Backend Engineer, Security
About your team
You will join a growing security team where you can take meaningful ownership of the practices and policies you help develop. You will work closely with backend engineering and other departments to integrate practical security requirements across the company.
About the role
As a Security Engineer, you'll cover a broad range of operational and strategic security work rather than a single narrow specialty. In your first few months, you'll focus on learning Eneba's tech stack and understanding how our services and systems fit together. That foundation is essential before you can secure those systems effectively.
Day-to-day, you can expect to:
-
Hands-on coding and security implementation work make up the largest part of the role today, alongside incident response and threat-hunting responsibilities.
-
Review and triage security submissions and incident reports.
-
Evaluate and respond to bug bounty reports, including remediation follow-through
-
Build, operate, and improve incident response and remediation processes.
-
Write and maintain security policies and documentation.
-
Communicate security requirements and risks clearly to non-technical departments
-
Review application monitoring and logs to catch and investigate anomalies
-
Support access governance and permission-management processes.
About the tech
The tech stack is the same one our backend teams work with. You're not expected to know all of it on day one, but you should expect to be learning how to use most of it within your first 3 months, and you'll also be working across other languages and systems used throughout the company as your role demands.
Code
-
PHP/Symfony
-
Golang
-
GraphQL
-
gRPC
-
CQRS, commands via saga/temporal, queries via GraphQL
-
Microservices architecture
-
Service orchestration with Saga / temporal.io
Databases
-
InfluxDB
-
Redis
-
ElasticSearch
-
MariaDB
-
MySQL
Infrastructure
-
Kubernetes
-
Helm
-
AWS
-
Terraform
-
Prometheus
What we're looking for
-
Strong written and verbal communication skills - this is our highest priority, since you'll regularly need to explain technical risk to non-technical audiences
-
Solid PHP knowledge
-
Security knowledge, or a clearly demonstrated interest in security (bug bounties, CTFs, security blogs, following the security community)
-
A background in IT, backend engineering, or a related technical field
-
Self-sufficiency - comfort taking ownership of tasks and making progress without constant guidance.
-
Ownership mentality and strong problem-solving skills
-
Openness to learning and working across multiple systems, languages, and technologies rather than staying in one lane
Nice to have
-
Experience with monitoring tools and application monitoring
-
Familiarity with the OWASP Top 10
