Why this role exists
Peak One holds businesses' contacts, offers, services and payment information – on one shared data model. That is an advantage for users and a responsibility at the same time. Security and data protection should be designed in from the start rather than bolted on later. This role builds that practice and keeps developing it.
Your outcomes
- A documented picture of the main risks and safeguards.
- Security checks built into the development flow rather than blocking at the end.
- Clear, practised rules for access, secrets and permissions.
- A rehearsed process for security incidents, aligned with data protection obligations.
Your day and scope
Threat modelling for new features, reviewing code and configuration, checking access rights, keeping an eye on dependencies and advising developers. You work closely with platform and infrastructure engineering and with the people responsible for data protection. You are open about what we already do well and where we are not there yet.
Boundaries: You own the technical security of Peak One and the practice behind it. Legal data protection assessments and building individual features sit with other roles, which you support with your expertise.
Your first 90 days
First 30 days
Understand the architecture, data flows and existing safeguards; document and prioritise the main risks honestly.
By day 60
Deliver the most urgent measures, for example on access or secrets, and embed a first security check in the development flow.
By day 90
Build a documented security incident process, rehearse it once and propose a reasoned roadmap for next steps.
What you bring
- Solid experience in application or platform security.
- Ability to read code and explain vulnerabilities concretely.
- Assessing risk soberly rather than spreading fear.
- Understanding of data protection duties when handling personal data.
What you can learn with us
- Our architecture and the shared data model.
- The business logic of the individual modules.
When this role is less of a fit
You see security mainly as a gatekeeper that says no, or you only want to write policies without doing hands-on technical work.
Compensation and conditions
We only commit to compensation, contract type, working hours and location once they are approved. We will tell you all of it concretely in the first call, before you invest time in further steps.
Your application process
Short application
Name, email and your answer to the role's entry question. CV optional.
First call
A personal conversation about the role, conditions and your questions. We cover compensation and location concretely here.
Work sample
An announced, time-boxed task: a short threat model for a fictional feature and a review of a synthetic code snippet. No access to real systems, no testing against third-party systems, no unpaid work. People assess prioritisation, clarity and practicality.
Decision
A person decides, never an AI. You always get a response.
Your entry question
„A team wants to build an AI feature that summarises customer data from Peak One. Which three questions do you ask first, and why?“
Apply now