Staff Security Engineer (all genders)
Core
Build scalable internal security products, guardrails, and automation for Cloud, App, Offensive, and GenAI security to enable safe, fast engineering at HelloFresh.
Role type
Staff Security Engineer (Individual Contributor)
Builds
Internal security platforms, paved roads, guardrails, and self-service capabilities for engineering teams.
Domain
Cloud Security, Application Security, Offensive Security, Generative AI Security
Deliverable
production ML models | product features | infrastructure
Required skills
Cloud security architecture, AWS, Kubernetes, IAM, network security, offensive security (penetration testing), software engineering (Python/Go/Java/TypeScript), automation, GenAI/LLM security, security tooling (SAST/DAST/SCA/IaC scanning)
Preferred skills
Security-by-design culture, threat modeling, SDLC integration, AI governance frameworks (NIST AI RMF, OWASP Top 10 for LLMs), GenAI force multiplier usage
Technologies
AWS, Kubernetes, Python, Go, Java, TypeScript, SAST, DAST, SCA, IaC scanning, SIEM, EDR, WAF, CNAPP/CSPM
Responsibilities
Define and drive security architecture across cloud environments; build and scale cloud security guardrails using automation and policy-as-code; partner with engineering to embed security into SDLC; lead initiatives in SAST, DAST, SCA, and supply chain security; drive offensive security activities including red/purple teaming; establish security patterns for GenAI and AI/ML systems; mentor senior engineers and influence technical direction.
Seniority
Staff, hands-on IC with strategic influence
