Lead Security Engineer
Catawiki Amsterdam, NetherlandsEst. Est. EUR 75,000–110,000 / yearSenior
Estimated range based on role, country and industry — not published by the company.
Key requirements
- Python
- Go
- Kubernetes
- Terraform
- Ci/Cd
- Audit
- Cloud Security
At Catawiki, every day brings the extraordinary! Whether it’s Daniel Ricciardo’s Formula 1 Car , a Woolly Mammoth’s Skeleton , Lady Gaga's Jumpsuit or Usain Bolt’s running shoe , we encounter exceptional objects every day.
We’re a one-of-a-kind marketplace for buying and selling special objects. Each week, more than 100,000 unique items are auctioned, all carefully curated by our passionate in-house experts.
Having sold over 25 million unique objects, our mission is to become the world’s most popular destination for special objects. As a growing, diverse and sustainable scale-up, we proudly live by three core values. If these values resonate with you, we’d love to explore how you can join us.
Taking ownership and driving impact
Being open to change and feedback
Being passionate about our mission and our customers.
About the role and team
As our Lead Security Engineer, you’ll provide hands-on technical leadership in our small Security team within Platform Engineering. You’ll shape the security engineering roadmap and own the delivery of complex security initiatives, working with Product and Platform Engineering to protect our marketplace, our customers and their data.
Our platform runs on Google Cloud and Kubernetes. You’ll focus on application and cloud security, secure software delivery and risks in internal and AI-enabled systems. You’ll combine deep technical work with influence across engineering, turning security risks into controls and practices that teams can use in their everyday workflows.
This is an individual contributor role. As the team evolves, there may be an opportunity to move into people management, based on demonstrated readiness and business needs.
What you will do
Shape the security engineering roadmap and lead complex initiatives from assessment and design through implementation, rollout and ongoing operation.
Design and build security controls and automation across applications, cloud infrastructure, identity and access, CI/CD and infrastructure as code.
Lead threat modelling and secure code and design reviews. Work with engineering teams early to identify risks and agree practical changes before systems reach production.
Investigate vulnerabilities and recurring security weaknesses. Prioritise findings based on exposure and business impact, work with system owners on remediation and build reusable controls that prevent recurrence.
Improve security checks in engineering workflows, including dependency and secret scanning. Reduce false positives and make findings easier for developers to understand and resolve.
Contribute to security incident investigations and response. Improve detection and response tooling and use lessons from incidents to strengthen preventive controls.
Mentor security engineers and help product engineers build security skills through technical guidance, documentation and practical training.
Work with Legal, IT and Trust & Safety on technical security controls, policies and audit evidence where responsibilities overlap.
Measure the effectiveness and adoption of the controls you deliver. Communicate progress, technical decisions and remaining risks clearly to engineering and business stakeholders.
Who you are
You have substantial hands-on security engineering experience in a software or cloud environment and a track record of delivering security improvements across multiple teams.
You have strong knowledge of application and cloud security, including identity and access management, secrets management and secure software development.
You have led threat modelling, secure code and design reviews and complex remediation work, turning findings into solutions that engineers adopt.
You can develop or automate in Ruby, Python, Go or a similar language and are comfortable reviewing backend code. You have built and operated security tooling or controls in production.
You have integrated security into CI/CD, cloud infrastructure or
See your match score for this role.
Xecodai maps the interview stages and shows what is preventing a 95% match.
