1,171,479open jobs
66,194companies
208,186added this week
Browse all
Salary
≈ $57k – $134k per year (Estimated)
Location
In office (Slovakia)
Seniority
Staff · 6+ years exp

Confirmed on the employer's own hiring board on Oct 4, 2026. First seen by Alion on Jan 26, 2026. Bloomreach scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Bloomreach is a digital commerce experience platform designed to drive e-commerce personalization, site search, and omnichannel marketing. Founded in 2009 and headquartered in Mountain View, California, the platform serves over 1,400 global enterprise brands and retailers - such as American Eagle, Pandora, BrewDog, and Bosch - by unifying customer data with product catalogs to deliver real-time personalized shopping experiences.

Bloomreach is building the world’s premier agentic platform for personalization.We’re revolutionizing how businesses connect with their customers, building and deploying AI agents to personalize the entire  customer journey.

  • We're taking autonomous search  mainstream, making product discovery more intuitive and conversational for customers, and more profitable for businesses.
  • We’re making conversational shopping  a reality, connecting every shopper with tailored guidance and product expertise - available on demand, at every touchpoint in their journey.
  • We're designing the future of autonomous marketing, taking the work out of workflows, and reclaiming the creative, strategic, and customer-first work marketers were always meant to do.

And we're building all of that on the intelligence of a single AI engine -  Loomi - so that personalization isn't only autonomous…it's also consistent.From retail to financial services, hospitality to gaming, businesses use Bloomreach to drive higher growth and lasting loyalty. We power personalization for more than 1,400 global brands, including American Eagle, Sonepar, and Pandora.

Senior Staff Security Engineer

The Senior Staff Security Engineer owns current and target-state data architectures and reporting while also designing, implementing, and monitoring cloud (AWS/GCP) infrastructure security controls; deploying, securing, configuring, and operating SIEM and other security resources; identifying, triaging, and remediating infrastructure and web vulnerabilities; leading incident triage and external-researcher engagement; mentoring junior staff; and helping shape secure, scalable approaches for AI-enabled tooling, automation, and emerging product capabilities.

Role summary and core responsibilities

  • 6+ years of relevant experience
  • Candidates must demonstrate proficiency in cloud security, network security, URL filtering, common security frameworks, and CVE lifecycle management
  • Practical IaC and scripting for automation
  • Strong cross-functional and external communication
  • Experience mentoring junior staff

Technical Skills:

  • Hands-on cloud security for AWS and GCP: design secure architectures, perform threat modeling, apply platform-native controls, and build and validate secure IaC.
  • SIEM ownership and detection engineering: deploy, configure, tune, and maintain SIEM; author and test detection rules and playbooks; integrate data sources; and operate with SLA-driven alerting and incident workflows.
  • Vulnerability and incident lifecycle ownership: identify, triage, and remediate infrastructure and web vulnerabilities.
  • Drive CVE lifecycle management and patching: perform root cause analysis and measure MTTR and remediation rates.
  • Network, web, and endpoint protections: design and manage firewalls, WAFs, cloud network controls, URL and web filtering, with demonstrable operational experience.
  • Secure automation and tooling: author automation for detection, alert enrichment, and remediation; build or extend security tooling using scripting or languages such as Python, Go, or Bash.
  • Infrastructure as code and secure CI pipelines: implement guardrails and policy-as-code in CI/CD pipelines, perform static IaC scanning, and enforce security baselines before deployment.
  • Detection, telemetry, and observability: define logging and telemetry requirements, ensure coverage for critical assets, and validate detection efficacy and alert fidelity.
  • Security standards, playbooks, and enforcement: develop, document, and operationalise organisation-wide security standards, runbooks, and playbooks; partner with engineering teams to drive adoption.
  • Threat-informed defensive engineering: apply threat modeling and adversary-focused testing to guide controls, detection, and resilient designs.
  • AI security and emerging technology risk: help define controls and guardrails for AI-enabled tools, internal automation, and product capabilities; assess risks around data access, model usage, prompt injection, and secure adoption of AI across engineering environments.
  • Cross-functional and external communication: communicate clearly with engineering teams, leadership, external researchers, and customers; lead vulnerability disclosure and researcher engagement.
  • Mentorship and prioritisation: mentor junior engineers, prioritise security projects based on risk and business impact, and drive continuous improvement of infrastructure security posture.
  • Familiarity with frameworks and common weaknesses: working knowledge of CIS, NIST, common security libraries and controls, and typical flaws exploited in infrastructure and web applications.

