Senior Cyber Security Engineer, Elastic
Job description
About the role
Bitpanda is actively seeking a seasoned security professional to safeguard the digital assets and identities of millions of users in a rapidly scaling environment. The successful candidate will own the end-to-end lifecycle of detection engineering, taking responsibility for designing, implementing, and optimizing security controls that proactively identify and mitigate sophisticated threats. You will lead the incident response function, driving investigations from initial alert through to remediation and lessons learned to strengthen the overall security posture. A core part of this role involves building and driving automation initiatives that enhance the efficiency and scalability of our security operations and reduce manual overhead. You will act as a technical leader, mentoring junior team members and shaping security architecture decisions that impact the entire organization. This position requires active participation in a rotating on-call schedule to ensure continuous coverage and rapid response to critical security events around the clock. You will partner closely with engineering and product teams to embed security directly into the development lifecycle and ensure that security requirements are met without compromising delivery speed.
Key facts
What you'll do
Develop and maintain a comprehensive detection library using Elastic Security, ES|QL, and KQL to identify advanced persistent threats and common attacker techniques across the environment.
Investigate complex security incidents and conduct proactive threat hunting across AWS, Elastic, and Datadog to uncover stealthy adversaries and potential insider risks.
Create and maintain automated workflows for investigation and response by leveraging SOAR platforms and custom APIs to accelerate remediation and reduce mean time to respond.
Enhance cloud security monitoring capabilities and system hardening measures while providing subject matter expertise for ISO 27001, PCI DSS, and DORA compliance initiatives.
Mentor team members by providing guidance, code reviews, and technical leadership, fostering a culture of continuous learning and improvement within the security function.
Participate in a rotating weekly on-call schedule to ensure timely detection, response, and resolution of high-severity security incidents at any hour.
Collaborate with cross-functional stakeholders including engineering, product, and operations to define security requirements, streamline processes, and improve overall risk management.
Design, review, and implement security controls and architectural patterns that align with best practices and regulatory requirements for cloud-native systems.
Contribute to the development of security playbooks, runbooks, and standard operating procedures to standardize responses and improve team efficiency.
Support the strategic security roadmap by evaluating new tools, technologies, and frameworks that can strengthen the security posture and support future growth.
Requirements
- Bring a minimum of 4 years of professional experience in security engineering, with a proven track record of delivering measurable security outcomes.
- Demonstrate a strong background in incident response, threat hunting, SIEM platforms, digital forensics, and infrastructure scripting for automation and analysis.
- Show a history of building and automating security operations rather than only maintaining manual processes or point solutions.
- Exhibit deep expertise in securing cloud-native environments, with a specific focus on AWS services, including identity and access management, network security, and system hardening techniques.
- Possess the ability to lead technical projects from initial conception through design, implementation, and completion, ensuring alignment with business objectives.
- Communicate effectively with both technical and non-technical audiences, using strong interpersonal and written skills to collaborate across teams and mentor colleagues.
- Hold the right to work and reside in Austria, ensuring full compliance with local employment laws and regulations.
- Have a strong command of the English language to facilitate clear communication within a distributed, international team environment.
Nice to have
Practical, hands-on experience with Elastic Security, including the use of ES|QL and KQL for building queries, visualizations, and detection rules.
Skills & tools
- AWS
- Elastic Security (ES|QL/KQL)
- Datadog
- SOAR
- SIEM
- Digital Forensics
- Scripting
Practical notes
- Compensation includes a competitive salary and participation in a stock option plan designed to align employee interests with long-term company goals.
- The role operates under a hybrid work model, supported by 25 days of annual work-from-anywhere flexibility, allowing you to choose your optimal work location.
- You will receive 3 additional wellbeing days beyond standard leave, recognizing the importance of mental health and personal balance.
- The company provides 8 weeks of gender-neutral new parent leave to support all employees during significant life events.
- Professional development is encouraged through unlimited access to Udemy, enabling continuous learning and skill expansion in your career.
- Wellbeing resources are available via OpenUP, offering confidential mental health support and guidance when needed.
- Onsite dining is provided at the Vienna office, allowing you to enjoy convenient and nutritious meals during your working day.
About the company
Based in Vienna, Bitpanda GmbH operates as a digital broker. Services include cryptocurrency trading, commodities, securities, and ETFs through web and mobile channels. Strong growth led to a valuation exceeding four billion US dollars in 2021, marking unicorn status as the first Austrian company to do so. Annual revenue grew from 98.66 million US dollars in 2022 to 161.81 million US dollars in 2023.