Responsibilities
- Ship hands-on security work and learn Glia's platform, Glia-specific security challenges, and how the rest of the Platform group operates.
- Co-own the company security roadmap together with our Security Leader, balancing domains by risk.
- Get to know the team, our tooling, and Glia's project delivery methodologies.
- Delivery & roadmap: own security programs end-to-end - from roadmap shaping and stakeholder alignment through implementation and adoption - prioritising by risk and unblocking the team.
- People & mentorship: run 1:1s, manage performance, and grow the team.
- Hands-on contribution: lead by example - stay close to the technical work and take on high-leverage security engineering yourself.
- Application & product security - threat modelling, secure SDLC, design/code review, supply chain security
- Infrastructure & cloud security - AWS posture, runtime security, IAM; close collaboration with the Infrastructure team
- Security automation & AI - develop and own automation and AI tooling supporting company security goals; secure our AI-assisted development practices and LLM tooling
- Endpoint & corporate security - developer endpoint security (MDM, privilege, software governance), secrets hygiene
- Whole-posture assessment - run framework-based assessments (CIS Controls), identify where attention bears most value, and turn findings into prioritised, engineering-consumable plans
- Compliance interface - connect technical work to SOC 2 / PCI-DSS / ISO 42001 needs
- Mentor engineers, lead blameless post-mortems for security incidents, and present to and align senior management
Requirements
- Credible hands-on experience in at least two security domains (e.g. AppSec + cloud/infra) and literacy across the rest - you think in overall posture and risk, not tools
- You have built or scaled a security program end-to-end (process, tooling, adoption), ideally in a low-structure environment
- Coding and automation ability (Python preferred) and cloud security depth (AWS)
- Experience with AI-assisted development, and with securing it: LLM tooling (e.g. MCP), AI governance awareness
- Leadership readiness with evidence - mentoring, deputising for a lead, or formal lead experience - and the commitment to step up as DevSec Team Lead after ramp-up, owning the team's delivery while staying technical
- An educator and multiplier, not a gatekeeper: you enjoy high-empathy collaboration with developers
- Located in Europe
Nice to Have
- Framework-based posture assessment experience (CIS Controls, NIST CSF, or similar) - you can run an assessment and turn it into a prioritised roadmap
- Pentest, audit, and compliance exposure (SOC 2, PCI-DSS, ISO 42001)
- Terraform/Kubernetes; endpoint/MDM and IdP experience
Benefits
- Professional development support (trainings, courses, conferences, books, etc)
- Transparent career development system
- Different options for your working preferences (office, remote, flexible)
- Access to all the latest tools and equipment you'll need
- Team events: annual employee awards, internal hackathons, and a dozen cool events from cooking to the Glia olympic games :)
- Generous referral bonuses
Additional Information
- Glia is an equal-opportunity employer.
- The Glia Talent Acquisition team uses @glia.com and @gliatalent.com email addresses for coordinating interviews, providing updates, and sending documents.
- Our hiring process involves an introduction, practical and team interviews, and a decision and offer.