Staff Security Engineer (m,f,x) at HelloFresh | DE | Rezi

Staff Security Engineer (m,f,x) at HelloFresh

Staff Security Engineer (m,f,x)

HelloFresh · DE

1 months ago

Staff Security Engineer (m,f,x)

HelloFresh · DE

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

We are looking for a Staff Security Engineer to join the Security Tribe and help shape the next generation of security capabilities at HelloFresh. This is a senior individual contributor role for someone who is deeply technical, pragmatic, and builder-minded. You will work across Cloud Security, Application & Product Security, Offensive Security, and GenAI Security, with a strong focus on creating scalable internal security products, paved roads, guardrails, and self-service capabilities for HelloFresh teams. You will not only identify risks, but also build the systems, automation, and platforms that help engineering teams move faster and safer.

Responsibilities

  • Own and elevate secure design and architecture at scale across HelloFresh, championing a security-by-design culture by defining, driving, and embedding robust architectural patterns, reference designs, and guardrails.
  • Define and drive security architecture across cloud environments, focusing on AWS, Kubernetes, IAM, network security, workload protection, secrets management, and secure-by-default infrastructure.
  • Build and scale cloud security guardrails using automation, policy-as-code, Infrastructure as Code, and platform-native controls.
  • Partner with engineering and product teams to embed security into the SDLC through threat modeling, secure design reviews, security testing, and developer-friendly remediation workflows.
  • Build internal security products and capabilities that make security self-serviceable for HelloFresh employees and engineering teams.
  • Lead initiatives across SAST, DAST, SCA, IaC scanning, secret detection, vulnerability management, and software supply chain security.
  • Drive offensive security activities including penetration testing, adversary simulation, purple teaming, and validation of detection and response capabilities.
  • Establish security patterns and controls for GenAI and AI/ML systems, including LLM applications, AI agents, RAG systems, model integrations, prompt injection risks, data leakage, and AI governance.
  • Coordinate with external security partners, auditors and consultants to properly scope, conduct and review external security engagements.
  • Use GenAI as a force multiplier to reduce operational toil, improve security workflows, automate analysis, and accelerate internal capability building.
  • Mentor senior engineers, influence technical direction, and act as a trusted security advisor across engineering, product, platform, data, and leadership teams.

Requirements

  • 8+ years of experience in security engineering, software engineering, cloud security, application security, or offensive security.
  • Deep hands-on experience securing cloud-native environments, preferably AWS, with strong knowledge of IAM, Kubernetes, networking, logging, detection, and infrastructure security.
  • Strong application and product security experience, including threat modeling, secure architecture reviews, OWASP risks, API security, and SDLC security.
  • Practical offensive security experience, including penetration testing, vulnerability research, exploitability analysis, or red/purple team exercises.
  • Strong engineering skills in one or more programming languages (e.g., Python, Go, Java, TypeScript), with the ability to build production-grade systems and security tooling.
  • Experience building automation, internal tools, developer platforms, security guardrails, or self-service security capabilities.
  • Experience securing GenAI, LLM, AI agent, RAG, or ML systems.
  • Familiarity with OWASP Top 10 for LLMs, MITRE ATLAS, NIST AI RMF, AI gateways, LLM guardrails, prompt evaluation, or AI red teaming.
  • Familiarity with modern security tooling such as CNAPP/CSPM, SAST, DAST, SCA, IaC scanning, secret scanning, WAF, SIEM, EDR, or vulnerability management platforms.
  • Ability to influence without authority, communicate complex risks clearly, and translate security problems into scalable engineering solutions.

Skills

  • AWS
  • Kubernetes
  • IAM
  • Network Security
  • Workload Protection
  • Secrets Management
  • Policy-as-Code
  • Infrastructure as Code
  • SAST
  • DAST
  • SCA
  • IaC Scanning
  • Secret Detection
  • Vulnerability Management
  • Software Supply Chain Security
  • Penetration Testing
  • Adversary Simulation
  • Purple Teaming
  • GenAI Security
  • LLM Security
  • AI/ML Security
  • Python
  • Go
  • Java
  • TypeScript
  • CNAPP/CSPM
  • WAF
  • SIEM
  • EDR

Location

  • Berlin

Work Type

  • Hybrid

Experience Level

  • Senior
  • 8+ years

Benefits

  • Competitive compensation package
  • HelloFresh- subsidized Pension Scheme
  • Berlin relocation support
  • Discounts on weekly HelloFresh box
  • Discounts on office meals
  • German language learning budget
  • Access to the HelloFresh Academy
  • Mental health support
  • Transportation perks
  • Working-parent-friendly benefits
  • 24/7 gym access
  • Wellbeing platforms like Headspace and Spill
  • Sabbatical leave options

About the Company

  • One of Europe's fastest-growing tech powerhouses in a dynamic phase of expansion.
  • A diverse global community of 90+ nationalities.