Cyber Security Staff Engineer
Job description
About the role
Solaris operates as Europe's leading embedded finance platform. The company holds a full German banking license and maintains a proprietary modular B2B technology stack. Solaris enables partners, ranging from small and medium businesses to large multinational non-financial corporations, to deliver compliant, customer-centric banking services across various industries. Founded in 2016, Solaris originated the Banking-as-a-Service model through a fusion of technology and banking expertise. The company is headquartered in Berlin and employs approximately 300 people in Europe.
This position involves guarding the platform while product development accelerates. The role focuses on designing security architecture for embedded finance APIs and cloud-based systems. You will collaborate directly with product teams to ensure features ship securely and remain compliant.
Key facts
What you'll do
You will design security workflows that embed SAST, DAST, SCA, and container scanning into continuous integration pipelines. You will own threat modeling sessions for application programming interfaces and microservices before production deployment. Performing deep-dive manual and automated secure code reviews across multiple codebases will be a core responsibility to uncover logic flaws and implementation weaknesses.
You will build and maintain "secure-by-default" internal libraries, frameworks, and developer tools to prevent entire categories of vulnerabilities. Managing the full application vulnerability lifecycle-from detection through validation and remediation-will fall within this role. You will act as a strategic advisor to product and engineering teams, providing security guidance that respects development speed and regulatory obligations.
Delivering hands-on secure coding workshops and security awareness sessions for engineering teams is expected, with topics covering OWASP Top 10 and risks associated with LLM and AI technologies. You will lead post-mortem analysis when security incidents affect application layers or data flows. Ensuring application security controls comply with financial data protection regulations and fintech standards is a mandatory duty. Adherence to institutional Processes & Procedures, as defined across Technology and Change Management policies, is required.
Requirements
You must hold a degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or demonstrate equivalent professional experience. A minimum of six years of professional experience in Application Security, DevSecOps, or Software Engineering roles is necessary, with a strong focus on security within high-growth cloud environments, particularly in Fintech or highly regulated sectors.
You must have a proven ability to analyze and secure code written in core tech stacks and modern programming languages, such as Java, Go, Python, TypeScript, or Rust. A deep understanding of web application vulnerabilities, API security, and exploitation techniques, including OWASP Top 10 and CWE, is essential.
Practical experience integrating security testing tools into modern CI/CD pipelines is required, using platforms such as GitHub Actions, GitLab CI, Jenkins, Snyk, or Semgrep. You should be experienced with cloud computing infrastructure, including AWS, GCP, or Azure, as well as containerization with Docker and orchestration using Kubernetes.
Experience managing or triaging external penetration testing reports and crowdsourced bug bounty programs is necessary. You must work comfortably within agile workflows and lean principles. Performing active threat modeling during the design phase is a core competency. The role operates as an individual contributor with a focus on technical mentorship.
Business-level fluency in written and spoken English is required. Proficiency in German is an advantage. You must translate complex cryptographic or technical security vulnerabilities into business risk for non-technical stakeholders and define actionable fixes for developers.
You will collaborate across teams while balancing security assurance with delivery objectives. The role demands strong analytical thinking to devise creative methods for securing current application architectures.
Nice to have
The source document did not specify any additional qualifications or skills.
Skills & tools
The source document did not specify particular skills or tools beyond those listed in the requirements and responsibilities.