Back to Jobs
Qdrant
Development 1h ago

Mid-Level Security Engineer

Qdrant
FranceFrance
GermanyGermany
NetherlandsNetherlands
SpainSpain
Full-time
Not Disclosed
Mid-Level

Job Description

Key Skills Required

Master these to land this role

PythonBestseller 🔥
Learn in 56 Hours
DevOpsBestseller 🔥
Learn in 63 Hours
RustAWSCybersecurity

Want to know if you're a match for this job?

Calculate My Match Score

What you will own

  • Run our public bug bounty program: triage reports, reproduce and validate findings, communicate clearly with security researchers, and drive remediation through to closure.

  • Investigate reported vulnerabilities at the code level, including our Rust core, Go and Python tooling.

  • Enable engineers to build secure systems: provide tooling, paved-road defaults, documentation, and practical guidance so security is the easy path, not a checkpoint.

  • Partner with engineering teams to design, review, and verify fixes, and set clear security requirements on changes where the risk warrants it.

  • Harden and maintain our GitHub organization’s security posture, including secret scanning, push protection, branch protection and rulesets, dependency alerts, and code scanning, in partnership with the engineering teams that use these repositories daily.

  • Monitor, investigate, and respond to security alerts across AWS, Kubernetes, CI/CD, and related infrastructure.

  • Track and report security metrics (vulnerability remediation SLAs, MTTR, patch latency, critical findings) and keep reporting current for the Security Officer.

  • Implement, configure, and maintain security tooling across our development and cloud environments.

  • Support security incident response, including investigation, containment, remediation, and follow-up.

  • Maintain clear, complete, and auditable records of vulnerability and incident work in our tracking systems.

  • Build security automation and guardrails that scale across the development lifecycle: CI/CD security checks, policy-as-code, GitHub automation, and automated cloud security controls, so secure defaults are enforced by tooling rather than review.

  • Participate in threat modeling and architecture reviews for new services and major changes.

We are also building out our ISMS, which creates opportunities to contribute to security-tooling evaluations, technical vendor assessments, and proof-of-concept work. Formal compliance ownership, vendor risk assessments, and customer security questionnaires remain with the Security Officer.

This is a hands-on technical role focused on security engineering, vulnerability management, and incident response. The Security Officer owns compliance, formal third-party risk assessments, and customer security questionnaires, allowing you to focus primarily on engineering work. On-call expectations are low: there is no formal rotation, though occasional availability for high-severity incidents is expected.

Who you are

  • You can read and navigate an unfamiliar codebase (Rust, Go, Python) well enough to validate a vulnerability report, trace its impact, and judge whether a proposed fix actually closes it.

  • You write and maintain automation and security tooling comfortably, and can hold a credible technical conversation in code review.

  • Experience triaging vulnerability reports or working with a bug bounty program, vulnerability disclosure program, product security team, or similar function.

  • Practical knowledge of cloud and container security, particularly AWS and Kubernetes.

  • Familiarity with GitHub security features and securing CI/CD pipelines.

  • The ability to investigate alerts and vulnerabilities methodically, distinguish genuine risk from noise, and recommend proportionate remediation.

  • Clear written communication skills for working with external researchers and internal engineering teams.

  • A self-directed approach and comfort independently managing a security queue.

  • 3+ years in a hands-on security engineering, product security, or vulnerability management role.

Nice to have

  • An offensive security background, such as penetration testing, CTF participation, vulnerability research, or exploit analysis.

  • Experience working in an open-source company or contributing security improvements to open-source projects.

  • Familiarity with cloud-native incident response.

Why join us

  • A remote-first, international team working on cutting-edge AI infrastructure.

  • A competitive salary with additional perks.

  • Flexible working hours and async-friendly culture.

  • High ownership and real impact.

  • Open-source, engineering-driven culture.

  • Choose your own laptop equipment.

For US-based candidates, we also offer a comprehensive benefits package including 401k match, health, dental, and vision insurance, plus flexible PTO policy.

How would you rate this job post?

See what other professionals think about this role.

banner

Qdrant (operating under qdrant.tech, legally Qdrant Berlin GmbH) is the premier, enterprise-grade open-source vector database management system, high-performance neural search engine, and similarity matching orchestration powerhouse engineered to act as the definitive, high-velocity infrastructure layer for Retrieval-Augmented Generation (RAG), large language model (LLM) persistent memory, and multimodal AI applications. Founded in 2021 by expert distributed systems and machine learning technologists Andre Zayarni and Andrey Vasnetsov, the corporate ecosystem completely eliminates the severe performance degradation, index-rebuilding latency spikes, and structural memory erosion commonly associated with legacy relational database plug-ins and primitive K-Nearest Neighbor (KNN) wrappers by building its custom storage architecture entirely from scratch in Rust. Moving far beyond traditional keyword search methods or high-latency post-filtering mechanisms, Qdrant natively unifies expansive JSON metadata payload filtering during HNSW graph traversal, native hybrid search combining dense and sparse vectors, ColBERT-based token-level late interaction reranking, and dynamic multivector storage configurations into a single high-availability data infrastructure framework. As the primary engine trusted by global developer communities and high-scale enterprise platforms, its open-source repository commands over 29,000 GitHub stars and powers critical AI pipelines for forward-thinking organizations globally. Backed by elite international venture groups, the enterprise has secured over $87 million in institutional funding—culminating in a massive Series B capital acceleration led by Spark Capital alongside 42 Capital and AVP to scale its managed Qdrant Cloud operations and native inference engine integrations. Under the hood, its technology stack harnesses advanced vector quantization strategies (including scalar and binary quantization) to execute up to a 64x memory footprint reduction with minimal recall loss, alongside real-time data indexing capabilities that expose newly added vector points instantaneously to active queries. Headquartered in Berlin, Germany, with a globally distributed remote engineering presence, the firm operates with absolute deterministic execution correctness across multi-tenant cloud and on-premise infrastructure environments. What sets Qdrant apart is its uncompromising dedication to replacing complex, multi-stage data orchestration loops with real-time, one-stage filtered similarity traversal and deep memory optimization; by bridging the gap between high-volume programmatic data repositories and millisecond-level neural vector retrieval, the corporation remains a definitive cornerstone of modern infrastructure scaling and worldwide applied artificial intelligence transformation.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Mid-Level Security Engineer at Qdrant