Staff Engineer - Infrastructure & Security
Senior / Staff DevSecOps Engineer - Fully Remote within Europe Security used to be something this team built into the product. Now it needs an owner. edenity. have partnered with one of Europe's most exciting infrastructure companies, building the identity layer that businesses use to understand exactly who they're doing business with. After two years quietly building, they've moved quickly: €40m raised from CapitalG and Index Ventures, alongside founders and executives from Stripe, Adyen, Notion, Remote, Qonto, Framer, Anthropic, Mollie, OpenAI and Goldman Sachs. Now the customer profile is changing. They're moving upstream into some of the most demanding financial institutions in Europe. Real banks. Serious security teams. Procurement processes that involve considerably more than someone ticking "SOC 2 compliant" on a spreadsheet. And that's created a genuinely interesting engineering problem. They're hiring their first dedicated security engineer.Not a GRC person. Not someone to write policies from the sidelines. And definitely not someone whose answer to every problem is another enterprise security platform.They need a builder who happens to be obsessed with security. The problem you'll own The infrastructure underneath the product is already deliberately simple and extremely scalable: Kubernetes, Postgres and Redis on AWS, built around open-source technology rather than layers of proprietary cloud magic. The engineering team has done a good job of security so far.But "good" stops being enough when global financial institutions start asking difficult questions.Vulnerabilities need owners and SLAs. Third-party dependencies need systematic review.Security Hub alerts need proper investigation.Responsible disclosures need triage rather than a ticket graveyard.Auditors need evidence.And when a bank's security team asks why something works the way it does, someone needs to be able to sit across the table, understand the concern, explain the architecture and occasionally tell them, intelligently, no. That's you. What you'll actually build You'll own the security surface end-to-end, with the freedom to decide what good looks like. That means:Building vulnerability management across open-source packages, infrastructure and third parties, from detection through remediation.Creating the automation and evidence trail that makes SOC 2 / ISO 27001 audits pleasantly uneventful.Designing vendor security management that engineers will actually use.Owning security alerting, investigation and responsible disclosure.Working directly with engineering to turn security requirements into shipped changes rather than PDFs.Joining customer security conversations, RFPs and audits with increasingly sophisticated banks and fintechs.Threat modelling new systems and spotting the things nobody else is worrying about yet.Remaining hands-on with infrastructure and DevOps alongside the platform team. There is no security department to hide inside.There is also no security department telling you how this has always been done. Who we're looking for Probably someone who's spent time somewhere where startup engineering meets serious regulation. You might have built security inside a fintech, payments company, bank infrastructure provider or another environment where enterprise customers expect evidence, not reassurance. You'll likely have:A strong DevOps / platform engineering foundation, with security layered deeply on top.Hands-on experience with Kubernetes, cloud infrastructure and CI/CD.Worked with frameworks such as SOC 2, ISO 27001 and GDPR, without becoming institutionalised by them.Experience building vulnerability, dependency, vendor or security monitoring processes.Enough technical depth to challenge engineers and enough commercial judgement to handle a bank's security team.The seniority to operate independently and decide what deserves fixing now, later, or never. Most importantly, you're pragmatic. You understand that perfect security doesn't exist. Good security is knowing where the real risks are, building the right controls around them, and making the secure path the easiest path for engineers. Why this one is different This isn't joining security engineer #14 and inheriting somebody else's playbook.You're arriving at the exact moment security becomes strategically important to the company.You'll define the tooling.You'll define the standards.You'll influence architecture.You'll work directly with some of Europe's strongest engineers and increasingly sophisticated financial institutions. And if you do it well, there's a very obvious path from first security engineer → security leadership as the company scales. The company itself is treated almost like a second product: something to continuously redesign so exceptional people can do exceptional work. High talent density, very little hierarchy, radical transparency and genuine ownership.They're remote-first, globally distributed and deliberately flexible about when and where people work. The package includes location-independent compensation, meaningful equity, 30+ days holiday, flexible working and generous parental/caregiver leave. A significant portion of the company's equity is also held by a non-profit foundation, meaning the value created here isn't designed solely to flow back to shareholders. In short: if you're a security engineer who'd rather build the security function than inherit one, this is probably worth a conversation.And if you're reading this thinking "I can do most of that, but not all of it"...Good. We'd still like to hear from you.
