams actually use.
with as little friction for the team as possible.
them to resolution with engineering.
customers expect.
management system, ensuring it reflects how Langdock actually operates, not just how a framework says it should.
genuinely reduce risk.
closure with the relevant owners.
lead scoping and readiness for new standards as the business requires (e.g. C5, TISAX, HDS, FedRAMP-adjacent requirements,
customer-specific frameworks).
controls in ways that fit into existing workflows (CI/CD, infrastructure, access management) rather than bolting security on
afterward.
as something to be automated. Use AI tooling as a force multiplier so this role scales with the company without scaling
headcount.
SaaS products are actually built and operated. Enough to have credible, specific conversations with engineers, and enough to
configure Entra ID, MDM, and provisioning automation yourself rather than just specifying it.
take a team and you're excited to prove it. You build scripts, workflows, and agents instead of doing repetitive work by hand.
least-privilege and just-in-time access, MDM rollout and policy design.
least one full audit cycle, ideally at a growth-stage SaaS or tech company.
"why," not just enforce the "what."
We work from our office in Berlin, Greifswalder Strasse 212. Everyone works together in person because the hardest problems get
solved faster at a whiteboard than in a Slack thread. Conversations happen faster, problems get solved quicker, and we actually
know each other.
Days start at 8:30. Lunch & dinner are together. We run, go to the gym, and take care of ourselves. Health is not separate from
work here, it is part of how we work well.
The vibe is calm but intense. No one is yelling or panicking. But everyone is working hard on things that matter.
Salaries are transparent and tied to levels, not negotiation. All roles include equity.
We will figure out the right level together based on your experience and scope. Levels are about the work you own, not your title
or years of experience. We narrow down the expected salary range early in the process.
We move fast. Most processes complete within two weeks.
If this sounds like your kind of work, we would like to meet you.
At Upvest, we are on a mission to make investing as easy as spending money. Upvest empowers businesses to offer a wide range of investment products and the best experience in the field of capital market investment and retirement planning. Upvest’s Investment API is easy to integrate so that fintechs and financial institutions can save resources and fully focus on their core business. We are proud to partner with Europe’s leading Fintechs and financial institutions such as DKB, Revolut, N26 and Raisin. Founded in 2017 by Martin Kassing, Upvest now brings together over 270 talented professionals from more than 70 nationalities. Upvest is backed by €280M in total funding from world-class investors, including BlackRock, Tencent, Sapphire Ventures, and Bessemer Venture Partners, Earlybird, Notion Capital, and Motive. Our latest €105M funding round in March 2026 - led by Sapphire and Tencent - serves as a massive catalyst for our growth, allowing us to offer premier investment experience. ABOUT THE ROLE: Upvest is at the inflection point where security needs to scale and remain a foundational discipline of the company. We're hiring a Security Engineering Lead to step into our lean and efficient Security team, set its multi-quarter direction, work cross-functionally and scale Security Engineering into a team that continues to own Upvest's entire application security and cloud security posture in a highly regulated environment as it scales. This role sits alongside our Security Operations and GRC teams, which owns detection, response, and compliance operations. Where SecOps keeps watch over what's happening now, Security Engineering shapes what we build and how we build it, embedding security into the SDLC, hardening our cloud environment, and building the platforms that make security teams more effective. You will own the secure paved roads every Upvest engineer relies on: automated SAST/DAST/SCA in our GitHub Actions pipelines, SSDLC adherence, IAM and network controls, and the technical implementation of DORA's (and other regulations') ICT risk framework for our platform. Our mission for the team is simple: make the secure way the easy way for everyone at Upvest. WHAT YOU’LL DO: * Set the multi-quarter strategy for application and cloud security across Upvest's Investment API platform — aligned with our product roadmap, our tenant commitments, and our regulatory obligations under DORA, MiFID II, and BaFin's MaRisk / BAIT requirements. * Lead, mentor, and grow our Security Engineering and Upvest's security culture. You'll inherit a small, talented team and own hiring, onboarding, growth, and retention as we scale. And you'll create initiatives to build security into the development and product life cycle. * Build paved roads. Own how Upvest performs encryption, authN/authZ, CI/CD, data, and network surfaces. We want fewer security review queues and more security baked into the templates. * Own application security end-to-end. Threat modeling, secure code review, SAST/DAST/SCA tooling integration in our GitHub Actions CI/CD, and vulnerability management. * Drive better cloud security posture across our GCP environment — IAM, VPC Service Controls, Cloud KMS, CSPM (Wiz), Binary Authorization for GKE, Terraform-driven infrastructure security baselines, and our Linkerd service mesh posture. * Mature Upvest's DORA technical implementation. Partner with our risk and compliance functions to translate DORA's ICT risk framework (Art. 5–9), secure development testing requirements (Art. 16), and threat-led penetration testing (Art. 24–27) into engineering work programmes — and into evidence we can show auditors and regulators. * Embed security in every product design. Partner deeply with product and engineering teams. Architecture reviews, design partnerships, security champions across product squads, collaboration beats gatekeeping. * Stay current on emerging threats. AI / LLM security, agentic identities, and the secure use of AI tooling in our own engineering workflow are an active concern * Represent Upvest's security posture clearly to everyone WHAT YOU BRING: * 6–10 years in security engineering, with 4+ years focused on product security or cloud security, and you work well in a regulated environment. You don't need to check every box, but we're asking for evidence that you've taken security from "owned by one team in a queue" to "embedded in how an engineering org ships." * Hands-on, technically credible. You earn the trust of engineers by going deep, so you're comfortable reading code, threat modeling designs, debating architectures, and writing tooling when it's valuable. * Cloud-native security depth. GCP preferred; AWS or Azure transferable. You know IAM, network segmentation, KMS, IaC security (Terraform), and Kubernetes hardening (RBAC, network policies, Pod Security Standards) as a craft. * Product/Application security foundations. OWASP Top 10 / ASVS, secure code review, SAST/DAST/SCA tooling integration, supply-chain security (SLSA, signing). * Lead through influence, not gatekeeping. You drive security outcomes through partnership with engineering teams. You can navigate ambiguity, set direction, and make sound risk-based decisions that scale with the organisation. People want to work with you, because you don't just say "no", you say "yeah, and this is how". * Hire and grow people. You've built or grown a small team. You set a high bar in interviews, invest in onboarding, give real-time feedback, and address performance issues quickly and fairly. Communicate cleanly across audiences e.g. a security incident write-up to engineering, a control narrative to an auditor, and a risk briefing to executives are three different documents, and you can write all three. NICE TO HAVE: * Experience securing multi-tenant B2B platforms or financial-API products: tenant isolation, API-as-product safety boundaries, and the specific operational shape of selling to regulated customers. * Experience with trading, custody, or securities settlement platforms, or curiosity about that domain. * Bug bounty / VDP programme management. * In a past life, you have shipped backend code in production, and you're comfortable in Go (preferred), Python, or another modern backend language. * Regulatory fluency. Working knowledge of DORA, MaRisk, BAIT, ISO 27001. You can change audit-speak or regulation into actionable technical requirements other people understand. You can hold your own with auditors and regulators without losing engineering pragmatism. * Background in engineering and offensive security * German skills are useful for some potential client interactions, but not required. Our working language is English. * Hands-on experience with AI/LLM security, agentic identity, or securing AI tooling in an engineering workflow. * Familiarity with the operational side of security is a bonus, hands-on experience with EDR and SIEM platforms, or a background in incident response. This matters in practice, you'll be part of the security on-call rotation, so being comfortable picking up an active incident is real, not theoretical. HOW WE UPVEST IN YOU: * Best-in-class AI tools: Every Upvenger has €20,000 per year to spend on the best AI tools available — so you're always working with the most powerful models and tooling on the market. * Impact-driven work: We’re building the infrastructure that will power the future of investing in Europe. It’s complex, ambitious, and meaningful. You’ll work with modern technologies and create something entirely new. No legacy systems, no limits. * Wellbeing: Recharge with 30 days of annual leave and maintain a healthy lifestyle with sports benefits. Access confidential professional coaching and enjoy the flexibility to work remotely abroad for up to 183 days a year. Recharge with UpRest, a one-month fully paid sabbatical after every 4 years of working at Upvest. * Development: Growth is in our DNA. Each Upvenger has access to a personal development budget and the freedom to decide how to use it. * Flexible work environment: Work from any of our hubs in Berlin, London or Tallinn hybrid or remotely across Europe, depending on the role. We give you the choice and budget to work where you’re most comfortable and productive, either at home or in the office. You choose. * Compensation and equity: We believe that all Upvengers contribute to our success and deserve a competitive, above-market salary and a participation in our employee equity program. * Team celebrations: Participate in company-wide events, such as UpFest, dinners, offsites and our Holiday party, to connect with colleagues and celebrate our achievements. * Inclusion: We’re committed to a culture where everyone belongs and thrives. Our Employee Resources Groups foster inclusion and connection, like Upfem for our female Upvengers, or UpVergent supporting neurodivergent Upvengers and allies. OUR VALUES: * Make it easy for others. We simplify the complex and act with the best intentions. * Own the outcome. We are proactive, fast and confident to get the job done, valuing progress over perfection. * Rise to the challenge. We aim high and push the boundaries. We stay curious, learn and celebrate our wins together. * Tell the story. We start with the Why to align on purpose. We are transparent and share knowledge to empower and inspire others. Upvest is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
ABOUT US: SRLabs is home to knowledge leaders securing critical infrastructures in finance, energy, and telecommunications. We focus on hands-on hacking resilience – not compliance – by combining cutting-edge hacking research with impactful consulting work for innovation-driven organizations. What makes us unique? We are a diverse, international team of experts who thrive on solving complex problems. Our backgrounds span coding, reverse engineering, penetration testing, exploit scripting, research, and consulting. This broad mix enables us to influence the security design of large-scale organizations. As our team grows, we are expanding our Defensive Capabilities and are looking for an experienced Senior Digital Forensic Specialist to strengthen our work in incident response, forensics, and client resilience. YOUR RESPONSIBILITIES In this role, you will take the lead on technical forensic investigations , applying deep expertise to analyze attacks, uncover evidence, and provide resolution strategies. You will operate in complex, large-scale environments, handling unique incidents and helping organizations recover while