
Farfetch · Porto
Farfetch is a leading global marketplace for the luxury fashion industry. The Farfetch Marketplace connects customers in over 190 countries and territories with...
Farfetch is a leading global marketplace for the luxury fashion industry. The Farfetch Marketplace connects customers in over 190 countries and territories with items from more than 50 countries and over 1,400 of the world’s best brands, boutiques, and department stores, delivering a truly unique shopping experience and access to the most extensive selection of luxury on a global marketplace.
We're on a mission to build end-to-end products and technology that powers the an incredible e-commerce experience for luxury customers everywhere, understanding the motivations and needs of our customers and partners, to designing and testing hypotheses, to creating industry-leading experiences for luxury customers.
Our office is near Porto, in the north of Portugal, and is located in a vibrant business hub. It offers a dynamic and welcoming environment where our employees can connect and network with a large community of tech professionals.
As the regional lead for our Detection, Analysis, and Response Team (DART) in Portugal, you will serve as the "special forces" commander for our security organization. You will lead a high-caliber team of incident responders, maintaining a calm and collected demeanor during high-pressure situations while thinking critically as both an attacker and a defender.
This position is uniquely based at the Farfetch office in Porto, where you will split your leadership and technical expertise between Coupang Corp and Farfetch. You are responsible for overseeing the detection and neutralization of credible threats, developing advanced detective capabilities, and fostering a culture of relentless problem-solving within the regional unit.
Farfetch is a leading global marketplace for the luxury fashion industry. The Farfetch Marketplace connects customers in over 190 countries and territories with items from more than 50 countries and over 1,400 of the world’s best brands, boutiques, and department stores, delivering a truly unique shopping experience and access to the most extensive selection of luxury on a global marketplace. TECHNOLOGY We're on a mission to build end-to-end products and technology that powers the an incredible e-commerce experience for luxury customers everywhere, understanding the motivations and needs of our customers and partners, to designing and testing hypotheses, to creating industry-leading experiences for luxury customers. PORTO Our office is near Porto, in the north of Portugal, and is located in a vibrant business hub. It offers a dynamic and welcoming environment where our employees can connect and network with a large community of tech professionals. THE ROLE As a vital member of our Detection, Analysis, and Response Team (DART) - the specialized Incident Response unit within our Security Response team - you will serve as the "special forces" of our security organization. In this role, you must maintain a calm, collected demeanor during high-pressure, time-sensitive situations while thinking critically as both an attacker and a defender. You will collaborate with cross-functional teams to analyze, respond to, and neutralize threats with precision and speed. Security Response is responsible for responding to credible threats by developing advanced detective capabilities and identifying mitigations for complex vulnerabilities. Our DART Engineers are relentless problem-solvers who gather and analyze event data to conduct thorough root-cause analyses. This position is based at the Farfetch office in Porto, Portugal. The successful candidate will split their time and responsibilities between Coupang Corp and Farfetch, providing high-level security expertise to both organizations.
Join Telavox as a Security Engineering Lead 🔐 Are you a hands-on security engineer who enjoys being close to the code, the systems, and the teams building them? At Telavox, security is not a gate at the end of development. It is an embedded capability that enables us to move fast, safely, and at scale. Telavox is a fast-growing digital telco that combines the reliability of telecom with the agility of SaaS across Europe and across the globe. As our platform grows, security becomes a force multiplier - not just protecting what we build, but actively enabling engineers to ship better and safer software every day. We are looking for a Security Engineering Lead to join our engineering organisation. In this role, you will sit at the heart of our platform, working embedded across product and platform teams to make security a built-in property of every system we ship. About the job As a Security Engineering Lead, you are the engineering execution layer that makes security real across the Platform organisation. You work embedded with product and platform teams - detecting and responding to threats, building tooling that improves security posture at scale, and enabling engineers to own security in their domains. You bridge the gap between the CISO’s strategic direction and day-to-day engineering reality, turning security goals into concrete engineering outcomes. Your day-to-day work includes: Triage and coordinate responses to emerging threats – assess severity, involve the right teams, and drive issues to resolution Own and evolve vulnerability scanning, SAST/DAST, secrets scanning, and infrastructure scanning across code and production systems Drive concrete security initiatives such as unified RBAC, network segmentation, and service-to-service security models, from concept to production Work directly with engineering teams to translate risk into actionable work in the product development process Embed security practices into engineering workflows so teams can ship securely by default The role is based either at our new HQ in Malmö or in our Stockholm office. About you You