Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой — после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Talon.One provides an incentives engine that unifies loyalty, promotions, and gamification into one platform. The platform uses enterprise-grade security and scalability to help companies create personalized promotions and loyalty programs from their data, serving brands such as Adidas, Sephora, and Carlsberg.
задачи
Threat-model new product features, including AI-embedded features, and turn findings into engineering work;
Own tenant isolation and API security across the Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP, and third-party integrations;
Act as the security design authority for AI features in collaboration with the UCP and Predict team;
Build automated cross-tenant and adversarial testing in CI;
Build automated golden paths for code security checks in CI workflows;
Run vulnerability management and coordinate patch response across squads outside Platform;
Build and own application and AI security monitoring, real-time detection rules, alerts, and security event runbooks;
Design the API integration security between Talon.One and Adyen;
Run a security champions programme across all tribes;
Experiment with AI and build workflows to identify, prioritize, and remediate product security risks at scale.
требования
Experience shipping production code through software engineering or coding-focused security work;
Experience with authorization and tenant isolation models in multi-tenant SaaS platforms;
Strong knowledge of automatically testing for broken object-level authorization;
Ability to design API security end-to-end, including authentication, credential lifecycle, rate limiting, abuse resistance, and webhook security;
Hands-on experience with threat-modeling methodologies such as STRIDE;
Experience translating identified threats into actionable engineering requirements and security tests;
Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows;
Understanding of how AI features are built, including retrieval, context assembly, tool calling, agent loops, and indirect prompt injection risks to multi-tenant isolation;
Hands-on experience with Google Cloud security, Kubernetes, Wiz, and Datadog;
Ability to build security monitoring and detections in-house, from signal design and tuning to runbook creation;
Strong knowledge of OWASP guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications;
Ability to influence engineers without direct reporting lines and work early in a function with no existing playbook.
условия
€1,000 Annual learning budget;
Free German language courses;
30 Days of annual leave, plus extra paid days for a birthday and moving day;
Home office setup budget and monthly home office allowance;
Freedom to work from abroad for up to 90 days worldwide;
Mental health support with nilo.health and a discounted Urban Sports Club membership;