PPRO
Posted 1mo ago

Staff Security Engineer

PPRO
Berlin, Berlin, Germany
HybridFull Time
Responsibilities
  • leading security
  • designing architecture
  • conducting assessments
Requirements
  • Technical lead experience in application and cloud security
  • Secure architecture
  • IaC and CI/CD security
  • Threat modelling, and mentorship
  • Fluent English
Technical tools mentioned
AWSGCPKubernetesDockerTerraformGitHub ActionsPythonbashCloud Native Application Protection Platform (CNAPP)Cloud Security Posture Management (CSPM)SIEM

Job description

At PPRO, our mission is to simplify access to local payment methods and our vision is to enable the sale of goods and services to anyone in the world using their preferred way to pay. We empower partners such as Ant Group, PayPal and Stripe to access new markets, connect with more customers, and accelerate their growth.

Our strength lies in our diverse global team with 50+ nationalities and 10+ international locations- all united around one goal – to deliver the best possible products and services to our partners and customers. While our company mission is to keep innovating global commerce, our internal mission is to #chooseaction, #beopen, #thinkcustomer, #gofurther and #wintogether

The Purpose:

As Staff Security Engineer at PPRO, you’ll act as the technical lead for the Security Engineering (SecEng) team, driving technical and operational excellence while coaching and developing your colleagues. You’ll be pivotal in supporting our mission to build robust, secure, and resilient systems.
 
This role offers the opportunity to apply deep security expertise across application and cloud domains. You’ll serve as the primary technical interface for the wider organisation, influencing architecture and guiding engineering teams to embed a “secure by design” philosophy in everything we build.
 
You will be the main technical point of contact between the SecEng team and engineers across the organization. You’ll design secure solution architectures and build Security as Code solutions that enable consistent controls and high-velocity delivery. You will perform security assessments for new projects and technologies, utilizing threat modeling to identify risks early and define standardized, repeatable security patterns for the wider engineering team. If you thrive on finding win-win solutions that embed security into modern development workflows to safeguard our customers, this will be a great opportunity to have a positive impact at scale across the payments ecosystem.


As Staff Security Engineer at PPRO, you’ll act as the technical lead for the Security Engineering (SecEng) team, driving technical and operational excellence while coaching and developing your colleagues. You’ll be pivotal in supporting our mission to build robust, secure, and resilient systems.
 
This role offers the opportunity to apply deep security expertise across application and cloud domains. You’ll serve as the primary technical interface for the wider organisation, influencing architecture and guiding engineering teams to embed a “secure by design” philosophy in everything we build.
 
You will be the main technical point of contact between the SecEng team and engineers across the organization. You’ll design secure solution architectures and build Security as Code solutions that enable consistent controls and high-velocity delivery. You will perform security assessments for new projects and technologies, utilizing threat modeling to identify risks early and define standardized, repeatable security patterns for the wider engineering team. If you thrive on finding win-win solutions that embed security into modern development workflows to safeguard our customers, this will be a great opportunity to have a positive impact at scale across the payments ecosystem.


At PPRO, Senior Software Engineers (m/w/x) make some of the most significant decisions for the company. Think of yourself as an important contributor to the success of your team, with a significant impact on the team’s product, but also on its culture and spirit.

The Transaction Processing - Gateways team in Berlin is in charge of building, enhancing and maintaining payment processing products, with PPRO Global processing gateway as the core platform. The team needs to ensure the platform is continuously fully-featured, scalable, reliable, cost-efficient, secure, and auditable while discovering new ways to reduce the integration efforts from customers and reduce the time to enable new payment methods. 


