Qdrant
Posted 1w ago

Security Engineer

Qdrant
Berlin or Paris or Amsterdam or Madrid
RemoteFull Time
Responsibilities
  • triaging reports
  • building automation
  • responding incidents
Requirements
  • 3+ years security engineering or vulnerability management experience
  • Hands-on with Rust/Go/Python
  • Cloud and container security
  • Bug bounty triage, and CI/CD security
  • Strong written communication
Technical tools mentioned
RustGoPythonAWSKubernetesGitHubCI/CD

Job description

Qdrant is an open-source vector search engine powering the next generation of AI applications, from semantic search and retrieval-augmented generation (RAG) to AI agents and real-time recommendations.

Trusted by global leaders like Canva, HubSpot, Tripadvisor, Bosch, and Deutsche Telekom, we’re building the retrieval infrastructure layer for modern AI. Recently raising $50M in Series B funding, we are growing rapidly and committed to transforming how AI understands and interacts with data.

As a remote-first company, we believe diverse backgrounds, perspectives, and experiences fuel innovation. Here, you’ll own meaningful work, tackle challenges, and grow alongside passionate individuals dedicated to shaping the future of AI.

We are looking for a Mid-Level Security Engineer to own the hands-on engineering and operational work within our security program. You will be embedded in the Cloud Engineering team, report into the Security Officer, and work closely together to identify risks, set priorities, and drive security issues through remediation. You will act as a security enabler across all Product & Engineering.

What you will own

  • Run our public bug bounty program: triage reports, reproduce and validate findings, communicate clearly with security researchers, and drive remediation through to closure.

  • Investigate reported vulnerabilities at the code level, including our Rust core, Go and Python tooling.

  • Enable engineers to build secure systems: provide tooling, paved-road defaults, documentation, and practical guidance so security is the easy path, not a checkpoint.

  • Partner with engineering teams to design, review, and verify fixes, and set clear security requirements on changes where the risk warrants it.

  • Harden and maintain our GitHub organization’s security posture, including secret scanning, push protection, branch protection and rulesets, dependency alerts, and code scanning, in partnership with the engineering teams that use these repositories daily.

  • Monitor, investigate, and respond to security alerts across AWS, Kubernetes, CI/CD, and related infrastructure.

  • Track and report security metrics (vulnerability remediation SLAs, MTTR, patch latency, critical findings) and keep reporting current for the Security Officer.

  • Implement, configure, and maintain security tooling across our development and cloud environments.

  • Support security incident response, including investigation, containment, remediation, and follow-up.

  • Maintain clear, complete, and auditable records of vulnerability and incident work in our tracking systems.

  • Build security automation and guardrails that scale across the development lifecycle: CI/CD security checks, policy-as-code, GitHub automation, and automated cloud security controls, so secure defaults are enforced by tooling rather than review.

  • Participate in threat modeling and architecture reviews for new services and major changes.

We are also building out our ISMS, which creates opportunities to contribute to security-tooling evaluations, technical vendor assessments, and proof-of-concept work. Formal compliance ownership, vendor risk assessments, and customer security questionnaires remain with the Security Officer.

This is a hands-on technical role focused on security engineering, vulnerability management, and incident response. The Security Officer owns compliance, formal third-party risk assessments, and customer security questionnaires, allowing you to focus primarily on engineering work. On-call expectations are low: there is no formal rotation, though occasional availability for high-severity incidents is expected.

Who you are

  • You can read and navigate an unfamiliar codebase (Rust, Go, Python) well enough to validate a vulnerability report, trace its impact, and judge whether a proposed fix actually closes it.

  • You write and maintain automation and security tooling comfortably, and can hold a credible technical conversation in code review.

  • Experience triaging vulnerability reports or working with a bug bounty program, vulnerability disclosure program, product security team, or similar function.

  • Practical knowledge of cloud and container security, particularly AWS and Kubernetes.

  • Familiarity with GitHub security features and securing CI/CD pipelines.

  • The ability to investigate alerts and vulnerabilities methodically, distinguish genuine risk from noise, and recommend proportionate remediation.

  • Clear written communication skills for working with external researchers and internal engineering teams.

  • A self-directed approach and comfort independently managing a security queue.

  • 3+ years in a hands-on security engineering, product security, or vulnerability management role.

Nice to have

  • An offensive security background, such as penetration testing, CTF participation, vulnerability research, or exploit analysis.

  • Experience working in an open-source company or contributing security improvements to open-source projects.

  • Familiarity with cloud-native incident response.

Why join us

  • A remote-first, international team working on cutting-edge AI infrastructure.

  • A competitive salary with additional perks.

  • Flexible working hours and async-friendly culture.

  • High ownership and real impact.

  • Open-source, engineering-driven culture.

  • Choose your own laptop equipment.

For US-based candidates, we also offer a comprehensive benefits package including 401k match, health, dental, and vision insurance, plus flexible PTO policy.


