1,450,551open jobs
86,146companies
223,842added this week
Browse all
Salary
≈ $74k – $189k per year (Estimated)
Location
In office (Berlin)
Seniority
Principal · 15+ years exp

Confirmed on the employer's own hiring board on Oct 10, 2026. First seen by Alion on Oct 9, 2026. HelloFresh Nordics scores A on the Alion truth index.

Overview
Company
Impact
Profile match
HelloFresh SE is a global meal-kit delivery company and direct-to-consumer food solutions provider. Headquartered in Berlin, Germany, the public company operates extensively across North America, Europe, Australia, and New Zealand under brand portfolios including HelloFresh, EveryPlate, Green Chef, Factor, and Youfoodz. Its core business activities involve designing pre-portioned meal recipes, sourcing ingredients, operating automated fulfillment centers, and delivering subscription-based meal kits and ready-to-eat meals directly to consumer households.

The role

We are looking for a Principal Security Engineer to serve as one of HelloFresh's most senior technical authorities in Security - shaping how we protect the company today while defining the security foundations we will need for the future.

This is not a Principal role defined by ownership of a single security domain. Your domain is HelloFresh.

You will operate at the intersection of technology strategy, security architecture, engineering and business risk, influencing some of the most consequential technical decisions we make. You will partner with senior Engineering, Product, Data, IT and business leadership to ensure security is not something applied after strategic decisions are made, but a fundamental input into those decisions. 

You think in systems, not Initiatives - and in years, not quarters.

Where others see an IAM issue, application vulnerability, endpoint incident or AI risk, you look for the architectural condition connecting them. You ask not only “How do we fix this?” but “Why can this class of failure exist at HelloFresh, and what should we change so that it becomes difficult by design?”

Your job is not merely to secure the systems HelloFresh has today. It is to influence what HelloFresh builds next, define the security architecture that makes it possible, and raise the technical capability of the organisation so that secure-by-default becomes a property of the company itself.

You will bring exceptional breadth across Cloud Security, Application & Product Security, Vulnerability Management, Offensive Security, Detection & Response, Enterprise IT Security, IAM & Zero Trust, Endpoint/MDM, Governance & Risk, Third-Party & Supply-Chain Security, and GenAI Security - with the depth and judgment to challenge our strongest specialists and go hands-on when the hardest problems demand it.

What you'll do

  • Demonstrate strong bias for action, moving quickly from ambiguity and constraints to clear decisions, ownership, and measurable outcomes. Balance speed with sound judgment, ensuring critical security risks are addressed decisively without creating unnecessary process or delay.
  • Make Security AI-native. Identify operational work across Security that should no longer require repetitive human execution. Drive agents, automation, internal security products and self-service capabilities that encode security expertise and make it available at company scale - with appropriate permissions, human oversight, evaluation and auditability.
  • Shape company and Group strategy through Security. Act as a strategic technical advisor to senior and executive leadership, influencing multi-year technology and business strategy across platforms, products, cloud, enterprise technology, AI, acquisitions and emerging technologies. Translate complex security issues into choices involving customer trust, resilience, engineering velocity, investment and business risk.
  • Own and elevate secure design and architecture at scale across HelloFresh. Define our security architectural principles, reference architectures, trust boundaries, standards, patterns and guardrails with the security leads. Act as a senior technical advisor for our most consequential architecture and security-risk decisions.
  • Connect the entire security system. Establish coherent technical direction across Cloud Security, AppSec/Product Security, Vulnerability Management, Offensive Security, Detection & Response, IT Security, IAM/Zero Trust, Endpoint & MDM, GRC and Third-Party/Supply-Chain Security. Identify systemic risks that individual teams cannot see or solve in isolation. Bring the industry perspective to implementation.
  • Eliminate classes of risk, not individual findings. Drive secure-by-default cloud and product architecture across AWS, Kubernetes, IAM, networking, APIs, distributed systems, CI/CD and software supply chains. Evolve vulnerability management, offensive security and detection toward threat-informed, exploitability-driven and continuously validated defence.
  • Define security for the AI and agentic era. Establish architecture for GenAI applications, LLMs, RAG, AI agents, MCP ecosystems and AI-assisted engineering - covering identity, permissions, tool access, data boundaries, prompt injection, model supply chain, monitoring and auditability. Provide direction for AWS Bedrock, Claude, Gemini, open-source GenAI models and open-source security-focused GenAI models and tooling.
  • Be a force multiplier. Mentor Staff, Senior Staff and Principal-track engineers, challenge architectural assumptions and raise the technical ceiling across Security and HelloFresh. Remain hands-on enough to prototype, review code, analyse attack paths and validate difficult technical decisions when required.

