Senior Infrastructure and Cloud Security Engineer
Copenhagen - Denmark
Job Summary
Veos security surface is unusual. We train models on-premise on dedicated GPU infrastructure run the product across AWS and GCP and operate a fleet of tens of thousands of cameras deployed at clubs and venues worldwide. That is a scope most SaaS security engineers never touch: physical devices in the field heavy on-prem compute and multi-cloud production all in one role.
We are forming a Security Enablement Team that makes it easier for every engineering and IT team at Veo to build ship and operate secure systems. You will own the infrastructure and cloud security slice where office networks data center networks and employee access to product systems meet partnering with the teams that own these systems so security is built in from the start. As an enablement function the team does not run these systems day to day. We build the paved roads tooling and patterns that let the owning teams operate securely by default.
You will join during a pivotal moment. We are standing the team up defining what good looks like across infrastructure network and workforce identity security and rolling out the first paved roads for a unified internal network across our datacenters (GCP AWS) and offices (Miami Berlin and Copenhagen) workforce identity and access and drift checks for cloud configuration and network rules. Youll have direct impact on how 100 engineers and every Veo employee work securely across our offices and clouds.
Youll join the Security Enablement Team and focus on the infrastructure and cloud security slice where office networks data center networks and employee access to product systems meet. Everything below follows the same pattern. We design the paved road prove it works and hand it to the team that will own it. We share ownership of the teams work pair on complex problems and rotate responsibilities. The systems themselves stay with the owning teams and our job is to make those teams successful.
- Lead the design reviews and tooling for our office and data center networks and the VPN that connects them as part of the network security direction the team sets together. Day-to-day operation and firewall changes stay with the team that owns the network
- Build patterns and tooling for secure cross-site connectivity and endpoint security posture that IT can adopt and run in a way that supports how Veo engineers actually work
- Build the patterns and automation for workforce identity and access including SSO hygiene MFA enforcement for employees and clean joiner mover and leaver flows for access to product systems with IT owning the day-to-day operation
- Build automated checks that surface drift in cloud configuration and network rules so the owning teams get a signal and can act on it
- Act on infrastructure and network findings from external penetration tests routed through the teams shared intake with the owning teams driving remediation
- Build the first version of cross-cutting capabilities such as the cross-site VPN or the drift checks then hand each one to a long-term owner with a written transition that covers the runbook ownership and escalation path
- Partner with GRC to build evidence pipelines for IT and access-related controls that produce auditable output without manual follow-up
- Run office hours where IT platform and product teams can get a network or access review
As the team matures youll help shape how Veos network and identity stack evolves across our offices and clouds as the company grows.
This role deliberately sits where IT cloud and security meet. You do not need to be world class at all three. You are strong in one or two and comfortable operating across the rest.
You likely have several years of experience at that intersection. That tends to show up in several of the following:
- Solid IT fundamentals: networking identity endpoint posture MFA and SSO at production scale
- Cloud infrastructure experience: hands-on work on at least one of GCP or AWS including IAM networking and basic Terraform-style IaC
- Workforce identity and access: hands-on experience with SSO and identity providers (Okta Google Workspace) and clean joiner mover and leaver flows
- A security mindset layered on that IT and cloud depth: you instinctively look for misconfigurations drift and bad access patterns without needing to be a dedicated security specialist
- Cross-context comfort: you can work on an office network problem and a product cloud problem in the same week without context-switching pain
- Platform-as-product mindset: youve built internal tooling that real teams adopt with guard rails built into the tools people already use and manual review as a last resort and you gathered feedback and measured impact
- Comfort handing work back to a long-term owner once the build phase is done
- Collaboration: you work through discussion and feedback share context effectively and write things down.
Youll join a Copenhagen-based Security Enablement Team of three engineers plus a manager. We operate as an enablement function: we build shared tooling and golden paths and we step in for focused high-leverage missions where no other team is positioned to deliver. We do not run a SOC and we do not carry a security pager.
Youll collaborate regularly with the Platform Product IT Firmware and GRC teams. We work pragmatically and iterate quickly. We document decisions favor simple solutions where possible and focus on tooling and platform patterns that help teams move faster with confidence.
If you read that list and matched on most of it but not all of it apply anyway. People who span IT cloud and security are rare and we do not expect every box ticked. We value diversity and inclusion and welcome applicants from all backgrounds.
Required Experience:
Senior IC
About Company
Record and live-stream your matches automatically and analyze your team's performance with AI-powered technology. Talk to our experts and get yours today.