hirly

Linkedinjobs

Product Security Engineer

Berlin

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Linkedinjobs first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Role family
Engineering
Seniority
Mid level
Country
DE
Work mode
Remote-friendly
First seen by hirly
15 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

ABOUT TALON.ONE:

Talon.One is the most powerful incentives engine that unifies loyalty, promotions and gamification into one holistic platform. Backed by enterprise-grade security and scalability, Talon.One empowers companies to build personalized, profitable promotions and loyalty programs using any data.

Today, over 250 of the world’s most-loved brands including Adidas, Sephora and Carlsberg work with Talon.One to drive deeper engagement and lasting loyalty with their customers.

ABOUT THE ROLE:

You'll be one of Talon.One's first two security engineering hires, owning the security of everything we ship to our customers and third-party partners, from API authorization to the AI features going into our platform and their real-time observability and detections. You'll work hands-on, pairing directly with engineers and product managers rather than filing tickets, across a multi-tenant platform that powers promotions and loyalty for some of Europe's largest retail and travel brands. Based in Berlin, hybrid.

ONCE YOU ARE HERE YOU WILL:

Threat-model new product features before they're built, including AI-embedded ones, and turn what you find into real engineering work

Own tenant isolation and API security across our Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP and third-party integrations

Act as the security design authority for our AI features, working closely with the team behind UCP and Predict

Build automated cross-tenant and adversarial testing that runs in CI, so isolation gets checked on every build, not only during our external yearly Pentest iterations

Build standard, frictionless and automated golden paths for code security checks in CI workflows that developers can adopt by default without slowing down delivery

Run vulnerability and coordinate efficient patch response across every squad outside Platform, from automated dependency updates to drilled emergency response

Build and own application and AI security monitoring with our observability tools and build real-time security detection rules and alerts, and security events runbooks

Design the security of the API integration between Talon.One and Adyen as our products come together

Run a security champions programme so all our tribes build real security capability, not just the security team

Experiment with AI, leverage innovative ways and build new workflows to identify, prioritize, and remediate product security risks at scale.

WHAT WE NEED YOU TO BRING TO THE TABLE:

Experience with shipping production code, whether you come from software engineering or from security work that includes coding

Experience with a multi-tenant SaaS platform's authorization and tenant isolation model, and strong knowledge of how to test for broken object-level authorization automatically

Design API security end-to-end: authentication, credential lifecycle, rate limiting, abuse resistance and webhook security

Hands-on experience with threat-modelling methodologies such as STRIDE, translating identified threats into actionable engineering requirements and security tests

Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows, with a focus on useful developer feedback and effective vulnerability remediation

Understanding how AI features actually get built, retrieval, context assembly, tool calling, agent loops, and know where indirect prompt injection breaks multi-tenant isolation

Hands-on experience with Google Cloud security, Kubernetes, and tools like Wiz and Datadog

Know how to build security monitoring and detections in-house tools (SIEM) yourself, from designing the signal through tuning it and writing the runbook

Strong knowledge of OWASP security guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications

Ability to influence engineers who don't report to you, and feel comfortable being early in a function with no existing playbook

WHAT'S IN IT FOR YOU:

90+ team of engineers, product managers and product designers in Berlin

Leaders with 8+ years of experience building our promotions engine

€1,000 annual learning budget and free German language courses to boost your skills

30 days of annual leave, plus extra paid days for your birthday and moving day

Home office setup budget, a monthly home office allowance

Freedom to work from abroad for up to 90 days worldwide!

Mental health support with nilo.health and a discounted Urban Sports Club membership

20% company subsidy on your pension contributions

Subsidised BVG public transport ticket and a dog-friendly Berlin office where your furry friend is welcome

Lease your ideal bike through BusinessBike

Original posting on Linkedinjobs's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job
Product Security Engineer – Linkedinjobs · Berlin | hirly.me