# Product & AI Security Engineer

[Linkedin](https://gurify.com/jobs?q=Linkedin) · Berlin · Posted yesterday

[AI & ML](https://gurify.com/jobs/ai-ml)

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.eu.greenhouse.io/linkedinjobs/jobs/4958392101)

## Job description

### ABOUT TALON.ONE:

Talon.One is the most powerful incentives engine that unifies loyalty, promotions and gamification into one holistic platform. Backed by enterprise-grade security and scalability, Talon.One empowers companies to build personalized, profitable promotions and loyalty programs using any data.

Today, over 250 of the world’s most-loved brands including Adidas, Sephora and Carlsberg work with Talon.One to drive deeper engagement and lasting loyalty with their customers.

### ABOUT THE ROLE:

You'll be one of Talon.One's first two security engineering hires, owning the security of everything we ship to our customers and third-party partners, from API authorization to the AI features going into our platform and their real-time observability and detections. You'll work hands-on, pairing directly with engineers and product managers rather than filing tickets, across a multi-tenant platform that powers promotions and loyalty for some of Europe's largest retail and travel brands. Based in Berlin, hybrid.

### ONCE YOU ARE HERE YOU WILL:

- Threat-model new product features before they're built, including AI-embedded ones, and turn what you find into real engineering work

- Own tenant isolation and API security across our Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP and third-party integrations

- Act as the security design authority for our AI features, working closely with the team behind UCP and Predict

- Build automated cross-tenant and adversarial testing that runs in CI, so isolation gets checked on every build, not only during our external yearly Pentest iterations

- Build standard, frictionless and automated golden paths for code security checks in CI workflows that developers can adopt by default without slowing down delivery

- Run vulnerability and coordinate efficient patch response across every squad outside Platform, from automated dependency updates to drilled emergency response

- Build and own application and AI security monitoring with our observability tools and build real-time security detection rules and alerts, and security events runbooks

- Design the security of the API integration between Talon.One and Adyen as our products come together

- Run a security champions programme so all our tribes build real security capability, not just the security team

- Experiment with AI, leverage innovative ways and build new workflows to identify, prioritize, and remediate product security risks at scale.

### WHAT WE NEED YOU TO BRING TO THE TABLE:

- Experience with shipping production code, whether you come from software engineering or from security work that includes coding

- Experience with a multi-tenant SaaS platform's authorization and tenant isolation model, and strong knowledge of how to test for broken object-level authorization automatically

- Design API security end-to-end: authentication, credential lifecycle, rate limiting, abuse resistance and webhook security

- Hands-on experience with threat-modelling methodologies such as STRIDE, translating identified threats into actionable engineering requirements and security tests

- Practical experience implementing and tuning SAST and DAST tools in CI/CD workflows, with a focus on useful developer feedback and effective vulnerability remediation

- Understanding how AI features actually get built, retrieval, context assembly, tool calling, agent loops, and know where indirect prompt injection breaks multi-tenant isolation

- Hands-on experience with Google Cloud security, Kubernetes, and tools like Wiz and Datadog

- Know how to build security monitoring and detections in-house tools (SIEM) yourself, from designing the signal through tuning it and writing the runbook

- Strong knowledge of OWASP security guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications

- Ability to influence engineers who don't report to you, and feel comfortable being early in a function with no existing playbook

### WHAT'S IN IT FOR YOU:

- 90+ team of engineers, product managers and product designers in Berlin

- Leaders with 8+ years of experience building our promotions engine

- €1,000 annual learning budget and free German language courses to boost your skills

- 30 days of annual leave, plus extra paid days for your birthday and moving day

- Home office setup budget, a monthly home office allowance

- Freedom to work from abroad for up to 90 days worldwide!

- Mental health support with nilo.health and a discounted Urban Sports Club membership

- 20% company subsidy on your pension contributions

- Subsidised BVG public transport ticket and a dog-friendly Berlin office where your furry friend is welcome

