Jobs Companies Langdock Security Lead - m/f/d

About this Security Lead - m/f/d role at Langdock

Langdock · Onsite · Berlin

Help Us Change the Way the World Works

Build something that matters.

Langdock exists to change the way the world works, bridging the gap between what technology can do and what people actually do with it. We bring all leading AI models into one secure, model-agnostic platform and make them usable across entire organizations. Over 10,000 companies use our platform every day, from fast-growing startups to some of Europe's largest enterprises. Their employees open Langdock to draft strategies, analyze documents, or automate workflows - helping them to work smarter, think more creatively, and reach their full potential.

About the Role

We're hiring a hands-on Security Lead to own security at Langdock across all surfaces. Not just the management system, but the actual security of our identities, devices, premises, and processes.

This is a broad ownership role, deliberately scoped for one ambitious person. We believe that with good automation and an AI-first way of working, one person can run what traditionally takes a small team: the certified ISMS, identity and access management, device management, security programs like bug bounty, and physical security. You'll use automation (and Langdock itself) aggressively to keep the operational load low and the bar high.

You'll design technical and organizational controls that enable us to run our business securely and that actually make sense for how we build and operate. You'll also make sure we can prove they work, quarter after quarter, audit after audit.

You'll work closely with engineering, operations, and sales by translating security and compliance requirements into controls people can realistically implement and maintain, and explaining our security posture to customers who consider Langdock.

What You Will Do

  • Own identity & access.

    • Own identity and access management across all our identity surfaces. Build and automate the processes for onboarding, offboarding, and privilege provisioning so the right people have the right access at the right time, and nothing more.

    • Properly configure and own our Entra ID. Conditional access, group and role design, lifecycle automation, and integration with the tools our teams actually use.

  • Own devices.

    • Own MDM and device management. Ensure every device that touches company data is enrolled, encrypted, patched, and recoverable with as little friction for the team as possible.

    • Own the device inventory. Keep an accurate, automated picture of what hardware exists, who has it, and what state it's in.

  • Own security programs.

    • Run our bug bounty and security programs. Set up and operate responsible disclosure / bug bounty, triage findings, and drive them to resolution with engineering.

    • Own physical security of our premises. Access control, visitor handling, and the physical controls our certifications and customers expect.

  • Own the ISMS.

    • Own the information security management system. Maintain and continuously improve our ISO 27001 and SOC 2 Type II certified management system, ensuring it reflects how Langdock actually operates, not just how a framework says it should.

    • Design controls, not paperwork. Define technical and organizational safety measures that are proportionate, practical, and genuinely reduce risk.

    • Manage the risk register. Identify, assess, prioritize, and track information security risks; drive risk treatment plans to closure with the relevant owners.

    • Maintain evidence in Vanta. Keep our control evidence current and audit-ready on an ongoing basis.

    • Run audits & new standards. Manage the end-to-end audit process for existing certifications (ISO 27001, SOC 2 Type II) and lead scoping and readiness for new standards as the business requires (e.g. C5, TISAX, HDS, FedRAMP-adjacent requirements, customer-specific frameworks).

  • Partner across the company.

    • Partner with engineering, operations, sales. Sit close to the teams that build and run the product; help them implement controls in ways that fit into existing workflows (CI/CD, infrastructure, access management) rather than bolting security on afterward.

    • Respond to customer and prospect security questions, including security questionnaires and due-diligence requests, as needed.

    • Automate relentlessly. Treat every recurring manual task (evidence collection, access reviews, provisioning, questionnaires) as something to be automated. Use AI tooling as a force multiplier so this role scales with the company without scaling headcount.

You Might Be a Fit If…

  • Technical background. You understand cloud infrastructure, identity providers, software development practices, and how modern SaaS products are actually built and operated. Enough to have credible, specific conversations with engineers, and enough to configure Entra ID, MDM, and provisioning automation yourself rather than just specifying it.

  • Ambition and an AI-first mindset. You genuinely believe one person with great automation and AI tooling can own what used to take a team and you're excited to prove it. You build scripts, workflows, and agents instead of doing repetitive work by hand.

  • Identity & endpoint experience. You've run (or built) IAM and device management in practice: lifecycle automation, least-privilege and just-in-time access, MDM rollout and policy design.

  • Hands-on ISMS experience. You've operated (not just documented) an ISO 27001 and/or SOC 2 program before, ideally through at least one full audit cycle, ideally at a growth-stage SaaS or tech company.

  • Pragmatism over bureaucracy. You default to the simplest control that achieves the risk reduction, and you can explain the "why," not just enforce the "what."

The Environment

We work from our office in Berlin, Greifswalder Strasse 212. Everyone works together in person because the hardest problems get solved faster at a whiteboard than in a Slack thread. Conversations happen faster, problems get solved quicker, and we actually know each other.

Days start at 8:30. Lunch & dinner are together. We run, go to the gym, and take care of ourselves. Health is not separate from work here, it is part of how we work well.

The vibe is calm but intense. No one is yelling or panicking. But everyone is working hard on things that matter.

Compensation

Salaries are transparent and tied to levels, not negotiation. All roles include equity.

We will figure out the right level together based on your experience and scope. Levels are about the work you own, not your title or years of experience. We narrow down the expected salary range early in the process.

Next steps

We move fast. Most processes complete within two weeks.

If this sounds like your kind of work, we would like to meet you.

Ready to apply to Langdock?
Apply to Langdock

Similar jobs

Sign up for suggestions tailored to the jobs you open and the searches you save.

More jobs at Langdock

See all jobs at Langdock →

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get an edge on your job hunt.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free