Confirmed on the employer's own hiring board on Oct 8, 2026. First seen by Alion on Sep 4, 2026.
Join Talon.One, a leading platform for promotions and loyalty in Europe. As a Product Security Engineer, you will be responsible for the security of everything we ship to our customers and third-party partners. You will work hands-on with engineers and product managers, threat-modeling new product features, owning tenant isolation and API security, and building automated testing. You will also run a security champions program and experiment with AI to identify and remediate product security risks at scale.
Missions
- Threat-model new product features before they're built, including AI-embedded ones, and turn what you find into real engineering work.
- Own tenant isolation and API security across our Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP and third-party integrations.
- Build automated cross-tenant and adversarial testing that runs in CI, so isolation gets checked on every build, not only during our external yearly Pentest iterations.
Profil recherché
- Design API security end-to-end: authentication, credential lifecycle, rate limiting, abuse resistance and webhook security- Experience with a multi-tenant SaaS platform's authorization and tenant isolation model, and strong knowledge of how to test for broken object-level authorization automatically
- Strong knowledge of OWASP security guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications
- Hands-on experience with Google Cloud security, Kubernetes, and tools like Wiz and Datadog
- Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows, with a focus on useful developer feedback and effective vulnerability remediation
- Understanding how AI features actually get built, retrieval, context assembly, tool calling, agent loops, and know where indirect prompt injection breaks multi-tenant isolation
- Know how to build security monitoring and detections in-house tools (SIEM) yourself, from designing the signal through tuning it and writing the runbook
- Experience with shipping production code, whether you come from software engineering or from security work that includes coding
- Ability to influence engineers who don't report to you, and feel comfortable being early in a function with no existing playbook
- Hands-on experience with threat-modelling methodologies such as STRIDE, translating identified threats into actionable engineering requirements and security tests

