Senior Product Security Engineer
Job description
About the role
N26 is actively seeking a Senior Product Security Engineer to define and own product security strategy across a diverse portfolio of digital financial services. The successful candidate will operate with a high degree of independence, taking full ownership of security outcomes while simultaneously empowering engineering teams to build resilient and innovative solutions. You will serve as a strategic mentor and thought leader, working to elevate the overall security maturity of our products and fostering a culture of proactive defense and continuous improvement. This position is critical as we integrate next-generation technologies, including artificial intelligence, into our complex financial infrastructure. You will lead the adaptation and evolution of security practices to ensure they are robust enough to support modern AI capabilities and maintain the integrity of our foundational microservice and mobile ecosystems. Your work will directly safeguard customer interactions and sensitive financial data, enabling the business to innovate with confidence.
What you'll do
You will define security requirements during the initial design phase for new digital services, features, and AI-driven functionalities to ensure security is built-in from the outset.
You will implement secure design principles and architectural patterns specifically for microservice components, APIs, and AI-enhanced features to mitigate systemic risks.
You will conduct thorough security assessments, including detailed threat modeling exercises and in-depth code reviews, to verify that implementation fidelity aligns with original design intent.
You will develop, deploy, and maintain comprehensive automation frameworks that integrate security validation seamlessly into CI/CD deployment pipelines and testing suites.
You will partner closely with product managers and engineering teams to embed security considerations into planning sessions, roadmaps, and ongoing experimentation initiatives.
You will perform active scanning of production systems and environments to identify, classify, and remediate vulnerabilities in a timely and efficient manner.
You will guide engineering professionals on specialized risks associated with artificial intelligence, machine learning models, and complex data-centric systems.
You will investigate emerging attack methodologies, adversarial techniques, and novel threat vectors targeting data flows, APIs, and intelligent systems to preempt future risks.
You will establish comprehensive security baselines and controls for new product initiatives, overseeing security from conception through design and ultimately to launch.
You will facilitate security training sessions, workshops, and knowledge-sharing programs to upskill cross-functional engineering teams and raise security awareness.
You will collaborate with compliance stakeholders and legal teams to ensure security initiatives align with relevant regulatory frameworks and industry standards.
You will review, evaluate, and recommend improvements to existing security tooling to enhance detection, prevention, and response capabilities.
You will coordinate incident response activities related to product security, working closely with engineering, operations, and incident management teams.
You will contribute to the development of meaningful security metrics, dashboards, and reporting to track the effectiveness of implemented controls and measure risk reduction over time.
Requirements
You possess expert-level software engineering skills, with a primary focus on Python or Go, enabling you to understand, review, and secure complex codebases.
You apply advanced threat modeling techniques to applications that leverage Large Language Models and other generative AI technologies.
You have a proven track record in conducting security testing for mobile applications, web platforms, and complex distributed systems at scale.
You have direct experience building and maintaining tools that support the full Secure Software Development Lifecycle, from requirements analysis to post-deployment monitoring.
You can analyze technologies involving Generative AI, including data governance frameworks, privacy implications, and model security challenges.
You have a history of independently resolving intricate security issues across varied product settings and under tight deadlines.
You demonstrate a deep understanding of secure coding practices, common vulnerability patterns such as OWASP Top 10, and secure software architecture.
You hold a strong grasp of foundational security principles, including authentication, authorization, encryption in transit and at rest, and comprehensive auditing.
You hold a strong understanding of microservice architecture patterns, mobile application security best practices, and modern data governance principles.
You are fluent in security concepts related to Generative AI, LLM security, prompt injection defenses, and responsible AI deployment.
Nice to have
There are no preferred items listed in the source material for this role.
Practical notes
Location: Spain
Engagement: Full-time
Compensation: 80000 EUR to 120000 EUR
This role requires fluency in security concepts such as microservice architecture, mobile application security, and data governance. You will utilize your expertise in Generative AI and Large Language Models to protect our products. Please confirm specific application steps on the official career portal.