← Zurück zur Liste
Stelle · Senior

Lead Security Engineer

Security Engineer • Senior • Remote • Vollzeit • Deutschland Deutschland

As Recare's first dedicated security engineer, you will build the security program, the tooling and the security story told to customers from scratch. You join as Deputy CISO and also deal with the new attack surfaces that AI adds.

Responsibilities

  • ▹Vulnerability management: scanners and dependency updates across repos, plus the process that gets findings closed
  • ▹Partner to Platform: review security-sensitive infrastructure decisions and explore options like customer-managed keys or HSMs (Platform still owns architecture)
  • ▹Certifications, technical side: control design and assessments for the ISO 27001 and C5 setup, the security case for a potential upcoming Class IIa medical device (MDR), and pentest scoping and follow-up, with regulation like the EU Cyber Resilience Act on the horizon (roughly a quarter to a third of the role)
  • ▹Customer security: reusable docs, evidence and AI-assisted questionnaires, so the tenth enterprise deal costs a fraction of the first; join the call when a hospital CISO asks something new about the AI architecture
  • ▹Incident response: process, runbooks and escalation, and lead when it is real; design an on-call that fits a company of this size
  • ▹Company-wide security: watch the threat landscape, turn this week's supply-chain mess into concrete actions and set the baselines IT applies to devices and accounts
  • ▹Build and own the security program, the tooling and the security story told to customers
  • ▹Address AI security questions: agent sandboxing, prompt injection, voice data, computer-use automation inside hospitals

Requirements

  • ▹6+ years across software and security engineering, and you can point to a security program (or a big part of one) you have owned
  • ▹Technical counterpart through at least one ISO 27001, C5 or SOC 2 certification cycle: you have designed controls, faced an auditor and written the technical side of a Statement of Applicability (a hard requirement)
  • ▹Run vulnerability management somewhere real: scanners, dependency bots, triage and the follow-through that gets things fixed
  • ▹Follow the security scene closely (podcasts, advisories, incident write-ups)
  • ▹Genuine curiosity about AI security, both securing AI systems (agents, sandboxing, data flows) and using AI tooling to work at leverage
  • ▹Able to talk to engineers, auditors and hospital security teams in English without a slide deck translating for you

Nice to have

  • ▹German language skills, since customers and the C5 world are German-speaking
  • ▹Experience in healthcare or another regulated domain
  • ▹Offensive security experience
  • ▹Security certifications such as OSCP, CISSP or similar

Soft skills

Excellent communication with engineers, auditors and customersAutonomyCuriosity about AI securityOwnership

What we offer

  • ▹Purposeful work with a positive impact on patients, their families and healthcare professionals
  • ▹Flat hierarchies and a culture of mutual respect and recognition
  • ▹Remote-friendly company with flexible working hours
  • ▹Workations possible by arrangement
  • ▹Edenred card to use according to your needs
  • ▹Extra vacation day on your birthday

About the company

Recare is one of the leading German HealthTech companies, reshaping discharge management. Its SaaS platform connects two-thirds of all German hospitals with over 650 rehabilitation clinics and 25,000 nursing and homecare providers. The company has around 120 employees.

Languages: Angol: folyékony (mérnökökkel, auditorokkal és kórházi biztonsági csapatokkal), Német: előny

Ähnliche Stellen