At Upvest, we are on a mission to make investing as easy as spending money. Upvest empowers businesses to offer a wide range of investment products and the best experience in the field of capital market investment and retirement planning. Upvest’s Investment API is easy to integrate so that fintechs and financial institutions can save resources and fully focus on their core business. We are proud to partner with Europe’s leading Fintechs and financial institutions such as DKB, Revolut, N26 and Raisin. Founded in 2017 by Martin Kassing, Upvest now brings together over 270 talented professionals from more than 70 nationalities. Upvest is backed by €280M in total funding from world-class investors, including BlackRock, Tencent, Sapphire Ventures, and Bessemer Venture Partners, Earlybird, Notion Capital, and Motive. Our latest €105M funding round in March 2026 - led by Sapphire and Tencent - serves as a massive catalyst for our growth, allowing us to offer premier investment experience. # What you’ll do:
Set the multi-quarter strategy for application and cloud security across Upvest's Investment API platform — aligned with our product roadmap, our tenant commitments, and our regulatory obligations under DORA, MiFID II, and BaFin's MaRisk / BAIT requirements. - Lead, mentor, and grow our Security Engineering and Upvest's security culture. You'll inherit a small, talented team and own hiring, onboarding, growth, and retention as we scale. And you'll create initiatives to build security into the development and product life cycle. - Own how Upvest performs encryption, authN/authZ, CI/CD, data, and network surfaces. We want fewer security review queues and more security baked into the templates. - Threat modeling, secure code review, SAST/DAST/SCA tooling integration in our GitHub Actions CI/CD, and vulnerability management. - — IAM, VPC Service Controls, Cloud KMS, CSPM (Wiz), Binary Authorization for GKE, Terraform-driven infrastructure security baselines, and our Linkerd service mesh posture. - Partner with our risk and compliance functions to translate DORA's ICT risk framework (Art. 5–9), secure development testing requirements (Art. 16), and threat-led penetration testing (Art. 24–27) into engineering work programmes — and into evidence we can show auditors and regulators. - Partner deeply with product and engineering teams. Architecture reviews, design partnerships, security champions across product squads, collaboration beats gatekeeping. - AI / LLM security, agentic identities, and the secure use of AI tooling in our own engineering workflow are an active concern
Build paved roads.
Own application security end-to-end.
Drive better cloud security posture across our GCP environment
Mature Upvest's DORA technical implementation.
Embed security in every product design.
Stay current on emerging threats.
Represent Upvest's security posture clearly to everyone
What you bring:
6–10 years in security engineering, with 4+ years focused on product security or cloud security, and you work well in a regulated environment. You don't need to check every box, but we're asking for evidence that you've taken security from "owned by one team in a queue" to "embedded in how an engineering org ships."
Hands-on, technically credible. You earn the trust of engineers by going deep, so you're comfortable reading code, threat modeling designs, debating architectures, and writing tooling when it's valuable. - Cloud-native security depth. GCP preferred; AWS or Azure transferable. You know IAM, network segmentation, KMS, IaC security (Terraform), and Kubernetes hardening (RBAC, network policies, Pod Security Standards) as a craft. - Product/Application security foundations. OWASP Top 10 / ASVS, secure code review, SAST/DAST/SCA tooling integration, supply-chain security (SLSA, signing). - Lead through influence, not gatekeeping. You drive security outcomes through partnership with engineering teams. You can navigate ambiguity, set direction, and make sound risk-based decisions that scale with the organisation. People want to work with you, because you don't just say "no", you say "yeah, and this is how". - Hire and grow people. You've built or grown a small team. You set a high bar in interviews, invest in onboarding, give real-time feedback, and address performance issues quickly and fairly. Communicate cleanly across audiences e.g. a security incident write-up to engineering, a control narrative to an auditor, and a risk briefing to executives are three different documents, and you can write all three.