building long-term resilience. You will also help clients improve their defensive capabilities and their cyber security maturity by doing assessments, threat hunting and technical analysis. You will work alongside hackers, researchers, and consultants to investigate attacks, contain incidents, and strengthen defenses within organizations. RESPONSIBILITIES * Be the trusted advisor for clients, maintaining strong and lasting relationships, even during crisis situations. * Lead forensic investigations, compromise assessments, and threat hunting activities. * Conduct incident response activities from detection and containment through to remediation and recovery. * Collaborate with incident responders to manage large-scale, complex security incidents. * Provide clear, actionable recommendations to clients in high-stakes situations. * Produce high-quality technical reports and presentations tailored to both technical and non-technical audiences. * Conduct technical trainings and workshops for clients and internal teams. Mentor junior consultants on projects requiring your expertise and guidance. * Engage in research and stay up to date on the latest best practices and techniques. WHAT DO YOU BRING? * Proven experience (at least 3 years) in IT Security Consulting, with a strong focus on incident response and digital forensics. * Expertise in at least two technical topics (incident response, digital forensics, threat intelligence, threat hunting, threat research, incident remediation, vulnerability research, cloud security, security architecture, SIEM, SOC, ...) * Strong analytical and problem-solving skills, ability to think quickly in high-stakes situations. * Experience in writing clear technical documentation and delivering client-facing presentations. * Excellent collaboration and teamwork skills, especially under crisis conditions. * Curiosity and willingness to constantly learn, staying ahead of attackers. * Excellent verbal and written English; German proficiency is a plus. * Willingness to travel when required. WHAT AWAITS YOU WITH US? * A diverse, highly motivated, and skilled security team. * Work that creates real impact for organizations and society. * A culture of continuous learning and improvement. * Flexible home office options. * Annual company retreat. * Urban Sports Club membership. * Deutschland ticket (public transportation). * 30 days of paid vacation. APPLY NOW We are looking forward to getting to know you and discuss the opportunity. We value diversity and encourage candidates from all backgrounds – especially those from underrepresented groups in IT security
ABOUT US: SRLabs is home to knowledge leaders securing critical infrastructures in finance, energy, and telecommunications. We focus on hands-on hacking resilience – not compliance –, which we shape by combining our hacking research with impactful consulting work for innovation leaders that have a natural thrive for cutting-edge technologies. What makes us unique? We come from diverse backgrounds from all over the world, and that's just the way we like it. From coding, reverse engineering, penetration testing, exploit scripting, process design, research and consulting skills, our mix of colleagues possesses a vast set of qualifications, that equips us to influence design decisions of large-scale organisations. YOUR RESPONSIBILITIES Job brief: As a Red teamer at SRLabs, you work in a small and specialised team simulating infiltrations of corporate environments with high levels of protection for our clients. From obtaining initial access via external vulnerabilities or phishing, over lateral movement and to a domain takeover, you take part in the full chain of emulating adversarial cyber attacks. To remain undetected and complete your mission, you are able to avoid noise and bypass detection solutions and other protection measures. You analyze protection and monitoring gaps for their technical and operational root causes, and provide actionable steps for closing these gaps, bearing in mind the customer specific constraints our clients are facing. Your strategic advice supports the management in defining the security roadmap and employing security budget most effectively. Your Responsibilities: * Participate in red team engagements at SRLabs' clients * Perform external penetration testing and run phishing campaigns * Bypass protection measures and move undetected inside corporate networks * Develop tools, scripts and exploits for red team engagements * Create presentations to communicate risk and provide strategic advice on process optimizations * Support the client in addressing findings, in both, written and verbal communication * Develop methodologies to extrapolate from Red Team insights to generic security assurance checks * (Optional) Lead red team exercises and take responsibility for what comes with it (scoping, task management, escalations, ...) WHAT DO YOU BRING? What do you bring: * Strong foundational knowledge of information technology, including (Operating systems, Networking and Web technologies) * Hands-on experience in offensive security and red teaming * Solid experience with Active Directory and Entra ID security * Experience in client-facing roles or security consulting, including (presenting technical findings to diverse audience and provide strategic advice to clients) * Infrastructure and web penetration testing * Proficiency in programming languages such as: * Python, C/C++, Go, Java * Excellent communication skills in English (written and verbal) Nice to have Relevant expertise from areas like * Malware delivery and development * Incident response * Vulnerability research and exploit development * Reconnaissance, OSINT and social engineering * Operational security and bypassing of security measures (AV/EDR, endpoint and infrastructure hardening, SIEM generated alerts, Honeypots, ...) * Detection engineering and SOC operation * Experience in management consulting and communication WHAT AWAITS YOU WITH US? What awaits you with us: * Diverse team of highly motivated and competent security experts * Culture of constant learning and improvement * Flexible home office. * You can work from anywhere in Germany * Yearly company retreat * Urban Sports Club membership * Deutschlandticket (public transportation) * 30 days paid vacation APPLY NOW We are looking forward to receiving your application.