Posted today · ArbeitnowSource discovery listing
Security Lead - m/f/d
Langdock
Role details
What you’ll be doing
Help Us Change the Way the World Works Build something that matters. Langdock exists to change the way the world works, bridging the gap between what technology can do and what people actually do with it. We bring all leading AI models into one secure, model-agnostic platform and make them usable across entire organizations. Over 10,000 companies use our platform every day, from fast-growing startups to some of Europe's largest enterprises. Their employees open Langdock to draft strategies, analyze documents, or automate workflows - helping them to work smarter, think more creatively, and reach their full potential. About the Role We’re hiring a hands-on Security Lead to strengthen the security of Langdock’s product, infrastructure, and internal systems. Your primary focus will be application and infrastructure security. You’ll work closely with our CTO and engineering teams to identify risks, assess our defenses, and drive practical improvements. You’ll coordinate penetration tests, triage incoming vulnerability reports, and make sure findings turn into lasting fixes. You should be comfortable getting into technical details, challenging assumptions, and helping engineers choose the right controls. You’ll also own the security of our internal IT environment, including identity, access, and device security. We’re looking for someone who builds reliable, automated processes and can judge whether our protections are effective. Alongside this technical work, you’ll help explain our security posture to customers and support our compliance efforts. The foundation of this role is making Langdock secure; audits and customer assessments should reflect that work. What You Will Do The role's responsibility will span over multiple fields, which are: Application security Coordinate penetration tests end to end. Define scope with engineering and external testing partners, support testing, assess findings, and follow remediation through to verification. Own vulnerability intake and triage. Monitor our security inbox and responsible disclosure program, assess reported issues, and work with engineering to prioritize and resolve them. Help engineering build securely. Review security-sensitive designs and changes, identify weaknesses in areas such as authentication, authorization, and data isolation, and recommend practical improvements. Infrastructure security Assess and improve our security posture. Work with engineering to evaluate how our production infrastructure and internal systems are protected, identify gaps, and drive improvements. Strengthen network and access controls. Review network separation, service exposure, privileged access, and permissions so systems and data are accessible only where needed. Verify that controls work in practice. Look beyond configuration checklists to understand how systems could be compromised and whether our protections would prevent or detect it. Internal security and automation Own identity and device security. Ensure we have effective MFA, appropriate access policies, and properly managed, encrypted, and patched devices. Automate the employee lifecycle. Build dependable processes for account provisioning, access changes, offboarding, and access reviews across Entra ID and our internal tools. Keep recurring work manageable. Use scripts, integrations, and AI tooling to automate security operations and surface issues that need attention. Customer assurance and compliance Support customer security assessments. Help answer questionnaires and join customer conversations that require a clear, technically credible explanation of our security controls. Contribute to our compliance programs. Support our ISO 27001 and SOC 2 Type II work through effective controls, current evidence, and technical input into audits and risk assessments. You Might Be a Fit If… Hands-on application and infrastructure security experience. You understand how modern SaaS applications and cloud environments are built, where they can fail, and how to protect them. Technical depth and sound judgment. You can investigate a vulnerability, assess its practical impact, discuss remediation with engineers, and distinguish urgent risks from lower-priority findings. Experience taking findings through to resolution. You’ve worked with penetration testers or vulnerability disclosure programs and helped teams turn reports into verified fixes. Confidence with identity and endpoint security. You’re comfortable configuring identity providers,
Skills & keywords