are a pragmatic, hands-on security engineer who thrives working deeply in systems and closely with engineering teams. You are comfortable moving between code, infrastructure, and architecture discussions, and you care about making security scalable, practical, and usable. You believe security works best when it is distributed, automated, and embedded, not bolted on in the end. You think ahead about what embedded security looks like when engineering is increasingly AI-augmented — agent credentials, MCP and tool-use boundaries, and secure-by-default workflows for code that humans and models write together. We are looking for someone with: A hands-on background in software or platform engineering, with real comfort in the terminal - able to run scans, inspect output, and file a PR when needed Demonstrated experience with the security tooling landscape: vulnerability management, SAST/DAST, secrets scanning, and infrastructure scanning - understanding trade-offs, not just installation A teaching and enabling mindset - sharing knowledge, running hands-on deep-dives, and leaving capability behind rather than creating dependency Strong ability to collaborate with engineers and translate security risks into practical engineering work Fluent English, written and spoken. Swedish is a plus Join us at Telavox 💚 Since Telavox's journey started in 2002, we have strengthened our position as the leading forward-thinking communication platform for businesses. As a digital mobile operator, we develop and own our all-in-one communication platform, which integrates telephony, PBX, messaging, meetings, and contact centers, giving businesses a smarter way to connect. Today, we’re a thriving company with 1.9 billion SEK in revenue and 500+ Telavoxers across nine countries. We embrace AI and automation to push the boundaries of business communication. We offer flexible work options and adaptable hours, giving you the freedom to balance life and career while staying connected to our vibrant Telavox culture. Read more about our new HQ in Malmö 🏠! How to apply! At Telavox, we don't focus on fitting in; we focus on making room for everyone. We’re always on the lookout for great talent, so applications are reviewed continuously. If you're ready to be part of an innovative, AI-driven telecom company, apply today with your CV and cover letter in English. For any questions, feel free to reach out to Talent Acquisition Partner Ami Faraguna at ann-marie.faraguna@telavox.com Learn more about what we do! ⬇️
At Upvest, we are on a mission to make investing as easy as spending money. Upvest empowers businesses to offer a wide range of investment products and the best experience in the field of capital market investment and retirement planning. Upvest’s Investment API is easy to integrate so that fintechs and financial institutions can save resources and fully focus on their core business. We are proud to partner with Europe’s leading Fintechs and financial institutions such as DKB, Revolut, N26 and Raisin. Founded in 2017 by Martin Kassing, Upvest now brings together over 270 talented professionals from more than 70 nationalities. Upvest is backed by €280M in total funding from world-class investors, including BlackRock, Tencent, Sapphire Ventures, and Bessemer Venture Partners, Earlybird, Notion Capital, and Motive. Our latest €105M funding round in March 2026 - led by Sapphire and Tencent - serves as a massive catalyst for our growth, allowing us to offer premier investment experience. ABOUT THE ROLE: Upvest is at the inflection point where security needs to scale and remain a foundational discipline of the company. We're hiring a Security Engineering Lead to step into our lean and efficient Security team, set its multi-quarter direction, work cross-functionally and scale Security Engineering into a team that continues to own Upvest's entire application security and cloud security posture in a highly regulated environment as it scales. This role sits alongside our Security Operations and GRC teams, which owns detection, response, and compliance operations. Where SecOps keeps watch over what's happening now, Security Engineering shapes what we build and how we build it, embedding security into the SDLC, hardening our cloud environment, and building the platforms that make security teams more effective. You will own the secure paved roads every Upvest engineer relies on: automated SAST/DAST/SCA in our GitHub Actions pipelines, SSDLC adherence, IAM and network controls, and the technical implementation of DORA's (and other regulations') ICT risk framework for our platform. Our mission for the team is simple: make the secure way the easy way for everyone at Upvest. WHAT YOU’LL DO: * Set the multi-quarter strategy for application and cloud security across Upvest's Investment API platform — aligned with our product roadmap, our tenant commitments, and our regulatory obligations under DORA, MiFID II, and BaFin's MaRisk / BAIT requirements. * Lead, mentor, and grow our Security Engineering and Upvest's security culture. You'll inherit a small, talented team and own hiring, onboarding, growth, and retention as we scale. And you'll create initiatives to build security into the development and product life cycle. * Build paved roads. Own how Upvest performs encryption, authN/authZ, CI/CD, data, and network surfaces. We want fewer security review queues and more security baked into the templates. * Own application security end-to-end. Threat modeling, secure code review, SAST/DAST/SCA tooling integration in our GitHub Actions CI/CD, and vulnerability management. * Drive better cloud security posture across our GCP environment — IAM, VPC Service Controls, Cloud KMS, CSPM (Wiz), Binary Authorization for GKE, Terraform-driven infrastructure security baselines, and our Linkerd service mesh posture. * Mature Upvest's DORA technical implementation. Partner with our risk and compliance functions to translate DORA's