
Upvest · Berlin
At Upvest, we are on a mission to make investing as easy as spending money. Upvest empowers businesses to offer a wide range of investment products and the best...
At Upvest, we are on a mission to make investing as easy as spending money. Upvest empowers businesses to offer a wide range of
investment products and the best experience in the field of capital market investment and retirement planning. Upvest’s Investment
API is easy to integrate so that fintechs and financial institutions can save resources and fully focus on their core business.
We are proud to partner with Europe’s leading Fintechs and financial institutions such as DKB, Revolut, N26 and Raisin. Founded in
2017 by Martin Kassing, Upvest now brings together over 270 talented professionals from more than 70 nationalities. Upvest is
backed by €280M in total funding from world-class investors, including BlackRock, Tencent, Sapphire Ventures, and Bessemer Venture
Partners, Earlybird, Notion Capital, and Motive. Our latest €105M funding round in March 2026 - led by Sapphire and Tencent -
serves as a massive catalyst for our growth, allowing us to offer premier investment experience.
Upvest is at the inflection point where security needs to scale and remain a foundational discipline of the company. We're hiring
a Security Engineering Lead to step into our lean and efficient Security team, set its multi-quarter direction, work
cross-functionally and scale Security Engineering into a team that continues to own Upvest's entire application security and cloud
security posture in a highly regulated environment as it scales.
This role sits alongside our Security Operations and GRC teams, which owns detection, response, and compliance operations. Where
SecOps keeps watch over what's happening now, Security Engineering shapes what we build and how we build it, embedding security
into the SDLC, hardening our cloud environment, and building the platforms that make security teams more effective.
You will own the secure paved roads every Upvest engineer relies on: automated SAST/DAST/SCA in our GitHub Actions pipelines,
SSDLC adherence, IAM and network controls, and the technical implementation of DORA's (and other regulations') ICT risk framework
for our platform.
Our mission for the team is simple: make the secure way the easy way for everyone at Upvest.
product roadmap, our tenant commitments, and our regulatory obligations under DORA, MiFID II, and BaFin's MaRisk / BAIT
requirements.
hiring, onboarding, growth, and retention as we scale. And you'll create initiatives to build security into the development and
product life cycle.
review queues and more security baked into the templates.
Actions CI/CD, and vulnerability management.
Authorization for GKE, Terraform-driven infrastructure security baselines, and our Linkerd service mesh posture.
framework (Art. 5–9), secure development testing requirements (Art. 16), and threat-led penetration testing (Art. 24–27) into
engineering work programmes — and into evidence we can show auditors and regulators.
partnerships, security champions across product squads, collaboration beats gatekeeping.
engineering workflow are an active concern
regulated environment. You don't need to check every box, but we're asking for evidence that you've taken security from "owned
by one team in a queue" to "embedded in how an engineering org ships."
modeling designs, debating architectures, and writing tooling when it's valuable.
(Terraform), and Kubernetes hardening (RBAC, network policies, Pod Security Standards) as a craft.
supply-chain security (SLSA, signing).
navigate ambiguity, set direction, and make sound risk-based decisions that scale with the organisation. People want to work
with you, because you don't just say "no", you say "yeah, and this is how".
real-time feedback, and address performance issues quickly and fairly.
Communicate cleanly across audiences e.g. a security incident write-up to engineering, a control narrative to an auditor, and a
risk briefing to executives are three different documents, and you can write all three.
and the specific operational shape of selling to regulated customers.
modern backend language.
actionable technical requirements other people understand. You can hold your own with auditors and regulators without losing
engineering pragmatism.
in incident response. This matters in practice, you'll be part of the security on-call rotation, so being comfortable picking
up an active incident is real, not theoretical.
with the most powerful models and tooling on the market.
ambitious, and meaningful. You’ll work with modern technologies and create something entirely new. No legacy systems, no
limits.
professional coaching and enjoy the flexibility to work remotely abroad for up to 183 days a year. Recharge with UpRest, a
one-month fully paid sabbatical after every 4 years of working at Upvest.
use it.
on the role. We give you the choice and budget to work where you’re most comfortable and productive, either at home or in the
office. You choose.
and a participation in our employee equity program.
colleagues and celebrate our achievements.
connection, like Upfem for our female Upvengers, or UpVergent supporting neurodivergent Upvengers and allies.
others.
