368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$73k – $183k per year (Estimated)
Location
Remote/Hybrid (Berlin, Germany)
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
Delivery Hero is a leading global local delivery platform, headquartered in Berlin, that connects consumers with restaurants, grocery stores, and local retailers. Founded in 2011, the company operates across dozens of countries, providing on-demand food delivery and pioneering "quick commerce" services for household essentials. Through its extensive international network and advanced logistics technology, it facilitates millions of daily deliveries while aiming to provide a fast and seamless experience for customers worldwide.

As the world’s pioneering local delivery platform, our mission is to deliver an amazing experience, fast, easy, and to your door. We operate in around 65 countries worldwide powered by tech, designed by people. As one of Europe’s largest tech platforms, headquartered in Berlin, Germany. Delivery Hero has been listed on the Frankfurt Stock Exchange since 2017 and is part of the MDAX stock market index. We enable creative minds to deliver solutions that create impact within our ecosystem. We move fast, take action and adapt. No matter where you're from or what you believe in, we build, we deliver, we lead. We are Delivery Hero.

We are looking for a Staff Security Engineer (all genders) to join our Product Security team on our journey to always deliver amazing experiences.

We are looking for a pragmatic, high-impact individual contributor to join our Product Security team as a Staff Product Security Engineer (IC4). In this pivotal role, you will drive the overarching technical strategy for application security, ensuring we reduce real-world risk across our entire product landscape without slowing down engineering velocity.

You will champion a "Secure by Design" philosophy, moving away from reactive auditing and security gatekeeping. Instead, you will treat security as a collaborative engineering challenge, designing the automated guardrails, developer tooling, and technical frameworks that enable our engineering teams to scale rapidly and securely by default. As a Staff-level individual contributor, your leadership will extend beyond the immediate product boundaries and you will achieve domain-wide impact by seamlessly bridging the gap between Application Security, AI/ML security, Infrastructure Security, and Security Operations.

Your mission:

  • Drive Product Security Maturity: Drive the strategic technical roadmap for the Product Security team, ensuring threat-modeling methodologies and secure coding practices scale efficiently across our global web and mobile application ecosystem.

  • Lead Threat Modeling & Security Architecture Reviews: Apply your expertise to identify complex security design flaws early in the Software Development Life Cycle (SDLC) using frameworks and automation tools, co-authoring architectural blueprints that are secure by default.

  • Scale Vulnerability Management & Governance: Architect and run our vulnerability management program at scale. You will ingest inputs from internal testing, automated tooling, and external Bug Bounty / Vulnerability Disclosure Programs, systematically validating and ranking vulnerabilities based on actual business risk.

  • Master Stakeholder Management: Translate complex software and AI-related vulnerabilities into clear, actionable business risks, partnering closely with engineering leadership and product verticals to drive timely remediation without friction. systematically tracking and optimizing metrics such as Mean Time to Remediate (MTTR) and SLA Adherence % to elevate our overall security posture.

  • Automate DevSecOps & CI/CD Pipelines: Replace manual gates with seamless DevSecOps workflows, embedding automated security testing tools (SAST, DAST, SCA) directly into developer pipelines to catch high-risk flaws early.

  • Pioneer AI-Driven Security Automation: Champion the adoption of artificial intelligence and LLMs to revolutionize our security workflows. You will design and implement cutting-edge AI-powered code security automation, leverage AI for automated vulnerability triage, and build smart security automation guardrails that scale engineering productivity.

  • Cross-Domain Collaboration & CSPM Management: Drive domain-wide impact by collaborating with Infrastructure Security to leverage Cloud Security Posture Management (CSPM) platforms, ensuring that application vulnerabilities are contextualized with cloud risk. Partner with Security Operations (Detection & Response) to ensure proper application logging, alerting, and incident readiness.

