Skip to content

Open nowPosted 47 days ago

Senior Security Engineer (all genders)

Capmo8 open roles

Where
Munich
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Engineer (all genders)Capmo · Munich
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Capmo's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.0%30 days
This job: posted 47 days ago

The posting

Your role

Capmo is the digital partner on construction sites, with over 100k projects delivered faster and more successfully with the help of our platform. We enable architects, engineers, project managers and contractors to collaborate efficiently and run lean and optimized projects. We are one of the fastest-growing B2B SaaS companies in Europe and stay true to our mission of making hard things in construction feel easy.

Thousands of project managers run their construction sites on Capmo every day — which means our customers trust us with data that is critical to their business. Keeping that trust is the job you'd own.

Help us continue to revolutionize the industry! Find out more about us and come join us in our engineering hubs in Berlin and Munich.

As a Senior Security Engineer at Capmo, you will get to:

  • own product and cloud security end to end — threat modeling, security reviews, secure-by-default patterns, and the tooling in our CI/CD pipelines (SAST, dependency and container scanning, secret detection) that keeps findings from piling up.
  • harden our AWS infrastructure: IAM architecture, network segmentation, encryption, logging, workload security — and encode the baselines as policy-as-code instead of a wiki page nobody reads.
  • build our detection and response capability from the ground up, and be the technical lead when something actually happens — from detection through containment to the post-incident review.
  • own our vulnerability disclosure and pentest programs, and drive remediation with the product teams rather than filing tickets and hoping.
  • back our compliance work (ISO 27001, SOC 2, GDPR) with real technical controls and evidence, and support customer security reviews together with Sales.
  • shape the direction of security at Capmo as a hands-on senior IC — building guardrails that engineers adopt because they're good, not because they're mandated.

What we offer

  • Become a shareholder: Take part in our success with our employee stock option program (VSOP).
  • Grow fast: Benefit from an annual development budget of €1,000 and two Development Days to invest in your personal and professional growth.
  • Fitness, food or mobility budget? With EGYM Wellpass, you get unlimited access to 90+ gyms and swimming pools in Germany – or choose a lunch subsidy or a mobility budget as your preferred benefit.
  • Think ahead: We contribute 20% to your company pension plan. (only applicable in Germany)
  • Hybrid work model: We work in a hybrid setup — 3 days together in the office and 2 days wherever you work best.
  • Exceptional Team: Join a talented and diverse team with limitless growth opportunities.
  • Culture Day Off: Take a day off for essential occasions.

What you bring along

  • 7+ years of hands-on security engineering, including several years owning application and cloud security for a production SaaS platform end to end.
  • A track record of building security programs — SDLC, vulnerability management, detection and response — not just operating tools someone else set up.
  • Expert-level understanding of vulnerability classes and attack techniques well beyond the OWASP Top 10: you can threat-model a new feature, spot the subtle authz flaw in review, and explain the exploit path to the engineer who wrote it.
  • Deep experience hardening cloud infrastructure at scale (AWS ideally, GCP or Azure fine): IAM, network segmentation, container security, security-as-code — designed by you, not inherited.
  • Strong software engineering skills — you write production-quality code, build automation from scratch, and hold your own in architecture discussions with senior engineers.
  • Proven incident response leadership: you've been the technical lead when things went wrong.
  • The judgment to make risk-based calls under ambiguity, and the influence to get teams to act on them without formal authority.
  • Excellent English; German is a plus. Willingness to be on-site 3 days per week in Munich or Berlin.

Nice to have: building up a security function in a scale-up, detection engineering, ISO 27001 / SOC 2 certification experience, certs like OSCP or CISSP (valued, but hands-on skills matter more).

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Capmo's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Capmo's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Capmo's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.