Security Engineer

Security Engineer

Full-Time 60000 - 80000 € / year (est.) Home office (partial)
S

At a Glance

  • Tasks: Secure our cloud and product security while collaborating with a dynamic engineering team.
  • Company: Join StackOne, a fast-growing startup backed by top investors, shaping the future of AI integrations.
  • Benefits: Enjoy competitive share options, health insurance, generous holiday, and a £1,000 home office budget.
  • Other info: Flexible hybrid working arrangements and a commitment to diversity and inclusion.
  • Why this job: Make a real impact in security engineering at one of Europe's fastest-growing startups.
  • Qualifications: 3+ years in security engineering with strong coding skills in TypeScript, Python, or Go.

The predicted salary is between 60000 - 80000 € per year.

About StackOne: StackOne is the AI Integration Gateway for SaaS products and AI Agents. Backed by GV and Workday Ventures ($24M raised), we help builders of SaaS platforms and AI Agents orchestrate hundreds of scalable, accurate, and enterprise-grade integrations. Our platform combines 25,000 pre-mapped actions on 200 connectors, an AI-powered integration development toolkit, plus security by design: a real‑time architecture, managed authentication and permissions, and end‑to‑end observability. Join us on our fast trajectory to build the future of agentic integrations.

About the role: We’re looking for a Security Engineer to be a key hire on our Engineering team and own our cloud and product security posture as we scale. You’ll work across our AWS and Cloudflare estate, harden our secure SDLC, run pen testing efforts end‑to‑end, and threat‑model the features powering our connectors, OAuth flows, and agent execution paths. It’s a hands‑on, DevSecOps‑heavy role: you write code, ship tooling, and embed security into how engineers work every day. You’ll report directly to the CTO and have broad scope across the platform (from CI/CD pipelines to multi‑tenant APIs to incident response on authentication flows).

Responsibilities:

  • Own the secure SDLC: drive SAST, dependency scanning, secrets detection, and PR‑blocking standards across every repository.
  • Harden our AWS and Cloudflare estate: IAM, secrets, network segmentation, KMS, WAF, GuardDuty, and zero‑trust patterns.
  • Run pen testing end‑to‑end: scope and coordinate engagements with both AI‑driven scanners and human researchers, then drive findings through fix and retest.
  • Threat‑model product features before they ship, new Auth provider, expanded multi‑tenant APIs, connector executions, agent tool‑calling paths etc.
  • Build detection and response capability around credential and authentication flows, with observability that closes incidents fast.
  • Partner with engineering to raise the bar day‑to‑day: architecture reviews, written standards, and security embedded in code review.
  • Use LLMs and agents to accelerate security workflows (triage, code review, evidence gathering) with guardrails you trust and help secure and monitor the (code/application/device) fleet.
  • Support compliance work where it intersects security engineering: SOC 2, ISO 27001, customer security reviews, and pen test responses.

What we’re looking for:

  • 3+ years in security engineering with hands‑on AWS security: IAM, KMS, networking, secrets, GuardDuty / Security Hub.
  • Strong coding ability in TypeScript or Python or Go comfortable shipping production code, not just configs and scripts.
  • Application security fluency: OWASP Top 10, threat modeling, and code‑level reviews on real systems.
  • Experience securing a B2B SaaS multi‑tenant production environment.
  • Comfort owning end‑to‑end work: scope, ship, measure. You don’t wait for a queue.
  • Clear communication with engineers, product, and non‑technical stakeholders.
  • Bias toward automating security checks instead of running manual checklists.
  • (Preferred) IaC fluency in AWS CDK or Terraform, comfortable reviewing infrastructure code for security misconfigs and writing custom scanning rules.
  • (Preferred) Experience with Aikido, Drata, Cloudflare Workers, or pen testing in a compliance‑mature environment.