Upvest is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all
employees.
HELP US CHANGE THE WAY THE WORLD WORKS BUILD SOMETHING THAT MATTERS. Langdock exists to change the way the world works, bridging the gap between what technology can do and what people actually do with it. We bring all leading AI models into one secure, model-agnostic platform and make them usable across entire organizations. Over 10,000 companies use our platform every day, from fast-growing startups to some of Europe's largest enterprises. Their employees open Langdock to draft strategies, analyze documents, or automate workflows - helping them to work smarter, think more creatively, and reach their full potential. ABOUT THE ROLE We're hiring a hands-on Security Lead to own security at Langdock across all surfaces. Not just the management system, but the actual security of our identities, devices, premises, and processes. This is a broad ownership role, deliberately scoped for one ambitious person. We believe that with good automation and an AI-first way of working, one person can run what traditionally takes a small team: the certified ISMS, identity and access management, device management, security programs like bug bounty, and physical security. You'll use automation (and Langdock itself) aggressively to keep the operational load low and the bar high. You'll design technical and organizational controls that enable us to run our business securely and that actually make sense for how we build and operate. You'll also make sure we can prove they work, quarter after quarter, audit after audit. You'll work closely with engineering, operations, and sales by translating security and compliance requirements into controls people can realistically implement and maintain, and explaining our security posture to customers who consider Langdock. WHAT YOU WILL DO * Own identity & access. * Own identity and access management across all our identity surfaces. Build and automate the processes for onboarding, offboarding, and privilege provisioning so the right people have the right access at the right time, and nothing more. * Properly configure and own our Entra ID. Conditional access, group and role design, lifecycle automation, and integration with the tools our teams actually use. * Own devices. * Own MDM and device management. Ensure every device that touches company data is enrolled, encrypted, patched, and recoverable with as little friction for the team as possible. * Own the device inventory. Keep an accurate, automated picture of what hardware exists, who has it, and what state it's in. * Own security programs. * Run our bug bounty and security programs. Set up and operate responsible disclosure / bug bounty, triage findings, and drive them to resolution with engineering. * Own physical security of our premises. Access control, visitor handling, and the physical controls our certifications and customers expect. * Own the ISMS. * Own the information security management system. Maintain and continuously improve our ISO 27001 and SOC 2 Type II certified management system, ensuring it reflects how Langdock actually operates, not just how a framework says it should. * Design controls, not paperwork. Define technical and organizational safety measures that are proportionate, practical, and genuinely reduce risk. * Manage the risk register. Identify, assess, prioritize, and track information security risks; drive risk treatment plans to closure with the relevant owners. * Maintain evidence in Vanta. Keep our control evidence current and audit-ready on an ongoing basis. * Run audits & new standards. Manage the end-to-end audit process for existing certifications (ISO 27001, SOC 2 Type II) and lead scoping and readiness for new standards as the business requires (e.g. C5, TISAX, HDS, FedRAMP-adjacent requirements, customer-specific frameworks). * Partner across the company. * Partner with engineering, operations, sales. Sit close to the teams that build and run the product; help them implement controls in ways that fit into existing workflows (CI/CD, infrastructure, access management) rather than bolting security on afterward. * Respond to customer and prospect security questions, including security questionnaires and due-diligence requests, as needed. * Automate relentlessly. Treat every recurring manual task (evidence collection, access reviews, provisioning, questionnaires) as something to be automated. Use AI tooling as a force multiplier so this role scales with the company without scaling headcount. YOU MIGHT BE A FIT IF… * Technical background. You understand cloud infrastructure, identity providers, software development practices, and how modern SaaS products are actually built and operated. Enough to have credible, specific conversations with engineers, and enough to configure Entra ID, MDM, and provisioning automation yourself rather than just specifying it. * Ambition and an AI-first mindset. You genuinely believe one person with great automation and AI tooling can own what used to take a team and you're excited to prove it. You build scripts, workflows, and agents instead of doing repetitive work by hand. * Identity & endpoint experience. You've run (or built) IAM and device management in practice: lifecycle automation, least-privilege and just-in-time access, MDM rollout and policy design. * Hands-on ISMS experience. You've operated (not just documented) an ISO 27001 and/or SOC 2 program before, ideally through at least one full audit cycle, ideally at a growth-stage SaaS or tech company. * Pragmatism over bureaucracy. You default to the simplest control that achieves the risk reduction, and you can explain the "why," not just enforce the "what." THE ENVIRONMENT We work from our office in Berlin, Greifswalder Strasse 212. Everyone works together in person because the hardest problems get solved faster at a whiteboard than in a Slack thread. Conversations happen faster, problems get solved quicker, and we actually know each other. Days start at 8:30. Lunch & dinner are together. We run, go to the gym, and take care of ourselves. Health is not separate from work here, it is part of how we work well. The vibe is calm but intense. No one is yelling or panicking. But everyone is working hard on things that matter. COMPENSATION Salaries are transparent and tied to levels, not negotiation. All roles include equity. We will figure out the right level together based on your experience and scope. Levels are about the work you own, not your title or years of experience. We narrow down the expected salary range early in the process. NEXT STEPS We move fast. Most processes complete within two weeks. If this sounds like your kind of work, we would like to meet you.
ABOUT US: SRLabs is home to knowledge leaders securing critical infrastructures in finance, energy, and telecommunications. We focus on hands-on hacking resilience – not compliance –, which we shape by combining our hacking research with impactful consulting work for innovation leaders that have a natural thrive for cutting-edge technologies. What makes us unique? We come from diverse backgrounds from all over the world, and that's just the way we like it. From coding, reverse engineering, penetration testing, exploit scripting, process design, research and consulting skills, our mix of colleagues possesses a vast set of qualifications, that equips us to influence design decisions of large-scale organisations. YOUR RESPONSIBILITIES Job brief: As a Red teamer at SRLabs, you work in a small and specialised team simulating infiltrations of corporate environments with high levels of protection for our clients. From obtaining initial access via external vulnerabilities or phishing, over lateral movement and to a domain takeover, you take part in the full chain of emulating adversarial cyber attacks. To remain undetected and complete your mission, you are able to avoid noise and bypass detection solutions and other protection measures. You analyze protection and monitoring gaps for their technical and operational root causes, and provide actionable steps for closing these gaps, bearing in mind the customer specific constraints our clients are facing. Your strategic advice supports the management in defining the security roadmap and employing security budget most effectively. Your Responsibilities: * Participate in red team engagements at SRLabs' clients * Perform external penetration testing and run phishing campaigns * Bypass protection measures and move undetected inside corporate networks * Develop tools, scripts and exploits for red team engagements * Create presentations to communicate risk and provide strategic advice on process optimizations * Support the client in addressing findings, in both, written and verbal communication * Develop methodologies to extrapolate from Red Team insights to generic security assurance checks * (Optional) Lead red team exercises and take responsibility for what comes with it (scoping, task management, escalations, ...) WHAT DO YOU BRING? What do you bring: * Strong foundational knowledge of information technology, including (Operating systems, Networking and Web technologies) * Hands-on experience in offensive security and red teaming * Solid experience with Active Directory and Entra ID security * Experience in client-facing roles or security consulting, including (presenting technical findings to diverse audience and provide strategic advice to clients) * Infrastructure and web penetration testing * Proficiency in programming languages such as: * Python, C/C++, Go, Java * Excellent communication skills in English (written and verbal) Nice to have Relevant expertise from areas like * Malware delivery and development * Incident response * Vulnerability research and exploit development * Reconnaissance, OSINT and social engineering * Operational security and bypassing of security measures (AV/EDR, endpoint and infrastructure hardening, SIEM generated alerts, Honeypots, ...) * Detection engineering and SOC operation * Experience in management consulting and communication WHAT AWAITS YOU WITH US? What awaits you with us: * Diverse team of highly motivated and competent security experts * Culture of constant learning and improvement * Flexible home office. * You can work from anywhere in Germany * Yearly company retreat * Urban Sports Club membership * Deutschlandticket (public transportation) * 30 days paid vacation APPLY NOW We are looking forward to receiving your application.
bunch is building the backbone of private markets. We are enabling next-gen fund operations with one integrated system that combines secure data infrastructure, AI-powered workflows and expert fund services. If you value ownership, growth through real responsibility, and working with a thoughtful, ambitious team, this role might be for you. We are seeking a Regulatory and Compliance Counsel (m/f/d) to join our growing legal team and lead all matters of risk, compliance and regulation for the bunch group. Reporting directly to our General Counsel, Jessica McBride, you will play a pivotal role in shaping our company's growth trajectory, ensuring we scale effectively and compliantly. YOUR ROLE * Own end-to-end our strategy, posture, policies and compliance with critical EU and UK frameworks, including GDPR, DORA and AML regulations * Co-own (together with Engineering) our IT security initiatives, including ISO 27001 and future certifications (e.g. SOC2), as well our company IT sec governance * Help shape and drive our company’s strategy on AI governance and ensure compliance with the EU AI Act * Be the point person for EU and UK regulatory developments affecting bunch’s business model * Support with regulatory analyses for market entry / go-to-market * Be responsible for regulatory (e.g. change-of-control) filings in connection with the execution of our M&A strategy * Manage all compliance and IT aspects of our vendors and providers and procurement process * Ensure that we stay compliant with ongoing financial and fiscal regulatory obligations, such as AIFMD, FATCA/CRS and German Bundesbank filings and local authority registrations * Shape our company’s risk and risk management strategy, together with leadership * Work directly with the General Counsel in a small and agile legal team ABOUT YOU * Completed studies in law (i.e., German Second State Exam, J.D., LL.B./LL.M. or equivalent qualification — but no German-law studies required) * At least 2-3 years of professional experience, with a broad focus on compliance, risk and regulatory matters, ideally gained in a regulated in-house environment * Experience with cross-border, multi-entity company groups and managing regulatory and compliance issues across borders * Affinity for IT security and the engineering aspects of security * Interest in taking on broader legal, operational and strategic workstreams within a start-up * Strong project management skills * Excellent written and spoken skills in English (C1+), along with solid German skills (B2+, but no native speakers required) * Be self-motivated, detail-oriented, organised, and comfortable with responsibility * Be excited about working in a fluid, innovative, fast-paced, and creative environment and about being a part of bunch's culture * If prior experience in or exposure to financial services or funds regulation, this is a plus, but not a prerequisite * Diverse backgrounds are strongly encouraged WORKPLACE & BENEFITS * Take part in a network of people passionate about investment and work closely with the most interesting players in private markets * Benefit from working with a diverse mix of talents, unrivalled energy, and team spirit within a culture of drive and ownership * Flexible hours and a hybrid office setup (3 days/week in office) * 4 remote calendar weeks/year * 28 days of vacation, 2 company days, plus local public holidays * A competitive compensation package * A great tech and work setup with everything you need Hiring process 1. People Team Interview (30 min) – Meet us & ensure mutual fit 2. Deep Dive Interview (45 min) – Collaboration, ownership, and culture 3. Case Study (90 min) – Technical skillset evaluation with the General Counsel 4. Final Stakeholder Interview (60 min) – Meet your important stakeholders About bunch bunch is building the operating infrastructure for the next generation of private markets. We combine AI-powered automation with deep regulatory expertise to replace fragmented spreadsheets and manual processes with one integrated platform across the fund lifecycle, purpose-built for private markets heading toward $32 trillion in Assets Under Management. We've 4x our ARR in 2025, crossed 150 fund managers and 12,000 LPs on the platform, and just closed our $35M Series B in May 2026. We're looking for ambitious people who want real ownership of hard problems, and who care about building infrastructure that actually matters to the people using it. ____ At bunch, we're committed to an inclusive environment where diversity is valued and celebrated. We provide equal opportunities to all qualified applicants. We process personal data in line with applicable laws (including GDPR). See our Privacy Policy for details on your rights and how to reach us.