Qdrant is an equal-opportunity employer. We believe the best ideas come from diverse teams, and we actively welcome applicants from all backgrounds. If this role excites you but you don't check every single box, we'd still love to hear from you! We don't want to miss out on great people because of a checklist.

Come build with us!

For information on how we handle your personal data, please refer to our Recruitment Privacy Policy


#LI-REMOTE

About Qdrant

Open-source vector search engine for AI retrieval and infrastructure.

Year founded
2021
Employees
100
Organization type
Private
Latest investment
Raised $50.00M Series B (2026) — led by Advance Venture Partners
Headquarters
DE

Similar jobs

Security Engineer roles near Berlin, Berlin
1w
Save
Mark Applied
Hide
Security Engineer — Platform Security
Berlin, Berlin, Germany
€55k-€90k/yr HybridFull Time
Gallup
Gallup: Provides global analytics and advice for leaders and organizations.
2+ YOEBachelor's degree in a relevant field, 2+ years securing enterprise cloud and infrastructure environments, cloud platform expertise, Splunk SIEM and EDR experience, vulnerability assessment, incident response, and scripting skills.
Splunk SIEM, Endpoint Detection and Response (EDR), Python, PowerShell, Bash, Azure, AWS, Microsoft 365, Oracle Cloud
1w
Save
Mark Applied
Hide
Security Engineer, Product Security - Global Security Organization
Singapore or Los Angeles or New York City or London or Dublin or Paris or Berlin or Dubai or Jakarta or Seoul or Tokyo
OnsiteFull Time
TikTok
TikTok: Global short-form video hosting and social media platform.
3+ YOERequires 3+ years in product security or cybersecurity, AI and automation experience, vulnerability analysis, incident response, and security researcher collaboration. Programming and Unix-based systems experience preferred.
Python, Go, JavaScript, OWASP Top 10
2w
Save
Mark Applied
Hide
Security Engineer
Berlin or London or Munich
OnsiteFull Time
Helsing
Helsing: AI-powered software and autonomous hardware for democratic defense missions.
Early-career security engineer with engineering foundations, ability to build non-trivial software, systems-level reasoning, and demonstrated self-directed security interest (CTFs, research, bug bounties).
AWS, GCP, Azure
3w
Save
Mark Applied
Hide
Security Engineer (all genders)
Augsburg or Krumbach or Berlin or Ingolstadt or Erlangen or Leipzig or Münster or Munich or Karlsruhe
€58k-€68k/yr HybridFull Time, Part Time
XITASO
XITASO: Software engineering consultancy for complex digital transformation projects.
2+ YOE2–5 years IT security or software development experience, strong knowledge of modern systems (APIs, cloud), conduct security assessments/tests, analyze risks, develop and implement security improvements, German and English C1.
3w
Save
Mark Applied
Hide
Senior Security Engineer, Enterprise Security
Chicago or New York City or Austin or Berlin or Bucharest or Dubai or Jakarta or London or Paris or San Francisco or São Paulo or Singapore or Seoul or Sydney or Tokyo
$129k-$180k/yr HybridFull Time
Braze
BrazeNASDAQ: BRZE: Platform for personalized customer engagement and cross-channel messaging.
5+ YOE5+ years security engineering experience, 3+ years in corporate security, hands-on endpoint, network, IAM, SSO, MDM, CrowdStrike EDR, SIEM, forensics, and SaaS security experience.
Crowdstrike EDR, SIEM, IAM, SSO, MDM
1mo
Save
Mark Applied
Hide
Security Engineer (m/f/d)
Berlin, Berlin, Germany
HybridFull Time
Security Research Labs
Security Research Labs: Cybersecurity research and consulting firm performing ethical hacking services.
Attacker-mindset security engineer with tooling, code-audit, fuzzing, AI/LLM assessment skills; familiarity with Rust, C/C++, Go, Solidity; strong communication for client advisory.
Rust, C, C++, Go, Solidity, Fuzzing, Static analysis, Dynamic analysis, CI, GitHub, LLM
1mo
Save
Mark Applied
Hide
Staff Security Engineer
Berlin, Berlin, Germany
HybridFull Time
PPRO
PPRO: Provides infrastructure for businesses to accept local payment methods.
Technical lead experience in application and cloud security, secure architecture, IaC and CI/CD security, threat modelling, and mentorship; fluent English.
AWS, GCP, Kubernetes, Docker, Terraform, GitHub Actions, Python, bash, Cloud Native Application Protection Platform (CNAPP), Cloud Security Posture Management (CSPM), SIEM
1mo
Save
Mark Applied
Hide
Security Engineer, Detection Response
San Francisco or New York City or London or Berlin or Remote
$208k-$312k/yr HybridFull Time
Vercel
Vercel: Frontend cloud platform for building and hosting web applications.
Extensive security operations experience with SIEM, logging, detection engineering, incident response, AWS, GitHub, SQL, scripting (Python/Bash) and compiled languages (Rust/Go).
SIEM, AWS, GitHub, SQL, Python, Bash, Rust, Go, EDR