> Markdown version of [/jobs/ext/2210342-product-ai-security-engineer](https://www.wearedevelopers.com/jobs/ext/2210342-product-ai-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product & AI Security Engineer - **Company:** Talon.One GmbH - **Location:** Berlin, Germany (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Software as a Service, Continuous Integration, Open Web Application Security, Rule Engine, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Datadog, Google Cloud, Grafana, Software Security, Rate Limiting, Kubernetes, Production Code, Integration Frameworks, Static Application Security Testing, Web Api, Dynamic Application Security Testing - **Published:** August 24, 2026 - **Apply:** https://www.adzuna.de/details/5853702619 ## About the Role * Experience with shipping production code, whether you come from software engineering or from security work that includes coding * Experience with a multi-tenant SaaS platform's authorization and tenant isolation model, and strong knowledge of how to test for broken object-level authorization automatically * Design API security end-to-end: authentication, credential lifecycle, rate limiting, abuse resistance and webhook security * Hands-on experience with threat-modelling methodologies such as STRIDE, translating identified threats into actionable engineering requirements and security tests * Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows, with a focus on useful developer feedback and effective vulnerability remediation * Understanding how AI features actually get built, retrieval, context assembly, tool calling, agent loops, and know where indirect prompt injection breaks multi-tenant isolation * Hands-on experience with Google Cloud security, Kubernetes, and tools like Wiz and Datadog * Know how to build security monitoring and detections in-house tools (SIEM) yourself, from designing the signal through tuning it and writing the runbook * Strong knowledge of OWASP security guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications * Ability to influence engineers who don't report to you, and feel comfortable being early in a function with no existing playbook ## Description You'll be one of Talon.One's first two security engineering hires, owning the security of everything we ship to our customers and third-party partners, from API authorization to the AI features going into our platform and their real-time observability and detections. You'll work hands-on, pairing directly with engineers and product managers rather than filing tickets, across a multi-tenant platform that powers promotions and loyalty for some of Europe's largest retail and travel brands. Based in Berlin, hybrid., * Threat-model new product features before they're built, including AI-embedded ones, and turn what you find into real engineering work * Own tenant isolation and API security across our Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP and third-party integrations * Act as the security design authority for our AI features, working closely with the team behind UCP and Predict * Build automated cross-tenant and adversarial testing that runs in CI, so isolation gets checked on every build, not only during our external yearly Pentest iterations * Build standard, frictionless and automated golden paths for code security checks in CI workflows that developers can adopt by default without slowing down delivery * Run vulnerability and coordinate efficient patch response across every squad outside Platform, from automated dependency updates to drilled emergency response * Build and own application and AI security monitoring with our observability tools and build real-time security detection rules and alerts, and security events runbooks * Design the security of the API integration between Talon.One and Adyen as our products come together * Run a security champions programme so all our tribes build real security capability, not just the security team * Experiment with AI, leverage innovative ways and build new workflows to identify, prioritize, and remediate product security risks at scale. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Web APIs you might not know about](https://www.wearedevelopers.com/videos/281-web-apis-you-might-not-know-about) - [5 steps for running a Kubernetes environment at scale](https://www.wearedevelopers.com/videos/88-5-steps-for-running-a-kubernetes-environment-at-scale) - [Software Engineering Social Connection: Yubo’s lean approach to scaling an 80M-user infrastructure](https://www.wearedevelopers.com/videos/1583-software-engineering-social-connection-yubo-s-lean-approach-to-scaling-an-80m-user-infrastructure) - [From Monolith Tinkering to Modern Software Development](https://www.wearedevelopers.com/videos/822-from-monolith-tinkering-to-modern-software-development) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix)