Software Development👥 51 employees📍 New York City, Düsseldorf, Tampa, Hamburg, Darmstadt, North Rhine-Westphalia, DEEst. 2018
Our mission is to build a ticketing platform that puts ticket sellers first — so they’re empowered to create experiences that people love. We help organizers to be more efficient, absolutely independ…
📋 Job Overview
Welcome to vivenu, the global leader in event ticketing tech and one of the world’s fastest-growing live entertainment tech firms. We are transforming event ticketing for global leaders like the Grammys, the Golden Globes, Stanford University and the Hockenheimring turning what was once a simple transaction into a strategic business advantage. Backed by over $65 million in funding, our platform empowers event organizers to own their brand experience, unlock deep data insights, and seamlessly integrate ticketing into their digital infrastructure.
🏢 About vivenu
With six offices worldwide and growing, we deliver a customizable, intuitive solution and industry-leading support that simplify even the most complex ticketing challenges – helping organizers deliver exceptional experiences and drive real growth. Join us and build the future of live entertainment.
🎯 The Role
This isn't just a maintenance role – it is a blank canvas to build, scale, and architect a state-of-the-art AppSec program from the ground up. We are currently operating at a fraction of our ultimate potential, which means you have an immense, blank-canvas opportunity to fundamentally shape our security culture, processes, and tooling across the entire global engineering organization. You will drive the entire AppSec lifecycle: from offensive red teaming and threat modeling to risk-based vulnerability management and pioneering a true shift-left culture.
✅ Key Responsibilities
Be a Trusted Advisor: Partner closely with engineering teams to champion security-by-design and elevate our overall security posture.
Offensive & Defensive Testing: Coordinate and execute threat modeling and advanced security tests across our product and underlying infrastructure.
Lead Next-Gen Vulnerability Management: Drive triage and remediation using modern, risk-based principles like EPSS, while leveraging AI technologies to accelerate security testing at scale.
Pioneer Security-as-Code: Design, implement, and automate security checks and guardrails (SAST, DAST, and secret scanning) directly into CI/CD pipelines.
Review & Refine: Perform deep-dive code and configuration reviews, advocating for secure coding practices that support a proactive shift-left strategy.
📌 Required Qualifications
Experience: 5+ years of dedicated Security Engineering experience, ideally within a high-growth SaaS, E-commerce, or Fintech environment.
SaaS Deep-Dive: The ability to dive deep into the business logic of a complex SaaS application to uncover and verify elusive attack vectors.
Web and API Security Mastery: a deep understanding of web/API attack vectors and scalable best practices and how to run workloads securely in a cloud environment (k8s, AWS/GCP/Azure)
Ownership: A proven track record of autonomously driving security initiatives from conception to completion.
Automation Mindset: Proficiency in at least one programming language for scripting and security tool development (bonus points for automating GRC evidence collection).
Education: A Bachelor’s or Master’s degree in Computer Science, Cybersecurity, IT, or a related technical field (or equivalent practical experience).
⭐ Desirable Experience
Experience navigating PCI DSS script security.
A background in Red/Purple Team operations and advanced penetration testing, paired with the empathy and collaboration skills needed to help dev teams fix software vulnerabilities.
Hands-on experience with Terraform for securing infrastructure-as-code and integrating security tests.