Our Stack:

  • Cloud & infra: AWS (ECS, RDS, Lambda, KMS, GuardDuty, Security Hub, Inspector), Cloudflare (Workers, WAF, Zero Trust)
  • IaC: AWS CDK, Terraform
  • Security tooling: Aikido (SAST, DAST, container scanning, pen testing), 1Password, GitHub (org‑level enforcement, Advanced Security)
  • Compliance & ops: Drata, Iru, EasyLlama
  • Observability & IR: Datadog, Sentry, Logfire, Incident.io
  • Languages: TypeScript (Node.js), Python

Benefits:

  • Meaningful share options (EMI) - share in the company’s success as we grow
  • 25 days holiday + 1 additional day per year of tenure
  • Private health insurance - including dental & optical
  • £15/day lunch budget when working from our London office, up to £120/month
  • £1,000 for your home office set up + £500/year top‑up
  • Annual team offsite to sunny spots (last ones were in Spain and Portugal)
  • Join one of Europe’s fastest-growing startups
  • Work with a veteran team of ex‑employees of Google, Microsoft, Oracle, Coinbase, JP Morgan and more
  • Health, fitness and gift card discounts
  • Cycle2Work and Electric Cars scheme
  • Hybrid working friendly - typically 2 days/week in our London office. We’re open to discussing flexible arrangements—please share any preferences in your application

We believe diversity drives innovation. We encourage individuals from all backgrounds to apply. As an equal‑opportunity employer, we celebrate diversity and are committed to creating an inclusive environment for all employees.

Security Engineer employer: StackOne Technologies Limited

StackOne is an exceptional employer, offering a dynamic work environment where innovation thrives and employees are empowered to shape the future of AI integrations. With competitive benefits such as meaningful share options, private health insurance, and a generous holiday allowance, alongside a strong focus on employee growth and a hybrid working model, StackOne fosters a culture of collaboration and inclusivity. Join a team of industry veterans in a fast-growing startup that values diversity and encourages personal and professional development.

S

Contact Detail:

StackOne Technologies Limited Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with current employees at StackOne. A friendly chat can sometimes lead to opportunities that aren’t even advertised!

Tip Number 2

Show off your skills! If you’ve got a GitHub or personal project showcasing your coding chops, make sure to highlight it during interviews. It’s a great way to demonstrate your hands-on experience in security engineering.

Tip Number 3

Prepare for technical interviews by brushing up on AWS security practices and coding challenges. We want to see how you think and solve problems, so practice articulating your thought process as you tackle these challenges.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step to engage with us directly.

We think you need these skills to ace Security Engineer

AWS Security
Cloudflare Security
Secure SDLC
Penetration Testing
Threat Modelling
TypeScript
Python

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Security Engineer role. Highlight your experience with AWS security, coding skills in TypeScript or Python, and any hands-on work you've done in securing B2B SaaS environments. We want to see how your background aligns with what we're looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about security engineering and how you can contribute to our mission at StackOne. Be sure to mention specific projects or experiences that relate to the responsibilities outlined in the job description.

Show Off Your Technical Skills:In your application, don't shy away from showcasing your technical skills. Whether it's your fluency in IaC tools like AWS CDK or Terraform, or your experience with pen testing, we want to know what makes you a great fit for our team. Include relevant examples where possible!

Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It helps us keep track of applications and ensures you’re considered for the role. Plus, it’s super easy—just follow the prompts and submit your materials!

How to prepare for a job interview at StackOne Technologies Limited

Know Your Security Fundamentals

Make sure you brush up on your knowledge of AWS security, IAM, KMS, and the OWASP Top 10. StackOne is looking for someone who can demonstrate a solid understanding of these concepts, so be prepared to discuss how you've applied them in real-world scenarios.

Showcase Your Coding Skills

Since this role involves writing production code, be ready to talk about your experience with TypeScript, Python, or Go. Bring examples of projects where you’ve shipped code that enhances security, and don’t hesitate to share any custom scanning rules or IaC configurations you’ve worked on.

Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in security contexts. Think about how you would approach threat modelling for new features or how you’d handle a pen test engagement. Practising these scenarios will help you articulate your thought process clearly.

Communicate Effectively

This role requires clear communication with both technical and non-technical stakeholders. Practice explaining complex security concepts in simple terms, and be ready to discuss how you’ve collaborated with engineering teams to embed security into their workflows.