Senior Security Officer

Qdrant Germany
Remote
This Job is No Longer Active This position is no longer accepting applications
AI Summary

Qdrant seeks a Senior Security Officer to lead security posture, bridge compliance and engineering, and scale security culture. The role requires 5+ years of experience in Security Engineering, DevSecOps, or as a Security Officer in a cloud-native SaaS environment. Key requirements include cloud proficiency, regulatory and policy fluency, and risk assessment skills.

Key Highlights
Lead security posture and bridge compliance and engineering
Scale security culture and security champions program
Maintain 'always-audit-ready' status and oversee annual SOC 2 audits
Key Responsibilities
Own and prioritize the Security Backlog
Lead and evolve the Security Champions initiative
Conduct formal Architectural Risk Assessments
Maintain 'always-audit-ready' status
Oversee annual SOC 2 audits
Technical Skills Required
AWS GCP Azure IAM Multi-AZ architectures Trusted Advisor SOC 2 Type II HIPAA GDPR OWASP SAMM Drata Vanta Rust High-performance database environments
Benefits & Perks
Competitive salary
Equity
Benefits
Fully remote setup
Flexible working hours
Clear ownership of reliability and operational excellence
Nice to Have
Familiarity with the OWASP SAMM framework
Experience using automated compliance tools
Background in Rust or high-performance database environments

Job Description


At Qdrant, security is not just a checkbox; it is a core feature of our high-performance vector database. As our Security Officer, you will be the strategic lead and technical executor of our security posture. You will bridge the gap between high-level compliance (SOC 2, GDPR, HIPAA, …) and deep-tier engineering. Your mission is to further evolve and scale our security culture with the existing "Security Champions" program while remaining hands-on with architectural risk assessments and Cloud infrastructure hardening. You aren't just managing a backlog — you are building the foundation that allows Qdrant to scale safely.


Location


This role is remote and open to candidates located in Europe.


Candidates must demonstrate a mastery of European regulatory landscapes; this geographical preference is based on the technical requirements of the role rather than citizenship.


Tasks

  • Backlog & Strategy: Own and prioritise the Security Backlog, translating high-level threats and compliance needs into actionable engineering requirements for the development teams.

  • Security Champions Program: Lead and evolve our existing Security Champions initiative, mentoring engineers to perform internal security reviews and ensuring security is a distributed responsibility rather than a bottleneck.

  • Architectural Risk Management: Conduct formal Architectural Risk Assessments on critical components (e.g., Cloud RBAC, JWT, Inference) to ensure security is "baked-in" during the design phase of the SDLC.

  • Compliance & Audits: Maintain our "always-audit-ready" status using Drata and HeyData. You will oversee annual SOC 2 audits, GDPR requirements, and drive our OWASP SAMM roadmap toward a maturity score of 1.0.

  • Multi-Cloud Security Governance: Oversee security posture management across AWS, GCP, and Azure; leading technical compliance audits and implementing automated identity and access management (IAM) to ensure infrastructure resilience.

  • Vulnerability Management & Pentesting: Manage the bi-annual penetration testing lifecycle, coordinate with external security researchers (Bug Bounty Program), and ensure timely remediation of findings in coordination with the development teams.

  • Sales & Growth Support: Act as the subject matter expert for customers, completing detailed security questionnaires and ensuring our marketing vendor ecosystem remains compliant.


Requirements

Must-have



  • Experience: 5+ years in Security Engineering, DevSecOps, or as a Security Officer in a cloud-native SaaS environment.

  • Cloud Proficiency: Technical knowledge of AWS, GCP, Azure (IAM, Multi-AZ architectures, Trusted Advisor, etc.).

  • Regulatory & Policy Fluency: Practical experience maintaining SOC 2 Type II, HIPAA, and GDPR. You can architect a unified security policy framework that satisfies multiple compliance standards simultaneously, reducing operational overhead for the engineering team.

  • Risk Assessment Skills: Ability to perform threat modeling and architectural risk classification on complex distributed systems.

  • Communication: Strong stakeholder management skills; you can advocate for security resources during quarterly capacity planning and explain P0 risks to leadership.

  • Self-Starter: The ability to move from "reading the exact policy" to "investigating the code" to provide an informed response to technical queries.


Nice-to-have



  • Familiarity with the OWASP SAMM framework.

  • Experience using automated compliance tools like Drata or Vanta.

  • Background in Rust or high-performance database environments.

  • Professional certifications such as CISSP, CISA, or CCSP (Certified Cloud Security Professional), or advanced security-focused certifications from major cloud providers (e.g., AWS Certified Security – Specialty, Azure Security Engineer, or Google Professional Cloud Security Engineer).

  • Experience navigating the AWS Foundational Technical Review (FTR).


Benefits

  • Competitive salary, equity, and benefits

  • Fully remote setup with flexible working hours

  • Clear ownership of reliability and operational excellence

  • Opportunity to work on mission-critical customer-facing infrastructure

  • Strong collaboration with platform and engineering teams


If you enjoy de-risking complex cloud architectures and scaling security through a culture of shared responsibility and technical rigor, we’d love to hear from you.


Similar Jobs

Explore other opportunities that match your interests

Security Engineer

Cyber Security
5d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Helsing

Germany

Prisma Access Professional Services Consultant

Cyber Security
6d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

83zero

Germany

Information Security, Compliance & IKS Manager

Cyber Security
1w ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

cloudiax

Germany

Subscribe our newsletter

New Things Will Always Update Regularly