What you’ll do:
  • Act as technical lead for the Security Engineering team, setting technical direction and coaching and mentoring engineers.
  • Serve as the external interface for the team, partnering with Engineering and Product teams to unblock them and embed security into all stages of the software development lifecycle.
  • Design and build reusable Security as Code artifacts and patterns that reduce developer friction while improving security outcomes.
  • Own the security of our cloud environment across AWS and GCP: conduct risk assessments and architecture reviews, design secure solutions, and write hardening standards and security guidelines.
  • Maintain and expand our Infrastructure as Code codebases and CI/CD pipelines, and develop automations for cloud security posture management (CSPM) and our Cloud Native Application Protection Platform (CNAPP).
  • Conduct threat modelling across applications, services and cloud systems, and create detection rules for our SIEM.
  • Provide expert application, product and cloud security guidance, and drive security assessments and penetration testing initiatives. 
  • Establish and share security standards and best practices across teams, consulting stakeholders and making data-driven decisions.
  • Explore how AI can solve security problems, and drive proactive improvements from emerging security trends and technologies.


  • What we look for in you:
  • Results-oriented, highly collaborative, pragmatic and proactive, and with a continuous improvement mindset.
  • A natural technical leader: able to guide, coach and mentor engineers, lead cross-team collaborations, and act as a trusted interface between security and the wider engineering organization.
  • Strong interpersonal and communication skills, able to unblock teams and foster security awareness throughout the company.
  • Deep experience across both application/product security and cloud security, with a strong background in software development.
  • Experience designing and building scalable security controls, architecture and services, taking strategic decisions and having a wide impact.
  • Strong expertise in cloud (preferably AWS, and GCP) and container security (Kubernetes, Docker).
  • Deep understanding of DevSecOps and CI/CD security controls, with hands-on experience in Infrastructure as Code (preferably Terraform), CI/CD pipelines (preferably GitHub Actions) and scripting (Python, bash).
  • Fluency with AI coding tools and curiosity about applying AI to security problems.
  • Developer mindset and empathetic approach to find innovative “win-win” solutions.
  • Security qualifications a bonus.
  • Excellent communication and collaboration skills and fluent proficient in English.
  • If you’re passionate about security and eager to make a significant impact in a fast-paced environment, we’d love to hear from you!


    What's in it for you?

    Hybrid working - We offer a hybrid structure with a 3 days / week on site expectation, so you can strike the balance between office and home working. In addition to our 30-day holiday allowance, we also provide a work from abroad policy, enabling employees to work remotely for up to another 30 days per year.

    Learning and Development - We offer a €1,000 annual budget to support your professional growth—because investing in your development benefits us all. In addition, we provide leadership cafés, on-the-job training, and other opportunities to help you grow your skills and thrive in your role.

    Insurance - Because better safe than sorry - we want our employees to benefit from various insurances including accident insurance, disability insurance, direct insurance (bAV) and travel insurance. 

    Gym membership - PPRO helps contribute towards the costs of your gym membership, supporting your physical fitness journey while easing the burden on your wallet

    Enhance Family Leave - We understand the importance of family - that's why we offer enhanced family leave to support you during key life moments.


    Mental Health Platform - We’ve teamed up with a top well-being platform to provide one-on-one therapy, chat therapy, therapist-led courses, guided meditations, and more.

    Pet-friendly office - Because work is better with your paw-tners by your side


    Our Principles: 

    We get things done: We are courageous; we take ownership, make decisions and get things done.

    We act with trust and integrity: We listen first and challenge respectfully. We seek out and leverage diverse perspectives. We welcome and offer honest and open feedback, always assuming positive intent

    We put the customer first: We are laser focused on delivering outstanding outcomes for our customers. We put the customer at the heart of what we do.

    We make things better: We boldly explore  new ideas and have an unwavering commitment to continuous improvement.

    We work as a team: We collaborate closely and value team success over individual achievement.

    About PPRO

    Provides infrastructure for businesses to accept local payment methods.

    Year founded
    2006
    Employees
    499
    Organization type
    Private
    Latest investment
    Raised $92.90M Series D (2024) — led by PayPal Ventures, J.P. Morgan, Citi
    Headquarters
    GB