Skills and qualifications:

  • AWS Certified Security
  • Google Professional Cloud Security Engineer
  • Splunk Certified Admin or Splunk Certified Enterprise Security Admin
  • CISSP (Certified Information Systems Security Professional)
  • Certified Cloud Security Professional (CCSP)
  • Cloud Security Alliance CCSK
  • Experience with AI security, AI governance, or securing AI-enabled products and workflows is a strong plus

The pay range actually offered will take into account a variety of potential factors considered in compensation, including but not limited to skills, qualifications, geographic location, accomplishments, experience, credentials, internal equity and business needs, and may vary from the range listed above.

Base Salary Range

1 236 364 Kč—1 545 455 Kč CZK

More things you'll like about Bloomreach:

Culture:

  • A great deal of freedom and trust. At Bloomreach we don’t clock in and out, and we have neither corporate rules nor long approval processes. This freedom goes hand in hand with responsibility. We are interested in results from day one. 

  • We have defined our 5 values and the 10 underlying key behaviors that we strongly believe in. We can only succeed if everyone lives these behaviors day to day. We've embedded them in our processes like recruitment, onboarding, feedback, personal development, performance review and internal communication. 

  • We believe in flexible working hours to accommodate your working style.

  • We work virtual-first with several Bloomreach Hubs available across three continents.

  • We organize company events to experience the global spirit of the company and get excited about what's ahead.

  • We encourage and support our employees to engage in volunteering activities - every Bloomreacher can take 5 paid days off to volunteer*.

  • The Bloomreach Glassdoor page elaborates on our stellar 4.7/5 rating. The Bloomreach Comparably page Culture score is even higher at 4.9/5

Personal Development:

  • We have a People Development Program - participating in personal development workshops on various topics run by experts from inside the company. We are continuously developing & updating competency maps for select functions.

  • Our resident communication coach Ivo Večeřa is available to help navigate work-related communications & decision-making challenges.*

  • Our managers are strongly encouraged to participate in the Leader Development Program to develop in the areas we consider essential for any leader. The program includes regular comprehensive feedback, consultations with a coach and follow-up check-ins.

  • Bloomreachers utilize the $1,500 professional education budget on an annual basis to purchase education products (books, courses, certifications, etc.)*

Well-being:

  • The Employee Assistance Program -- with counselors -- is available for non-work-related challenges.*

  • Subscription to Calm - sleep and meditation app.*

  • We organize ‘DisConnect’ days where Bloomreachers globally enjoy one additional day off each quarter, allowing us to unwind together and focus on activities away from the screen with our loved ones.

  • We facilitate sports, yoga, and meditation opportunities for each other.

  • Extended parental leave up to 26 calendar weeks for Primary Caregivers.*

Compensation:

  • Restricted Stock Units or Stock Options are granted depending on a team member’s role, seniority, and location.*

  • Everyone gets to participate in the company's success through the company performance bonus.*

  • We offer an employee referral bonus of up to $3,000!

  • We reward & celebrate work anniversaries -- Bloomversaries!*

(*Subject to employment type. Interns are exempt from marked benefits, usually for the first 6 months.)

Excited? Join us and transform the future of commerce experiences!

If this position doesn't suit you, but you know someone who might be a great fit, share it - we will be very grateful!

