Skip to content

Open nowPosted 11 hours ago

Lead Security Engineer

Catawiki45 open roles

Where
Amsterdam, Netherlands
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowLead Security EngineerCatawiki · Amsterdam, Netherlands
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Catawiki's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market. Catawiki postings stay open a median of 6 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 11 hours ago

Catawiki median: 6 days open

The posting

At Catawiki, every day brings the extraordinary! Whether it’s Daniel Ricciardo’s Formula 1 Car, a Woolly Mammoth’s Skeleton, Lady Gaga's Jumpsuit or Usain Bolt’s running shoe, we encounter exceptional objects every day.

We’re a one-of-a-kind marketplace for buying and selling special objects. Each week, more than 100,000 unique items are auctioned, all carefully curated by our passionate in-house experts.

Having sold over 25 million unique objects, our mission is to become the world’s most popular destination for special objects. As a growing, diverse and sustainable scale-up, we proudly live by three core values. If these values resonate with you, we’d love to explore how you can join us.

  • Taking ownership and driving impact
  • Being open to change and feedback
  • Being passionate about our mission and our customers.

About the role and team

As our Lead Security Engineer, you’ll provide hands-on technical leadership in our small Security team within Platform Engineering. You’ll shape the security engineering roadmap and own the delivery of complex security initiatives, working with Product and Platform Engineering to protect our marketplace, our customers and their data.

Our platform runs on Google Cloud and Kubernetes. You’ll focus on application and cloud security, secure software delivery and risks in internal and AI-enabled systems. You’ll combine deep technical work with influence across engineering, turning security risks into controls and practices that teams can use in their everyday workflows.

This is an individual contributor role. As the team evolves, there may be an opportunity to move into people management, based on demonstrated readiness and business needs.

What you will do

  • Shape the security engineering roadmap and lead complex initiatives from assessment and design through implementation, rollout and ongoing operation.
  • Design and build security controls and automation across applications, cloud infrastructure, identity and access, CI/CD and infrastructure as code.
  • Lead threat modelling and secure code and design reviews. Work with engineering teams early to identify risks and agree practical changes before systems reach production.
  • Investigate vulnerabilities and recurring security weaknesses. Prioritise findings based on exposure and business impact, work with system owners on remediation and build reusable controls that prevent recurrence.
  • Improve security checks in engineering workflows, including dependency and secret scanning. Reduce false positives and make findings easier for developers to understand and resolve.
  • Contribute to security incident investigations and response. Improve detection and response tooling and use lessons from incidents to strengthen preventive controls.
  • Mentor security engineers and help product engineers build security skills through technical guidance, documentation and practical training.
  • Work with Legal, IT and Trust & Safety on technical security controls, policies and audit evidence where responsibilities overlap.
  • Measure the effectiveness and adoption of the controls you deliver. Communicate progress, technical decisions and remaining risks clearly to engineering and business stakeholders.

Who you are

  • You have substantial hands-on security engineering experience in a software or cloud environment and a track record of delivering security improvements across multiple teams.
  • You have strong knowledge of application and cloud security, including identity and access management, secrets management and secure software development.
  • You have led threat modelling, secure code and design reviews and complex remediation work, turning findings into solutions that engineers adopt.
  • You can develop or automate in Ruby, Python, Go or a similar language and are comfortable reviewing backend code. You have built and operated security tooling or controls in production.
  • You have integrated security into CI/CD, cloud infrastructure or infrastructure as code and can make sound trade-offs between risk reduction and engineering effort.
  • You have contributed to security incident investigations or responses and can work effectively with others under pressure.
  • You have led technical initiatives and mentored engineers. You’re interested in developing your leadership skills, including potentially taking on people management in the future.
  • You influence through technical credibility and collaboration, explain risks clearly to different audiences and take responsibility for seeing complex work through to completion.

Helpful experience

  • Experience with Google Cloud, Kubernetes and Terraform or similar infrastructure tooling.
  • Experience in a marketplace, e-commerce or another software product business, including account and API security.
  • Experience securing AI-enabled applications, agents or data pipelines, or using AI to improve security engineering workflows.

Why You'll Love Working with Us

  • Create a visible impact by working at scale in a global organisation serving millions of customers across 80+ categories. In our flat structure, every role has a broad scope and directly impacts both our customers and the business.
  • Learn and grow through our Learning & Development initiatives, including clear development plans and mentorship programmes to support your career progression.
  • A culture of connection defines us. We’re a passionate, diverse team of 800+ Catawikians representing 60+ nationalities. We foster an inclusive and queer-friendly environment where everyone is encouraged to bring their full self to work.
  • Celebrate life’s moments with us. You’ll receive a €100 Catavoucher when you join, a €50 Catavoucher on your birthday, and an extra day off each year to “Pursue Your Passion”. We also offer additional leave for key work anniversaries and important life events. Benefits may vary by location.

Our Offices and Way of Working

Our vibrant offices in Amsterdam and Lisbon are designed to inspire collaboration. Most Catawikians operate in a hybrid setup, combining office-based and remote work, with a minimum of two days per week in the office, unless a role is explicitly stated as fully remote or fully office-based.

Interested?

Apply with an English CV and Cover Letter. By applying, you agree to Catawiki’s Applicant Privacy Policy. If you’re excited about this role but don’t meet every requirement, we still encourage you to apply anyway. You may be just the right candidate for this or other roles.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Catawiki's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Catawiki's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Catawiki's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.