    Similar jobs

    Security Engineer roles near Berlin, Berlin
    3d
    Save
    Mark Applied
    Hide
    Senior Security Engineer (all genders)
    Munich or Berlin
    OnsiteFull Time
    Capmo
    Capmo: Cloud-based construction project management software for contractors.
    7+ YOESecurity engineering role requiring 7–10 years of experience; the posting provides no detailed qualifications or responsibilities.
    Node.js, React.js, AWS, TypeScript
    2w
    Save
    Mark Applied
    Hide
    Security Engineer — Platform Security
    Berlin, Berlin, Germany
    €55k-€90k/yr HybridFull Time
    Gallup
    Gallup: Provides global analytics and advice for leaders and organizations.
    2+ YOEBachelor's degree in a relevant field, 2+ years securing enterprise cloud and infrastructure environments, cloud platform expertise, Splunk SIEM and EDR experience, vulnerability assessment, incident response, and scripting skills.
    Splunk SIEM, Endpoint Detection and Response (EDR), Python, PowerShell, Bash, Azure, AWS, Microsoft 365, Oracle Cloud
    2w
    Save
    Mark Applied
    Hide
    Security Engineer, Product Security - Global Security Organization
    Singapore or Los Angeles or New York City or London or Dublin or Paris or Berlin or Dubai or Jakarta or Seoul or Tokyo
    OnsiteFull Time
    TikTok
    TikTok: Global short-form video hosting and social media platform.
    3+ YOERequires 3+ years in product security or cybersecurity, AI and automation experience, vulnerability analysis, incident response, and security researcher collaboration. Programming and Unix-based systems experience preferred.
    Python, Go, JavaScript, OWASP Top 10
    2w
    Save
    Mark Applied
    Hide
    Security Engineer
    Berlin or Paris or Amsterdam or Madrid
    RemoteFull Time
    Qdrant
    Qdrant: Open-source vector search engine for AI retrieval and infrastructure.
    3+ YOE3+ years security engineering or vulnerability management experience; hands-on with Rust/Go/Python, cloud and container security, bug bounty triage, and CI/CD security; strong written communication.
    Rust, Go, Python, AWS, Kubernetes, GitHub, CI/CD
    3w
    Save
    Mark Applied
    Hide
    Security Engineer
    Berlin or London or Munich
    OnsiteFull Time
    Helsing
    Helsing: AI-powered software and autonomous hardware for democratic defense missions.
    Early-career security engineer with engineering foundations, ability to build non-trivial software, systems-level reasoning, and demonstrated self-directed security interest (CTFs, research, bug bounties).
    AWS, GCP, Azure
    4w
    Save
    Mark Applied
    Hide
    Security Engineer (all genders)
    Augsburg or Krumbach or Berlin or Ingolstadt or Erlangen or Leipzig or Münster or Munich or Karlsruhe
    €58k-€68k/yr HybridFull Time, Part Time
    XITASO
    XITASO: Software engineering consultancy for complex digital transformation projects.
    2+ YOE2–5 years IT security or software development experience, strong knowledge of modern systems (APIs, cloud), conduct security assessments/tests, analyze risks, develop and implement security improvements, German and English C1.
    1mo
    Save
    Mark Applied
    Hide
    Senior Security Engineer, Enterprise Security
    Chicago or New York City or Austin or Berlin or Bucharest or Dubai or Jakarta or London or Paris or San Francisco or São Paulo or Singapore or Seoul or Sydney or Tokyo
    $129k-$180k/yr HybridFull Time
    Braze
    BrazeNASDAQ: BRZE: Platform for personalized customer engagement and cross-channel messaging.
    5+ YOE5+ years security engineering experience, 3+ years in corporate security, hands-on endpoint, network, IAM, SSO, MDM, CrowdStrike EDR, SIEM, forensics, and SaaS security experience.
    Crowdstrike EDR, SIEM, IAM, SSO, MDM
    1mo
    Save
    Mark Applied
    Hide
    Security Engineer (m/f/d)
    Berlin, Berlin, Germany
    HybridFull Time
    Security Research Labs
    Security Research Labs: Cybersecurity research and consulting firm performing ethical hacking services.
    Attacker-mindset security engineer with tooling, code-audit, fuzzing, AI/LLM assessment skills; familiarity with Rust, C/C++, Go, Solidity; strong communication for client advisory.
    Rust, C, C++, Go, Solidity, Fuzzing, Static analysis, Dynamic analysis, CI, GitHub, LLM