Cloud Security Engineer @YGO GmbH
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 1mth ago

[Hiring] Cloud Security Engineer @YGO GmbH

1mth ago - YGO GmbH is hiring a remote Cloud Security Engineer. πŸ’Έ Salary: unspecified πŸ“Location: Europe, Africa

Role Description

We are hiring a Cloud Security Engineer to own the security of our cloud platform, the APIs our enterprise clients run on, and the company itself.

The role carries two things at once:

  • You own security engineering directly and hands-on.
  • You build the security function around it as we grow.

At YGO, a pod lead is a squad leader and a spokesperson, close to the work and close to the client, rather than a full-time manager. You will not stop being an engineer.

The work is broad:

  • Review source code in the morning.
  • Investigate an endpoint alert after lunch.
  • Help design a new authentication flow the next day.

You identify the highest-risk problems, decide what happens first, and execute.

We serve major travel enterprises and have enterprise commitments going live from the start of 2027. Security is a condition of that business, not a layer added afterward.

What you'll own

  • Application security:
    • Hands-on code and architecture review across our APIs, backend services, and internal tooling.
    • Targeted penetration testing to validate issues yourself.
    • Working with engineers on root causes and practical fixes rather than handing over reports.
    • Vulnerability management and the external penetration tests we commission.
  • Detection and response:
    • Knowing we are under attack while it is happening and what happens next.
    • Alerting, intrusion detection, incident process, and the on-call path.
  • Cloud and platform hardening:
    • Access control, network boundaries, secrets management, containers, and the deployment pipeline.
    • Security through the SDLC: CI/CD, repositories, and dependencies.
  • The security of our APIs:
    • Authentication and authorization, tenant isolation, token scoping and lifecycle, abuse prevention, enterprise SSO, and the audit trail our clients and our own accountability depend on.
  • The security of our AI systems:
    • Prompt injection, tool and agent permissions, our MCP server, retrieval and data ingestion.
    • The data-residency rules we are held to contractually.
  • Identity and company security:
    • SSO, MFA, and privileged access for employees, onboarding and offboarding, access reviews, MDM, endpoint security, and SaaS access.
    • The practical IT security a company our size needs done, not discussed.
  • Secure design across the pods:
    • Threat modelling and design review that enables engineers rather than gatekeeping them and raises the standard of what they ship.
  • The security function itself:
    • Set the priorities and the roadmap from actual risk, not security theatre.
    • Decide what we build, buy, automate, or leave for later.
    • Grow the team and hire into it, represent security to enterprise clients, and carry our SOC 2 programme on Drata.
    • Compliance is part of the job and it is not the centre of it.

What you'll secure

  • An AI search and recommendation engine for major travel enterprises: enterprise integration, SSO, client security reviews, GDS integrations.
  • A content enrichment API sold as SaaS: high scale, public facing, data and AI heavy.
  • The platform underneath: a client console with organisations, projects and API tokens, supplier and business-client integrations, data ingestion, an MCP server, and several LLM providers behind a single internal library.

Our stack

  • Backend: Go monorepo (no framework, 3+ services).
  • Data: PostgreSQL, Redis, Redis Asynq queue.
  • Hosting: PaaS-managed containers, Cloudflare in front.
  • Observability: Jaeger tracing, BetterStack for logging, alerting and on-call.
  • Compliance: Drata, SOC 2 in progress.
  • AI tooling: Claude Code, used across the whole team.

Qualifications

  • 5+ years of hands-on security work spanning more than one discipline.
  • Application security depth.
  • A strong grasp of authentication and authorization.
  • Cloud security fundamentals, properly.
  • Defensive experience alongside the offensive.
  • Threat modelling and secure architecture for cloud, container and API systems.
  • An engineering background.
  • Comfort in resource-constrained environments.
  • The appetite to build a team.
  • Working proficiency with Claude Code.
  • Judgement about pace.
  • Experience of SOC 2, ISO 27001 or demanding enterprise security reviews.
  • Excellent spoken and written English.

Nice to have

  • AI and LLM security.
  • Early security hire experience.
  • Experience leading or mentoring security engineers.
  • Go.
  • Security tooling or automation you built yourself.
  • MDM, endpoint protection and identity provider administration (Google Workspace or similar).
  • Compliance automation tooling (Drata, Vanta, Secureframe or similar).
  • Security certifications.
  • GDPR depth.
  • German.

Company Description

YGO.ai is a VC-funded AI tourism platform.

Before You Apply
️
remote Be aware of the location restriction for this remote position: Europe, Africa
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Cloud Security Engineer @YGO GmbH
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Europe, Africa
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,681+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later