What you'll bring

  • 15+ years of deep technical experience, with demonstrated impact at Senior Staff, Principal, Security Architect or comparable scope. The scale of your impact matters more than the number itself.
  • Exceptional breadth across security with recognised depth in multiple domains and a track record of shaping company-wide technical strategy and architecture.
  • Deep expertise across several of Cloud Security, Product/AppSec, Offensive Security, Detection & Response, IAM/Zero Trust, Enterprise/IT Security, Endpoint/MDM, Security Platform Engineering and AI Security - with strong fluency across the broader landscape.
  • Deep understanding of AWS/cloud-native architecture, Kubernetes, IAM, networking, modern application architecture, APIs, distributed systems, CI/CD and software supply chains.
  • Strong adversarial judgment and the ability to connect architecture, realistic attack paths, exploitability, detection and business consequence.
  • Strong engineering skills in multiple programming languages such as Python, Go, Java, TypeScript or Rust.
  • A history of building or shaping platforms, paved roads, automation, policy-as-code, security products and self-service capabilities that materially changed how engineering organisations operate.
  • Exceptional technical judgment and communication - equally credible discussing an exploit chain with a security researcher, architecture with a Staff Engineer and strategic risk with an executive.
  • Demonstrated ability to influence without authority, make high-consequence decisions under ambiguity and make other senior engineers more effective through your technical leadership.

Nice to have

Experience operating at Principal, Distinguished Engineer or equivalent technical scope in a large technology organisation; hands-on GenAI/LLM/agentic security experience; familiarity with OWASP guidance for GenAI/LLMs, MITRE ATLAS and NIST AI RMF; experience with AWS Bedrock, Claude, Gemini and open-source GenAI/security models; experience with major technology transformations or acquisitions; and meaningful contributions through open source, security research, standards, publications or conferences.

Relevant advanced certifications are welcome, but at this level original thinking, technical judgment, engineering credibility and demonstrated impact matter substantially more than certifications.

What we offer

  • Global collaboration across HelloTech's hubs in Berlin, Warsaw, NYC, Boulder, and Toronto.
  • High-leverage, technically diverse work spanning ML, backend, data, and product engineering, with a direct line to business outcomes.
  • A genuinely AI-native environment with a mandate to scale that approach further.
  • Technical and engineering leadership in an autonomous, product-led setup, with end-to-end ownership from problem definition to production.
  • Enjoy a discount on HelloFresh meal kits, delivered straight to your door.
  • Build for the long-term with our company pension scheme.
  • Benefit from discounted memberships with Urban Sports Club and John Reed, yoga classes, and access to Headspace and Spill.
  • Balance your work and life with flexible hours, Work From Home/Abroad options, and a home office setup budget.
  • Receive childcare support (not available for interns/working students).
  • Get a monthly allowance for the Deutschlandticket to support sustainable commuting.
  • Embrace "Learning Never Stops" with access to internal trainings and a central L&D budget (remove for interns).
  • Work from a modern, comfortable office in Berlin-Kreuzberg and enjoy social events like team outings, Friday beers, and company runs.

