Skip to main content
Back to jobs

Senior Security Engineer (all genders)

Capmo

Munich 9/6/2026 Experienced
Apply on source ↗ Save

<br><strong>Your role</strong><p><p style="line-height:1.38;margin-top:12pt;margin-bottom:12pt;"><span style="font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Capmo is the digital partner on construction sites, with over 100k projects delivered faster and more successfully with the help of our platform. We enable architects, engineers, project managers and contractors to collaborate efficiently and run lean and optimized projects. We are one of the fastest-growing B2B SaaS companies in Europe and stay true to our mission of making hard things in construction feel easy.</span></p><p style="line-height:1.38;margin-top:12pt;margin-bottom:12pt;"><span style="font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Thousands of project managers run their construction sites on Capmo every day — which means our customers trust us with data that is critical to their business. Keeping that trust is the job you'd own.</span></p><p style="line-height:1.38;margin-top:12pt;margin-bottom:12pt;"><span style="font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Help us continue to revolutionize the industry! Find out more about us and come join us in our engineering hubs in Berlin and Munich.</span></p><p style="line-height:1.38;margin-top:12pt;margin-bottom:12pt;"><span style="font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:700;font-style:normal;text-decoration:none;">As a Senior Security Engineer at Capmo, you will get to:</span></p><ul><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:12pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">own product and cloud security end to end — threat modeling, security reviews, secure-by-default patterns, and the tooling in our CI/CD pipelines (SAST, dependency and container scanning, secret detection) that keeps findings from piling up.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">harden our AWS infrastructure: IAM architecture, network segmentation, encryption, logging, workload security — and encode the baselines as policy-as-code instead of a wiki page nobody reads.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">build our detection and response capability from the ground up, and be the technical lead when something actually happens — from detection through containment to the post-incident review.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">own our vulnerability disclosure and pentest programs, and drive remediation with the product teams rather than filing tickets and hoping.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">back our compliance work (ISO 27001, SOC 2, GDPR) with real technical controls and evidence, and support customer security reviews together with Sales.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:12pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">shape the direction of security at Capmo as a hands-on senior IC — building guardrails that engineers adopt because they're good, not because they're mandated.</span></p></li></ul></p><br><strong>What we offer</strong><p><ul><li style="color:rgb(0,0,0);font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Become a shareholder: </strong>Take part in our success with our employee stock option program (VSOP).</li><li style="color:rgb(0,0,0);font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Grow fast:</strong> Benefit from an annual development budget of €1,000 and two Development Days to invest in your personal and professional growth.</li><li style="color:rgb(0,0,0);font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Fitness, food or mobility budget?</strong> With EGYM Wellpass, you get unlimited access to 90+ gyms and swimming pools in Germany – or choose a lunch subsidy or a mobility budget as your preferred benefit. </li><li style="color:rgb(0,0,0);font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Think ahead:</strong> We contribute 20% to your company pension plan. (only applicable in Germany)</li><li style="color:rgb(0,0,0);font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Hybrid work model:</strong> We work in a hybrid setup — 3 days together in the office and 2 days wherever you work best.</li><li style="color:rgb(0,0,0);font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Exceptional Team:</strong> Join a talented and diverse team with limitless growth opportunities.</li><li style="color:rgb(0,0,0);font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Culture Day Off:</strong> Take a day off for essential occasions.</li></ul></p><br><strong>What you bring along</strong><p><ul><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:12pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">7+ years of hands-on security engineering, including several years owning application and cloud security for a production SaaS platform end to end.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">A track record of building security programs — SDLC, vulnerability management, detection and response — not just operating tools someone else set up.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Expert-level understanding of vulnerability classes and attack techniques well beyond the OWASP Top 10: you can threat-model a new feature, spot the subtle authz flaw in review, and explain the exploit path to the engineer who wrote it.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Deep experience hardening cloud infrastructure at scale (AWS ideally, GCP or Azure fine): IAM, network segmentation, container security, security-as-code — designed by you, not inherited.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Strong software engineering skills — you write production-quality code, build automation from scratch, and hold your own in architecture discussions with senior engineers.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Proven incident response leadership: you've been the technical lead when things went wrong.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">The judgment to make risk-based calls under ambiguity, and the influence to get teams to act on them without formal authority.</span></p></li><li style="list-style-type:disc;font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:12pt;margin-bottom:0pt;"><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Excellent English; German is a plus. Willingness to be on-site 3 days per week in Munich or Berlin.</span></p></li></ul><p style="line-height:1.38;margin-top:12pt;margin-bottom:0pt;"><span style="font-size:14px;font-family:Arial, Helvetica, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><span style="background-color:transparent;font-weight:700;font-style:normal;text-decoration:none;">Nice to have:</span><span style="background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"> building up a security function in a scale-up, detection engineering, ISO 27001 / SOC 2 certification experience, certs like OSCP or CISSP (valued, but hands-on skills matter more).</span></span><span style="font-size:11pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><br></span></p></p><p>Find <a href="https://www.arbeitnow.com">Jobs in Germany</a> on Arbeitnow</a>

nodeJSreact.jsAWSTypeScript

Related on GOH