Senior Product Security Engineer
Job description
About the role
You will own the security strategy for Veo's KickOff platform and the supporting on-prem infrastructure, ensuring that security controls are baked into every layer of our global AI sports video processing system. You will partner closely with product, platform, and infrastructure teams to define and implement security standards that protect our customers' video data and our AI models. You will design and evolve threat models for new features and large-scale infrastructure changes, translating complex risk scenarios into actionable technical requirements. You will lead security reviews for code, architecture, and third-party integrations, establishing a consistent and high bar across cloud and on-prem environments. You will drive incident response readiness for critical production services, owning playbooks and collaborating during postmortems to turn lessons into preventative controls. You will work with data science and operations to secure sensitive training workflows and video processing pipelines, ensuring that security scales with innovation. You will evangelize security best practices through documentation, tooling, and cross-functional mentorship, helping engineers ship safely without slowing down. You will continuously measure the effectiveness of security controls, using data to prioritize investments and demonstrate impact to both technical and executive stakeholders.
Key facts
What you'll do
Conduct threat modeling sessions for new KickOff platform features and on-prem infrastructure changes, identifying attack vectors and designing security controls before implementation.
Define and maintain a security architecture for our multi-cluster Kubernetes environment, covering both cloud-based services and on-prem model training workloads.
Implement and enforce security policies as code across development, testing, and production environments using GitOps principles and infrastructure automation.
Lead security code reviews for platform components, ensuring that authentication, authorization, encryption, and logging meet Veo's standards and regulatory expectations.
Design and operate detection and response mechanisms tailored to AI video processing systems, including monitoring for data exfiltration, model theft attempts, and pipeline abuse.
Collaborate with incident response teams during production outages or security events, leading root cause analysis and updating runbooks with actionable improvements.
Partner with data science and video processing teams to secure sensitive datasets, model artifacts, and training pipelines against insider and external threats.
Evaluate and integrate third-party security tools and services, assessing their fit within our cloud and on-prem stack while balancing usability and protection.
Establish security metrics and dashboards to track posture over time, reporting progress and risk trends to engineering leadership and stakeholders.
Mentor engineers on secure coding practices, cloud security patterns, and infrastructure hardening, embedding security into the daily workflow of the organization.
Champion secure delivery practices by working with product managers and scrum teams to prioritize security work alongside feature development.
Define and run security playbooks for common scenarios such as compromised credentials, container vulnerabilities, and configuration drift in hybrid environments.
Coordinate with compliance and legal stakeholders to ensure that security controls align with data protection requirements for video storage and processing across jurisdictions.
Drive continuous improvement of the security program by researching emerging threats, attack techniques, and defensive technologies relevant to AI and media processing platforms.
Requirements
You must have a Bachelor's or Master's degree in Computer Science, Information Security, or a closely related technical field.
You must have 5+ years of professional experience in application or infrastructure security, with a proven track record of securing complex software systems.
You must have hands-on experience with Kubernetes security, including network policies, pod security standards, admission controllers, and secrets management in both cloud and on-prem contexts.
You must be proficient in writing and reviewing code in at least one modern programming language, with the ability to perform deep security analysis of codebases and integrations.
You must have experience designing and implementing security controls in a GitOps-driven environment, using tools such as Argo CD, Flux, or similar platforms.
You must have a strong understanding of cloud security principles and architectures on at least one major cloud provider, as well as experience operating hybrid or on-prem infrastructure.
You must have demonstrated experience with security monitoring, detection, and incident response, including working with SIEMs, logs, and threat detection systems.
You must have a strong grasp of identity and access management concepts, including SSO, OAuth, OIDC, and RBAC, and experience implementing least-privilege access at scale.
Nice to have
Experience with AI or machine learning pipelines and the associated security and privacy risks is a plus.
Familiarity with video processing or media pipelines and their unique security challenges is a plus.
Contributions to open source security tools or participation in security research communities.
Practical notes
This role is full time based in Copenhagen.
The position requires collaboration across engineering, data science, and operations teams across time zones.
Veo is committed to building a diverse and inclusive workplace where all team members can thrive.