Redefine the Future of Live Entertainment Tech
Welcome to vivenu, the global leader in event ticketing tech and one of the world's fastest-growing live entertainment tech firms. We are transforming event ticketing for global leaders like the Grammys, the Golden Globes, Stanford University and the Hockenheimring. Backed by over $65 million in funding, our platform empowers event organizers to own their brand experience, unlock deep data insights, and seamlessly integrate ticketing into their digital infrastructure.
With over 10 million end users and usage quadrupling annually, our infrastructure now handles over 1 billion requests per month — and counting.
This isn't just a maintenance role – it is a blank canvas to build, scale, and architect a state-of-the-art AppSec program from the ground up. You will drive the entire AppSec lifecycle: from offensive red teaming and threat modeling to risk-based vulnerability management and pioneering a true shift-left culture.
What Makes This Role Challenging and Engaging
- High-Impact Technical Environment: You won't just follow blueprints; you will holistically influence a shift-left architecture across both application and platform layers.
- Modern Technology Stack: Dive into securing a massive TypeScript monolith alongside Go supporting services.
- Web and API: secure the application of the vivenu platform which provides customers with an out-of-the-box ticketing software as well as the underlying API structure.
- Complex Multi-Cloud Architecture: Challenge your skills against a sophisticated multi-tenant, multi-region environment spanning k8s, GCP and separate database services.
- Cutting-Edge Deployment: Secure a next-gen Kubernetes "satellite architecture" utilizing hardened private compute nodes, VPC peering, and Argo CD for GitOps.
As a Senior Security Engineer - AppSec (d/f/m) Your Responsibilities Will Include
- Be a Trusted Advisor: Partner closely with engineering teams to champion security-by-design.
- Offensive & Defensive Testing: Coordinate and execute threat modeling and advanced security tests.
- Lead Next-Gen Vulnerability Management: Drive triage and remediation using modern, risk-based principles like EPSS, while leveraging AI technologies.
- Pioneer Security-as-Code: Design, implement, and automate security checks and guardrails (SAST, DAST, and secret scanning) directly into CI/CD pipelines.
- Review & Refine: Perform deep-dive code and configuration reviews.
What You Will Need to Succeed in This Role
- Experience: 5+ years of dedicated Security Engineering experience, ideally within a high-growth SaaS, E-commerce, or Fintech environment.
- SaaS Deep-Dive: The ability to dive deep into the business logic of a complex SaaS application to uncover and verify elusive attack vectors.
- Web and API Security Mastery: a deep understanding of web/API attack vectors and how to run workloads securely in a cloud environment (k8s, AWS/GCP/Azure).
- Ownership: A proven track record of autonomously driving security initiatives from conception to completion.
- Automation Mindset: Proficiency in at least one programming language for scripting and security tool development.
- Education: A Bachelor's or Master's degree in Computer Science, Cybersecurity, IT, or a related technical field (or equivalent practical experience).
Preferred
- Experience navigating PCI DSS script security.
- A background in Red/Purple Team operations and advanced penetration testing.
- Hands-on experience with Terraform for securing infrastructure-as-code.
- Familiarity with our modern tech stack: GCP, Golang, and TypeScript.
Why Join vivenu?
Play a mission-critical role for global brands. We scale sustainably on a profitable, VC-backed foundation. Collaborate with over 160 dedicated professionals, including leaders from Google, Slack, and Salesforce.