ICT risk framework (Art. 5–9), secure development testing requirements (Art. 16), and threat-led penetration testing (Art. 24–27) into engineering work programmes — and into evidence we can show auditors and regulators. * Embed security in every product design. Partner deeply with product and engineering teams. Architecture reviews, design partnerships, security champions across product squads, collaboration beats gatekeeping. * Stay current on emerging threats. AI / LLM security, agentic identities, and the secure use of AI tooling in our own engineering workflow are an active concern * Represent Upvest's security posture clearly to everyone WHAT YOU BRING: * 6–10 years in security engineering, with 4+ years focused on product security or cloud security, and you work well in a regulated environment. You don't need to check every box, but we're asking for evidence that you've taken security from "owned by one team in a queue" to "embedded in how an engineering org ships." * Hands-on, technically credible. You earn the trust of engineers by going deep, so you're comfortable reading code, threat modeling designs, debating architectures, and writing tooling when it's valuable. * Cloud-native security depth. GCP preferred; AWS or Azure transferable. You know IAM, network segmentation, KMS, IaC security (Terraform), and Kubernetes hardening (RBAC, network policies, Pod Security Standards) as a craft. * Product/Application security foundations. OWASP Top 10 / ASVS, secure code review, SAST/DAST/SCA tooling integration, supply-chain security (SLSA, signing). * Lead through influence, not gatekeeping. You drive security outcomes through partnership with engineering teams. You can navigate ambiguity, set direction, and make sound risk-based decisions that scale with the organisation. People want to work with you, because you don't just say "no", you say "yeah, and this is how". * Hire and grow people. You've built or grown a small team. You set a high bar in interviews, invest in onboarding, give real-time feedback, and address performance issues quickly and fairly. Communicate cleanly across audiences e.g. a security incident write-up to engineering, a control narrative to an auditor, and a risk briefing to executives are three different documents, and you can write all three. NICE TO HAVE: * Experience securing multi-tenant B2B platforms or financial-API products: tenant isolation, API-as-product safety boundaries, and the specific operational shape of selling to regulated customers. * Experience with trading, custody, or securities settlement platforms, or curiosity about that domain. * Bug bounty / VDP programme management. * In a past life, you have shipped backend code in production, and you're comfortable in Go (preferred), Python, or another modern backend language. * Regulatory fluency. Working knowledge of DORA, MaRisk, BAIT, ISO 27001. You can change audit-speak or regulation into actionable technical requirements other people understand. You can hold your own with auditors and regulators without losing engineering pragmatism. * Background in engineering and offensive security * German skills are useful for some potential client interactions, but not required. Our working language is English. * Hands-on experience with AI/LLM security, agentic identity, or securing AI tooling in an engineering workflow. * Familiarity with the operational side of security is a bonus, hands-on experience with EDR and SIEM platforms, or a background in incident response. This matters in practice, you'll be part of the security on-call rotation, so being comfortable picking up an active incident is real, not theoretical. HOW WE UPVEST IN YOU: * Best-in-class AI tools: Every Upvenger has €20,000 per year to spend on the best AI tools available — so you're always working with the most powerful models and tooling on the market. * Impact-driven work: We’re building the infrastructure that will power the future of investing in Europe. It’s complex, ambitious, and meaningful. You’ll work with modern technologies and create something entirely new. No legacy systems, no limits. * Wellbeing: Recharge with 30 days of annual leave and maintain a healthy lifestyle with sports benefits. Access confidential professional coaching and enjoy the flexibility to work remotely abroad for up to 183 days a year. Recharge with UpRest, a one-month fully paid sabbatical after every 4 years of working at Upvest. * Development: Growth is in our DNA. Each Upvenger has access to a personal development budget and the freedom to decide how to use it. * Flexible work environment: Work from any of our hubs in Berlin, London or Tallinn hybrid or remotely across Europe, depending on the role. We give you the choice and budget to work where you’re most comfortable and productive, either at home or in the office. You choose. * Compensation and equity: We believe that all Upvengers contribute to our success and deserve a competitive, above-market salary and a participation in our employee equity program. * Team celebrations: Participate in company-wide events, such as UpFest, dinners, offsites and our Holiday party, to connect with colleagues and celebrate our achievements. * Inclusion: We’re committed to a culture where everyone belongs and thrives. Our Employee Resources Groups foster inclusion and connection, like Upfem for our female Upvengers, or UpVergent supporting neurodivergent Upvengers and allies. OUR VALUES: * Make it easy for others. We simplify the complex and act with the best intentions. * Own the outcome. We are proactive, fast and confident to get the job done, valuing progress over perfection. * Rise to the challenge. We aim high and push the boundaries. We stay curious, learn and celebrate our wins together. * Tell the story. We start with the Why to align on purpose. We are transparent and share knowledge to empower and inspire others. Upvest is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.