- Lease your ideal bike through BusinessBike

**Live in Linkedin’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- RE [RevOps & Data Engineer (AI x Greentech) (m/f/d)](https://gurify.com/job/revops-data-engineer-ai-x-greentech-m-f-d-at-reonic-ffea65a92cfe) Reonic · Berlin · 5 days ago
- PE [Product Manager, Agents](https://gurify.com/job/product-manager-agents-at-peec-43223955efe0) Peec · Berlin · 4 days ago
- TC [Principal Product Manager (AI Product) (f/m/d)](https://gurify.com/job/principal-product-manager-ai-product-f-m-d-at-think-cell-dc1e9a1e6912) Think Cell · Berlin (Germany) · last week
- DS [Data Scientist / Data Engineer - Nucs AI](https://gurify.com/job/data-scientist-data-engineer-nucs-ai-73eb41aad612) Berlin, Germany · last week
- RE [Product Designer (AI x Greentech) (m/f/d)](https://gurify.com/job/product-designer-ai-x-greentech-m-f-d-at-reonic-c96d360d36a8) Reonic · Berlin · 2 weeks ago
- RE [Growth Product Manager - UK (AI x Greentech) (m/f/d)](https://gurify.com/job/growth-product-manager-uk-ai-x-greentech-m-f-d-at-reonic-41b86e980d8a) Reonic · Berlin · 2 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Product \u0026 AI Security Engineer","description":"\u003Ch3\u003EABOUT TALON.ONE:\u003C/h3\u003E\u003Cp\u003ETalon.One is the most powerful incentives engine that unifies loyalty, promotions and gamification into one holistic platform. Backed by enterprise-grade security and scalability, Talon.One empowers companies to build personalized, profitable promotions and loyalty programs using any data.\u003C/p\u003E\u003Cp\u003EToday, over 250 of the world\u2019s most-loved brands including Adidas, Sephora and Carlsberg work with Talon.One to drive deeper engagement and lasting loyalty with their customers.\u003C/p\u003E\u003Ch3\u003EABOUT THE ROLE:\u003C/h3\u003E\u003Cp\u003EYou\u0026#39;ll be one of Talon.One\u0026#39;s first two security engineering hires, owning the security of everything we ship to our customers and third-party partners, from API authorization to the AI features going into our platform and their real-time observability and detections. You\u0026#39;ll work hands-on, pairing directly with engineers and product managers rather than filing tickets, across a multi-tenant platform that powers promotions and loyalty for some of Europe\u0026#39;s largest retail and travel brands. Based in Berlin, hybrid.\u003C/p\u003E\u003Ch3\u003EONCE YOU ARE HERE YOU WILL:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EThreat-model new product features before they\u0026#39;re built, including AI-embedded ones, and turn what you find into real engineering work\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOwn tenant isolation and API security across our Rule Engine, Integration API, Management API, CAMA, UCP Predict features, Talon.One MCP and third-party integrations\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAct as the security design authority for our AI features, working closely with the team behind UCP and Predict\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild automated cross-tenant and adversarial testing that runs in CI, so isolation gets checked on every build, not only during our external yearly Pentest iterations\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild standard, frictionless and automated golden paths for code security checks in CI workflows that developers can adopt by default without slowing down delivery\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERun vulnerability and coordinate efficient patch response across every squad outside Platform, from automated dependency updates to drilled emergency response\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild and own application and AI security monitoring with our observability tools and build real-time security detection rules and alerts, and security events runbooks\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDesign the security of the API integration between Talon.One and Adyen as our products come together\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERun a security champions programme so all our tribes build real security capability, not just the security team\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperiment with AI, leverage innovative ways and build new workflows to identify, prioritize, and remediate product security risks at scale.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWHAT WE NEED YOU TO BRING TO THE TABLE:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience with shipping production code, whether you come from software engineering or from security work that includes coding\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with a multi-tenant SaaS platform\u0026#39;s authorization and tenant isolation model, and strong knowledge of how to test for broken object-level authorization automatically\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDesign API security end-to-end: authentication, credential lifecycle, rate limiting, abuse resistance and webhook security\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands-on experience with threat-modelling methodologies such as STRIDE, translating identified threats into actionable engineering requirements and security tests\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPractical experience implementing and tuning SAST and DAST tools in CI/CD workflows, with a focus on useful developer feedback and effective vulnerability remediation\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnderstanding how AI features actually get built, retrieval, context assembly, tool calling, agent loops, and know where indirect prompt injection breaks multi-tenant isolation\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands-on experience with Google Cloud security, Kubernetes, and tools like Wiz and Datadog\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EKnow how to build security monitoring and detections in-house tools (SIEM) yourself, from designing the signal through tuning it and writing the runbook\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong knowledge of OWASP security guidance, including the OWASP Top 10, API Security Top 10, and Top 10 for Large Language Model Applications\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to influence engineers who don\u0026#39;t report to you, and feel comfortable being early in a function with no existing playbook\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWHAT\u0026#39;S IN IT FOR YOU:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E90\u002B team of engineers, product managers and product designers in Berlin\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELeaders with 8\u002B years of experience building our promotions engine\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E\u20AC1,000 annual learning budget and free German language courses to boost your skills\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E30 days of annual leave, plus extra paid days for your birthday and moving day\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHome office setup budget, a monthly home office allowance\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFreedom to work from abroad for up to 90 days worldwide!\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMental health support with nilo.health and a discounted Urban Sports Club membership\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E20% company subsidy on your pension contributions\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESubsidised BVG public transport ticket and a dog-friendly Berlin office where your furry friend is welcome\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELease your ideal bike through BusinessBike\u003C/li\u003E\u003C/ul\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"product-ai-security-engineer-at-linkedin-dde4a2718339"},"url":"https://gurify.com/job/product-ai-security-engineer-at-linkedin-dde4a2718339","datePosted":"2026-08-21","validThrough":"2026-10-06T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Linkedin","sameAs":"https://job-boards.eu.greenhouse.io/linkedinjobs"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"DE","addressLocality":"Berlin"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Germany","item":"https://gurify.com/jobs/germany"},{"@type":"ListItem","position":3,"name":"Product \u0026 AI Security Engineer","item":"https://gurify.com/job/product-ai-security-engineer-at-linkedin-dde4a2718339"}]}
```
