Director Of Security Engineering
Job description
About the role
Parloa is on a mission to customer interactions by leveraging AI to create meaningful and engaging experiences. We are seeking a highly experienced and strategic leader to fill the role of Director of Security Engineering. In this position, you will assume full ownership of our security initiatives, guiding the development and implementation of security strategies that protect our products, data, and infrastructure. You will play a critical role in establishing a security-first culture across the organization, working closely with engineering, product, and executive teams to ensure security is integrated into every aspect of our operations. Your leadership will be instrumental in maintaining our compliance standards, managing security risks, and advancing our security posture as we grow and innovate.
Key facts
What you'll do
- Develop, refine, and execute the overall security strategy aligned with the company's growth plans and technological advancements.
- Lead, mentor, and expand the security engineering team, recruiting top talent and fostering leadership within the department.
- Oversee application security practices throughout the entire software development lifecycle, ensuring secure coding standards, vulnerability management, and security testing are embedded into engineering workflows.
- Design and implement security frameworks and controls for cloud-native applications, focusing on AWS and GCP environments, including identity and access management, network security, and infrastructure security.
- Establish and manage threat detection, monitoring, and incident response programs, continuously improving detection capabilities and leading investigations into security incidents.
- Collaborate with engineering teams to integrate security into CI/CD pipelines, DevOps practices, and infrastructure automation, ensuring security is built into every stage of development and deployment.
- Strengthen cloud security posture by implementing best practices for cloud configurations, access controls, and data protection across AWS and GCP platforms.
- Serve as the security representative during customer interactions, addressing security-related inquiries and demonstrating the company's commitment to security and compliance.
- Promote security practices tailored to AI systems, including securing large language model (LLM) pipelines, data handling, and model training processes.
- Work closely with the IT and Security teams to coordinate security efforts, ensuring policies and procedures are aligned and effectively implemented.
- Develop and track security metrics and KPIs to measure improvements, report on security posture, and inform strategic decisions.
- Stay current on emerging security threats, industry standards, and regulatory requirements, ensuring the company's security measures remain up-to-date and effective.
- Lead security audits, compliance assessments, and participate in external security reviews to maintain certifications such as SOC 2 and ISO 27001.
- Provide security guidance and training to engineering and product teams to foster a security-aware culture throughout the organization.
- Manage security budgets and resources efficiently, prioritizing initiatives that deliver the highest impact on security posture.
- Act as a security thought leader within the company, influencing product design and architecture decisions from a security perspective.
Requirements
- Over 12 years of professional experience in security, with at least 5 years in leadership roles, preferably within SaaS or platform environments.
- Extensive hands-on experience with cloud-native and containerized systems, particularly AWS and GCP, including managing security in these environments.
- Deep understanding of application security principles, secure architecture design, vulnerability management, and secure coding practices.
- Proven experience in detection and response, including managing security operations centers (SOCs), incident response, and threat intelligence.
- Strong leadership skills with the ability to build, mentor, and motivate security teams.
- Excellent communication skills, capable of translating complex security concepts into understandable language for technical teams and business stakeholders.
- Familiarity with security compliance frameworks such as SOC 2, ISO 27001, and experience conducting security audits and assessments.
- Knowledge of securing AI systems, especially large language models (LLMs), data pipelines, and model training security, is highly desirable.
- Ability to work effectively with cross-functional teams, including engineering, product, legal, and executive leadership.
- Strong problem-solving skills and a proactive approach to identifying and mitigating security risks.
- Experience managing security budgets and resources efficiently to maximize impact.
- A proactive learner who stays current with emerging security trends, threats, and best practices.
Nice to have
- Experience in the AI and machine learning security domain, particularly in securing LLM pipelines and data management.
- Knowledge of compliance standards such as GDPR, HIPAA, or other relevant regulations.
- Certifications such as CISSP, CISM, or OSCP are advantageous.
- Prior experience working in a fast-paced, innovative tech environment with a focus on security.
- Familiarity with security tools such as SAST, DAST, SCA, and incident response platforms.
Skills & tools
- AWS, GCP, Kubernetes
- Secure coding practices
- SAST, DAST, SCA tools
- Incident response methodologies
- Security compliance frameworks
- Cloud security best practices
- Threat detection and monitoring tools
- Security metrics and KPI development
Practical notes
This position is open to candidates who have the right to work in Germany. Parloa offers a competitive benefits package and a dynamic work environment focused on innovation and growth. The role involves on-site work at our Berlin office, with the possibility of remote work within Germany. Candidates should be prepared to engage in security audits, compliance assessments, and ongoing security training initiatives. The company values proactive security leadership and encourages continuous learning and development in the security domain.