Any unsolicited resumes/candidate profiles submitted through our website or to personal email accounts of employees of Bloomreach are considered property of Bloomreach and are not subject to payment of agency fees.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,171,479 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Slovakia
≈ $112k – $219k per year (Estimated) • In office • Contractor • Washington
DevOps
Splunk
GCP
Azure
AWS
Cybersecurity
Crowdstrike
Nessus
Snort
Qualys Cloud Platform
Microsoft Sentinel
Suricata
SentinelOne
Microsoft Defender
IBM QRadar
SIEM
Apply
$135k – $203k per year • In office • Secret • Full-Time • 5+ years exp • Bachelor's Degree • Colorado Springs
Python
PowerShell
Bash
DevOps
GCP
Azure
AWS
Linux
Windows
Cybersecurity
Wireshark
Crowdstrike
Tcpdump
Autopsy
SentinelOne
MITRE ATT&CK
Carbon Black
FTK
EnCase
X-Ways Forensics
SIEM
Apply
≈ $62k – $128k per year (Estimated) • In office • Full-Time • 3+ years exp • High School Diploma • Memphis
AI/ML
Supervision
Apply
DevSecOps Engineer 3 days ago
≈ $50k – $114k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Lisbon
Python
DevOps
Terraform
Ansible
GCP
VMWare
Git
AWS
GitLab
IAM
TCP/IP
DNS
Apply
Security Engineer 3 days ago
≈ $37k – $91k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Lisbon
JavaScript
DevOps
GCP
Azure
CI/CD
AWS
Incident Management
GitLab
IAM
Cybersecurity
Snyk
SonarQube
OWASP Top 10
Management
Agile
Apply
Systems Engineer 1 day ago
$109k – $175k per year • Equity • In office • Full-Time • 4+ years exp • Norwood
Python
SQL
PowerShell
DevOps
Ansible
GCP
Red Hat
OpenShift
VMWare
Prometheus
Azure
AWS
Grafana
SaltStack
Configuration Management
Linux
Apply
≈ $39k – $82k per year (Estimated) • Remote (Portugal) • Full-Time • 5+ years exp • Bachelor's Degree • Lisbon
Python
PowerShell
Bash
DevOps
Terraform
Ansible
AWS CDK
CloudFormation
CI/CD
Git
AWS
Docker
Kubernetes
Platform Engineering
AWS Lambda
Amazon EC2
Amazon ECS
Linux
Apply
Database Engineer 1 day ago
≈ $38k – $90k per year (Estimated) • Hybrid • Full-Time • Lisbon
SQL
C#
C#
.NET
Entity Framework Core
Databases
MySQL
PostgreSQL
MS SQL
Amazon Aurora
DevOps
CI/CD
AWS
Docker
Amazon EC2
Linux
Apply
≈ $41k – $89k per year (Estimated) • Hybrid • Full-Time • Lisbon
DevOps
CI/CD
Platform Engineering
Apply
≈ $44k – $126k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Lisbon
JavaScript
Java
TypeScript
Java
Maven
Spring Boot
Apache Tomcat
Databases
PostgreSQL
Oracle
Apache Kafka
Frontend
Angular
DevOps
Rest API
CI/CD
Jenkins
Docker
Kubernetes
GitLab
Management
Agile
Apply
≈ $49k – $112k per year (Estimated) • Equity • In office • 6+ years exp • Slovakia
Python
Bash
AI/ML
AI Agents
LLM Guardrails
DevOps
Splunk
CI/CD
AWS
Docker
Kubernetes
IAM
Linux
Cybersecurity
CVE
Zero Trust
Twingate
SIEM
Apply
$43k – $54k per year • Equity • In office • 6+ years exp • Slovakia
Python
Bash
AI/ML
AI Agents
LLM Guardrails
DevOps
Splunk
CI/CD
AWS
Docker
Kubernetes
IAM
Linux
Cybersecurity
CVE
Zero Trust
Twingate
SIEM
Apply
$32k – $40k per year • Equity • In office • 2+ years exp • Slovakia
AI/ML
AI Agents
LLM
Cybersecurity
Burp Suite
Nmap
OWASP ZAP
OWASP Top 10
STRIDE
Threat Modeling
OWASP
Apply
Security Analyst 16 days ago
≈ $10k – $29k per year (Estimated) • Equity • In office • India
Python
JavaScript
PowerShell
Node JS
Node JS
Commander.js
AI/ML
Claude
ChatGPT
AI Agents
Falcon
Gemini
LLM
DevOps
Splunk
GCP
AWS
Cybersecurity
Crowdstrike
Prisma Cloud
Qualys Cloud Platform
Microsoft Defender
Wiz
Sysdig Secure
Microsoft Defender for Cloud
SIEM
Apply
$62k – $78k per year • Equity • In office • 6+ years exp • Slovakia
Python
AI/ML
AI Agents
LLM Guardrails
DevOps
Splunk
GCP
CI/CD
AWS
SLI/SLO/SLA
Cybersecurity
CVE
Threat Modeling
SIEM
Apply
$43k – $54k per year • Equity • In office • 6+ years exp • Slovakia
Python
Bash
AI/ML
AI Agents
LLM Guardrails
DevOps
Splunk
CI/CD
AWS
Docker
Kubernetes
IAM
Linux
Cybersecurity
CVE
Zero Trust
Twingate
SIEM
Apply
≈ $49k – $112k per year (Estimated) • Equity • In office • 6+ years exp • Slovakia
Python
Bash
AI/ML
AI Agents
LLM Guardrails
DevOps
Splunk
CI/CD
AWS
Docker
Kubernetes
IAM
Linux
Cybersecurity
CVE
Zero Trust
Twingate
SIEM
Apply
≈ $53k – $125k per year (Estimated) • Equity • In office • 4+ years exp • Slovakia
Python
C++
AI/ML
AI Agents
Red Teaming
DevOps
GCP
Azure
AWS
Kubernetes
Linux
Windows
Cybersecurity
SentinelOne
Threat Modeling
Apply
≈ $46k – $105k per year (Estimated) • Equity • Hybrid • Slovakia
YARA
DevOps
DNS
Cybersecurity
YARA
SentinelOne
MISP
EPSS
KEV
Apply
$32k – $40k per year • Equity • In office • 2+ years exp • Slovakia
AI/ML
AI Agents
LLM
Cybersecurity
Burp Suite
Nmap
OWASP ZAP
OWASP Top 10
STRIDE
Threat Modeling
OWASP
Apply
See all jobs
This is one of many
1,171,479 more open roles from verified company boards, updated every day.