  • Mentor and Inspire: Act as a technical beacon within the security and engineering organizations. Define key security metrics, drive a strong security culture, and mentor junior and senior engineers to foster a world-class community of Security Champions

  • Proven Engineering Leadership: A strong track record of driving complex application security and DevSecOps initiatives as a staff-level individual contributor in massive, global software environments.

  • Comprehensive Web & Mobile Security: Deep, fundamental understanding of modern web and mobile application security topics, including hands-on experience managing external Bug Bounty and vulnerability disclosure programs.

  • AI Security Expertise: Strong working knowledge of industry-standard security frameworks for artificial intelligence, such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI RMF.

  • AI & Security Automation Hands-on Experience: Practical understanding of utilizing artificial intelligence (including LLMs/Generative AI) for security engineering use cases, such as automated vulnerability analysis, script generation, triage optimization, and code security remediation.

  • Privacy, Ethics & Regulations: A solid understanding of global data privacy laws (e.g., GDPR), ethical AI considerations, and the regulatory impacts of the EU AI Act on application architecture.

  • Risk-Based Vulnerability Management: Strong expertise in vulnerability validation and triage, with the ability to look past raw CVSS scores to calculate actual business impact, coupled with excellent stakeholder management skills to align engineering teams on remediation.

  • Secure Coding & Remediation Proficiency: Deep hands-on proficiency in multiple modern programming languages (e.g., Java, Python, Go) and the ability to confidently code, review, and remediate complex vulnerabilities (such as the OWASP Top 10) directly within application repositories.

  • Cloud & CSPM Familiarity: Strong working knowledge of cloud security (AWS, GCP, or Azure) and containerized ecosystems (Kubernetes, Docker), alongside an understanding of how to align application security signals with Cloud Security Posture Management (CSPM) platforms.

  • Identity & Access Management (IAM): Deep understanding of modern authentication and authorization protocols (OAuth, OIDC, SAML) and how to design and enforce Zero Trust architectures at scale.

  • Cross-Functional Security Ops Alignment: Basic working knowledge of security operations, threat detection, and incident response, ensuring that product architectures are built to be auditable, observable, and resilient against live attacks.

Nice to have:

  • Experience securing highly distributed, event-driven microservices architectures at global scale.

  • History of public security research, CVE discovery, or active contributions to open-source security or AI safety tooling.

  • Advanced application security or cloud certifications (e.g., CSSLP, CASE, AWS Security Specialty, Google Professional Cloud Security Engineer, or CISSP).

Ensuring you and all our Heroes are looked after, happy, and healthy is always on the menu. Because if you’re in good shape, then we’re in good shape.

  • Make the most of our hybrid working model and join the team for face-to-face connection and collaboration in our beautiful Berlin campus 2 days a week

  • We offer 27 days holiday with an extra day on 2nd and 3rd year of service

  • We will support you in developing yourself and your career growth opportunities: 1.000 € Educational Budget, Language Courses, Parental Support and access to the Udemy Business platform to explore a variety of online courses.

  • Get moving and release those wonderful, mind-boosting endorphins: Health Checkups, Meditation, Yoga, Gym & Bicycle Subsidy

  • Cash. Dough. Cheddar. Whatever you call it, we’ll help you with it: Employee Share Purchase Plan, Sabbatical Bank, Public Transportation Ticket Discount, Life & Accident Insurance, Corporate Pension Plan

  • The power of getting together over some food is unrivaled. Here are a few ways to help you do that. All the yum: Digital Meal Vouchers, Food Vouchers, Corporate Discounts. Courses.

We believe diversity and inclusion are key to creating not only an exciting product, but also an amazing customer and employee experience. Fostering this starts with hiring - therefore we do not discriminate on the basis of racial identities, religious beliefs, color, national origin, gender identities or expressions, sexual orientations, age, marital or disability statuses, or any other aspect that makes you, you.

We encourage you to let us know if you need any accommodations or specific accessibility support to ensure a smooth interview experience-just let us know with an email to our Inclusion Officer at [email protected] it in your application.

