aijobsdesk38K+ open roles
← All roles

Security Lead - m/f/d

LangdockOtherOnsiteFull-timeBerlin
€90k-€140k+ Equityposted 58d ago

HELP US CHANGE THE WAY THE WORLD WORKS

BUILD SOMETHING THAT MATTERS.

Langdock exists to change the way the world works, bridging the gap between what technology can do and what people actually do with it. We bring all leading AI models into one secure, model-agnostic platform and make them usable across entire organizations. Over 10,000 companies use our platform every day, from fast-growing startups to some of Europe's largest enterprises. Their employees open Langdock to draft strategies, analyze documents, or automate workflows - helping them to work smarter, think more creatively, and reach their full potential.

ABOUT THE ROLE

We’re hiring a hands-on Security Lead to strengthen the security of Langdock’s product, infrastructure, and internal systems.

Your primary focus will be application and infrastructure security. You’ll work closely with our CTO and engineering teams to identify risks, assess our defenses, and drive practical improvements. You’ll coordinate penetration tests, triage incoming vulnerability reports, and make sure findings turn into lasting fixes. You should be comfortable getting into technical details, challenging assumptions, and helping engineers choose the right controls.

You’ll also own the security of our internal IT environment, including identity, access, and device security. We’re looking for someone who builds reliable, automated processes and can judge whether our protections are effective.

Alongside this technical work, you’ll help explain our security posture to customers and support our compliance efforts. The foundation of this role is making Langdock secure; audits and customer assessments should reflect that work.

WHAT YOU WILL DO

The role's responsibility will span over multiple fields, which are:

APPLICATION SECURITY

- Coordinate penetration tests end to end. Define scope with engineering and external testing partners, support testing, assess findings, and follow remediation through to verification.

- Own vulnerability intake and triage. Monitor our security inbox and responsible disclosure program, assess reported issues, and work with engineering to prioritize and resolve them.

- Help engineering build securely. Review security-sensitive designs and changes, identify weaknesses in areas such as authentication, authorization, and data isolation, and recommend practical improvements.

INFRASTRUCTURE SECURITY

- Assess and improve our security posture. Work with engineering to evaluate how our production infrastructure and internal systems are protected, identify gaps, and drive improvements.

- Strengthen network and access controls. Review network separation, service exposure, privileged access, and permissions so systems and data are accessible only where needed.

- Verify that controls work in practice. Look beyond configuration checklists to understand how systems could be compromised and whether our protections would prevent or detect it.

INTERNAL SECURITY AND AUTOMATION

- Own identity and device security. Ensure we have effective MFA, appropriate access policies, and properly managed, encrypted, and patched devices.

- Automate the employee lifecycle. Build dependable processes for account provisioning, access changes, offboarding, and access reviews across Entra ID and our internal tools.

- Keep recurring work manageable. Use scripts, integrations, and AI tooling to automate security operations and surface issues that need attention.

CUSTOMER ASSURANCE AND COMPLIANCE

- Support customer security assessments. Help answer questionnaires and join customer conversations that require a clear, technically credible explanation of our security controls.

- Contribute to our compliance programs. Support our ISO 27001 and SOC 2 Type II work through effective controls, current evidence, and technical input into audits and risk assessments.

YOU MIGHT BE A FIT IF…

- Hands-on application and infrastructure security experience. You understand how modern SaaS applications and cloud environments are built, where they can fail, and how to protect them.

- Technical depth and sound judgment. You can investigate a vulnerability, assess its practical impact, discuss remediation with engineers, and distinguish urgent risks from lower-priority findings.

- Experience taking findings through to resolution. You’ve worked with penetration testers or vulnerability disclosure programs and helped teams turn reports into verified fixes.

- Confidence with identity and endpoint security. You’re comfortable configuring identity providers, MFA, access policies, and device management, and automating the processes around them.

- An automation mindset. You build scripts, workflows, and integrations to reduce recurring work, and use AI tooling thoughtfully to increase your effectiveness.

- Clear communication. You can explain technical risks and controls to engineers, colleagues, and customers. German is a plus, but not a requirement.

- Pragmatism. You prioritize meaningful risk reduction and choose controls that teams can realistically implement and maintain.

Experience with ISO 27001, SOC 2, and customer security assessments is valuable. Your strongest skill set should be in technical security.

THE ENVIRONMENT

We work from our office in Berlin, Greifswalder Strasse 212. Everyone works together in person because the hardest problems get solved faster at a whiteboard than in a Slack thread. Conversations happen faster, problems get solved quicker, and we actually know each other.

Days start at 8:30. Lunch & dinner are together. We run, go to the gym, and take care of ourselves. Health is not separate from work here, it is part of how we work well.

The vibe is calm but intense. No one is yelling or panicking. But everyone is working hard on things that matter.

COMPENSATION

Salaries are transparent and tied to levels, not negotiation. All roles include equity.

We will figure out the right level together based on your experience and scope. Levels are about the work you own, not your title or years of experience. We narrow down the expected salary range early in the process.

NEXT STEPS

We move fast. Most processes complete within two weeks.

If this sounds like your kind of work, we would like to meet you.