Above all, we are looking for individuals who will make HelloFresh better. We believe there are many different ways of developing skills and we love diverse experiences, so even if you don't tick every box but think you'd thrive in this role, we'd really like to hear from you.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,450,551 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Berlin
≈ $89k – $209k per year (Estimated) • In office • Munich
Cybersecurity
ISO 27001
Apply
≈ $83k – $213k per year (Estimated) • In office • 8+ years exp • Munich
AI/ML
LLM
EU AI Act
Cybersecurity
ISO 27001
Threat Modeling
Apply
≈ $78k – $198k per year (Estimated) • In office • Full-Time
DevOps
SLI/SLO/SLA
IAM
Cybersecurity
ISO 27001
SIEM
Apply
≈ $95k – $174k per year (Estimated) • In office • Rheda-Wiedenbrück
AI/ML
Red Teaming
Cybersecurity
ISO 27001
Zero Trust
Apply
≈ $72k – $168k per year (Estimated) • In office • Gütersloh
DevOps
AWS
Cybersecurity
MISP
SIEM
Apply
≈ $26k – $73k per year (Estimated) • In office • Prague
Python
Java
DevOps
Linux
DNS
DHCP
Apply
≈ $20k – $40k per year (Estimated) • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Hyderabad
Python
Python
Flask
FastAPI
Django
Databases
MySQL
MS SQL
AI/ML
Copilot
Cursor
LangGraph
LangChain
ChatGPT
Fine-tuning
Prompt Engineering
NLP
Llama
Mistral
Transformers
LLM
OpenAI
Hugging Face
DevOps
Rest API
GCP
Azure
AWS
GitHub
Analytics
ETL/ELT
Management
Agile
Scrum
Apply
≈ $76k – $208k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Washington
Python
SAS
Stata
Apply
≈ $76k – $208k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Washington
Python
SAS
Stata
Apply
$92k – $152k per year • Equity • In office • Internship • 8+ years exp • Bachelor's Degree • Burlingame
Python
MATLAB
AI/ML
Multimodal AI
Computer Vision
TensorFlow
PyTorch
Machine Learning
DevOps
GitHub
Apply
≈ $63k – $134k per year (Estimated) • Hybrid • Berlin
AI/ML
Model Context Protocol
LLM
LLM Guardrails
DevOps
IAM
Linux
Windows
TCP/IP
VPN
Cybersecurity
Zero Trust
DLP
Management
Slack
Apply
≈ $44k – $96k per year (Estimated) • In office • 1+ year exp • Calgary
Apply
≈ $65k – $122k per year (Estimated) • Hybrid • 4+ years exp • Berlin
AI/ML
AI Agents
LLM Guardrails
Management
Agile
Marketing
Iterable
Apply
≈ $39k – $85k per year (Estimated) • In office • Derby
Apply
$56k – $65k per year • In office • 1+ year exp • High School Diploma • Aurora
Apply
≈ $64k – $150k per year (Estimated) • In office • Berlin
Cybersecurity
MITRE ATT&CK
IoT
OPC UA
Apply
≈ $41k – $84k per year (Estimated) • Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Berlin
DevOps
Azure
Incident Management
Windows
Cybersecurity
Microsoft Entra ID
Active Directory
Management
Jira
ServiceNow
Agile
ITIL
ITSM
Microsoft Office
Apply
≈ $62k – $111k per year (Estimated) • Remote (Germany) • 5+ years exp • Berlin
Python
JavaScript
TypeScript
Ruby
Databases
PostgreSQL
DevOps
Rest API
GCP
CI/CD
SOAP
Management
Jira
Google Maps
Agile
QA
Selenium
Cypress
Swagger
Appium
Postman
Apply
≈ $59k – $130k per year (Estimated) • Remote (Germany) • Full-Time • Berlin
Python
JavaScript
TypeScript
SQL
PowerShell
C#
C#
ASP.NET Core
Databases
Redis
DevOps
Terraform
Ansible
Helm
Loki
containerd
Prometheus
Pulumi
CI/CD
GitOps
Windows Server
Docker
Kubernetes
Cloudflare
Grafana
kubectl
DNS
Cybersecurity
ISO 27001
GDPR
Microsoft Entra ID
Management
SharePoint
Apply
Hybrid • 8+ years exp • Bachelor's Degree • Berlin
Marketing
YouTube
Apply
See all jobs
This is one of many
1,450,551 more open roles from verified company boards, updated every day.