Severely disabled applicants with equal qualifications will be given preferential consideration.

You're welcome to share your pronouns (he/she/they) right from the start so we can address you respectfully from our first contact.

We believe diversity and inclusion are key to creating not only an exciting product, but also an amazing customer and employee experience. Fostering this starts with hiring - therefore we do not discriminate on the basis of racial identities, religious beliefs, color, national origin, gender identities or expressions, sexual orientations, age, marital or disability statuses, or any other aspect that makes you, you.

We encourage you to let us know if you need any accommodations or specific accessibility support to ensure a smooth interview experience-just let us know with an email to our Inclusion Officer at [email protected].

Severely disabled applicants with equal qualifications will be given preferential consideration.

You're welcome to share your pronouns (he/she/they) right from the start so we can address you respectfully from our first contact.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Berlin
$19k – $48k per year (Estimated) • Remote • Yekaterinburg
Java
Java
Apache Camel
Gradle
Maven
Databases
ActiveMQ
Apache Kafka
PostgreSQL
DevOps
CI/CD
Docker
Git
gRPC
Kubernetes
Apply
$245k per year • Remote/Hybrid • 4+ years exp • Bachelor's Degree • San Mateo
JavaScript
TypeScript
AI/ML
LLM
Recommender Systems
Frontend
Babel
GraphQL
React.js
Webpack
DevOps
CI/CD
Docker
QA
Jest
Apply
$133k – $181k per year • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Cooper
Bash
PowerShell
Python
DevOps
Ansible
Azure
Configuration Management
Docker
Kubernetes
OpenShift
Ubuntu
Windows Server
Cybersecurity
CIS Benchmarks
Defense in Depth
Nessus
Qualys Cloud Platform
Zero Trust
Apply
$153k – $207k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • Cooper
PowerShell
DevOps
Azure
Docker
Kubernetes
Windows Server
IAM
Cybersecurity
Keycloak
Microsoft Entra ID
Okta
Zero Trust
Apply
$20k – $47k per year (Estimated) • Remote • Full-Time • Belgorod
Python
SQL
DevOps
CI/CD
Apply
Remote/Hybrid • Full-Time • Montevideo
Swift
Swift
Hero
AI/ML
AI Agents
Mobile
Fastlane
UIKit
DevOps
CI/CD
Jenkins
Apply
$51k – $118k per year (Estimated) • Equity • In office • Full-Time • 10+ years exp • Berlin
Python
SQL
DevOps
GCP
Cybersecurity
GDPR
Analytics
Tableau
Apply
In office • Full-Time • 7+ years exp • Dubai
Design
Figma
Apply
In office • Full-Time • 10+ years exp • Bachelor's Degree • Dubai
Apply
Remote/Hybrid • Full-Time • 2+ years exp • Montevideo
SQL
Databases
Google BigQuery
Apply
Design Engineer 1 hour ago
$63k – $133k per year (Estimated) • In office • Full-Time • Berlin
TypeScript
AI/ML
AI Agents
DevOps
GitHub
Design
Figma
Apply
$62k – $127k per year (Estimated) • In office • Full-Time • Mainz • Mannheim • Dresden • Ludwigsburg • Berlin
Apply
Product Engineer 6 hours ago
$81k – $128k per year • In office • Full-Time • 1+ year exp • Berlin
TypeScript
JavaScript
AI/ML
AI Agents
Human-in-the-Loop
Frontend
React.js
Tailwind CSS
Apply
Backend Engineer 6 hours ago
$81k – $128k per year • In office • Full-Time • 1+ year exp • Berlin
TypeScript
Node JS
JavaScript
Node JS
Nest.JS
Prisma
Databases
PostgreSQL
DevOps
Pulumi
Terraform
Apply
$81k – $128k per year • In office • Full-Time • 1+ year exp • Berlin
Node JS
TypeScript
JavaScript
Node JS
Nest.JS
Prisma
Databases
PostgreSQL
Frontend
React.js
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.