> Markdown version of [/jobs/ext/2315098-security-engineer](https://www.wearedevelopers.com/jobs/ext/2315098-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Qdrant - **Location:** Amsterdam, Netherlands (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Software System Penetration Testing, Cloud Computing, Code Review, Continuous Integration, Github, Python (Programming Language), Open Source Technology, Software Vulnerability Management, Policy as Code, Information Security Management System, Cloud Platform System, Software Security, Mttr, Kubernetes, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://nl.indeed.com/viewjob?jk=e2050d86832587cc ## About the Role * You write and maintain automation and security tooling comfortably, and can hold a credible technical conversation in code review. * Experience triaging vulnerability reports or working with a bug bounty program, vulnerability disclosure program, product security team, or similar function. * Practical knowledge of cloud and container security, particularly AWS and Kubernetes. * Familiarity with GitHub security features and securing CI/CD pipelines. * The ability to investigate alerts and vulnerabilities methodically, distinguish genuine risk from noise, and recommend proportionate remediation. * Clear written communication skills for working with external researchers and internal engineering teams. * A self-directed approach and comfort independently managing a security queue. * 3+ years in a hands-on security engineering, product security, or vulnerability management role. Nice to have * An offensive security background, such as penetration testing, CTF participation, vulnerability research, or exploit analysis. * Experience working in an open-source company or contributing security improvements to open-source projects. * Familiarity with cloud-native incident response. ## Description * Run our public bug bounty program: triage reports, reproduce and validate findings, communicate clearly with security researchers, and drive remediation through to closure. * Investigate reported vulnerabilities at the code level, including our Rust core, Go and Python tooling. * Enable engineers to build secure systems: provide tooling, paved-road defaults, documentation, and practical guidance so security is the easy path, not a checkpoint. * Partner with engineering teams to design, review, and verify fixes, and set clear security requirements on changes where the risk warrants it. * Harden and maintain our GitHub organization's security posture, including secret scanning, push protection, branch protection and rulesets, dependency alerts, and code scanning, in partnership with the engineering teams that use these repositories daily. * Monitor, investigate, and respond to security alerts across AWS, Kubernetes, CI/CD, and related infrastructure. * Track and report security metrics (vulnerability remediation SLAs, MTTR, patch latency, critical findings) and keep reporting current for the Security Officer. * Implement, configure, and maintain security tooling across our development and cloud environments. * Support security incident response, including investigation, containment, remediation, and follow-up. * Maintain clear, complete, and auditable records of vulnerability and incident work in our tracking systems. * Build security automation and guardrails that scale across the development lifecycle: CI/CD security checks, policy-as-code, GitHub automation, and automated cloud security controls, so secure defaults are enforced by tooling rather than review. * Participate in threat modeling and architecture reviews for new services and major changes. We are also building out our ISMS, which creates opportunities to contribute to security-tooling evaluations, technical vendor assessments, and proof-of-concept work. Formal compliance ownership, vendor risk assessments, and customer security questionnaires remain with the Security Officer. This is a hands-on technical role focused on security engineering, vulnerability management, and incident response. The Security Officer owns compliance, formal third-party risk assessments, and customer security questionnaires, allowing you to focus primarily on engineering work. On-call expectations are low: there is no formal rotation, though occasional availability for high-severity incidents is expected., * You can read and navigate an unfamiliar codebase (Rust, Go, Python) well enough to validate a vulnerability report, trace its impact, and judge whether a proposed fix actually closes it. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)