Senior Security Engineer
EstoniaJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
The role
We're looking for a Senior Security Engineer who thinks about security end to end — not one domain deep, but the whole posture: application, infrastructure, supply chain, endpoints, operations, and the compliance surface behind them.
You will co-own the company security roadmap together with our Security Leader, balancing domains by risk — while staying a hands-on technical contributor.
You will own security programs end-to-end: from roadmap shaping and stakeholder alignment through implementation and adoption.
This role carries a realistic growth path to DevSec Team Lead — a player-coach role: leading the team's delivery and growth while remaining deeply hands-on, with career progression on the engineering IC track.
The work
The role spans the whole security surface, prioritising by risk rather than by specialty:
Application & product security — threat modelling, secure SDLC, design/code review, supply chain security
Infrastructure & cloud security — AWS posture, runtime security, IAM; close collaboration with the Infrastructure team
Security automation & AI — develop and own automation and AI tooling supporting company security goals; secure our AI-assisted development practices and LLM tooling
Endpoint & corporate security — developer endpoint security (MDM, privilege, software governance), secrets hygiene
Whole-posture assessment — run framework-based assessments (CIS Controls), identify where attention bears most value, and turn findings into prioritised, engineering-consumable plans
Compliance interface — connect technical work to SOC 2 / PCI-DSS / ISO 42001 needs
Mentor engineers, lead blameless post-mortems for security incidents, and present to and align senior management
DevSec is part of the Platform group and works closely with Infrastructure, Developer Acceleration, and Observability. The team is remote-first with fully remote rituals — we have team members in Estonia and Poland today, and for this role we hire anywhere in Europe.
Tech Stack you will be working with
Infrastructure: AWS (Terraform, Kubernetes)
CI/CD: GitHub Actions
Vulnerability detection & runtime security: Snyk, Sysdig/Falco
SSO & MDM: Okta, Jamf
Coding: Python preferred; our product stack includes Elixir, Ruby, and Golang
AI-assisted development: Claude Code and agentic tooling are part of everyday engineering at Glia
Requirements
Credible hands-on experience in at least two security domains (e.g. AppSec + cloud/infra) and literacy across the rest — you think in overall posture and risk, not tools
You have built or scaled a security program end-to-end (process, tooling, adoption), ideally in a low-structure environment
Coding and automation ability (Python preferred) and cloud security depth (AWS)
Experience with AI-assisted development, and with securing it: LLM tooling (e.g. MCP), AI governance awareness
Leadership appetite with evidence — mentoring, deputising for a lead, or formal lead experience — and the ambition to own a team's delivery while staying technical
An educator and multiplier, not a gatekeeper: you enjoy high-empathy collaboration with developers
Located in Europe
Nice to have
Framework-based posture assessment experience (CIS Controls, NIST CSF, or similar) — you can run an assessment and turn it into a prioritised roadmap
Pentest, audit, and compliance exposure (SOC 2, PCI-DSS, ISO 42001)
Terraform/Kubernetes; endpoint/MDM and IdP experience
Benefits
Glia stock options and competitive salary
Professional development support (trainings, courses, conferences, books, etc)
Transparent career development system
Different options for your working preferences (office, remote, flexible)
Access to all the latest tools and equipment you'll need
Sports compensation, reimbursement for therapy, counseling sessions
Team events: annual employee awards, internal hackathons, and a dozen cool events from cooking to the Glia olympic games :)
Generous referral bonuses
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.