Pipeline
Browse Jobs
Sign inSign up
Pipeline
Browse jobsSign inContactTermsPrivacyCookiesPreferences
Logos provided by Logo.dev

© 2026 Pipeline. All rights reserved.

  1. Home
  2. Jobs
  3. VDC - Engineering 1009422
  4. Staff Security Engineer
Veeam Software logo

Veeam Software

Staff Security Engineer at Veeam Software

Prague, CzechiaFull-timeVDC - Engineering 1009422Posted 26 days ago
Apply with Pipeline→

About the Role

<div class="content-intro"><div class="elementToProof"> <p>Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.</p> </div></div><p><strong>About the Role</strong></p> <p><span class="TextRun SCXW263978009 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW263978009 BCX8">We’re</span><span class="NormalTextRun SCXW263978009 BCX8">&nbsp;looking for a Staff Security Engineer to define and drive the&nbsp;</span><span class="NormalTextRun SCXW263978009 BCX8">authentica</span><span class="NormalTextRun SCXW263978009 BCX8">tion an</span><span class="NormalTextRun SCXW263978009 BCX8">d au</span><span class="NormalTextRun SCXW263978009 BCX8">thoriz</span><span class="NormalTextRun SCXW263978009 BCX8">ation</span><span class="NormalTextRun SCXW263978009 BCX8">&nbsp;architec</span><span class="NormalTextRun SCXW263978009 BCX8">ture</span><span class="NormalTextRun SCXW263978009 BCX8">&nbsp;for <a href="https://www.veeam.com/products/veeam-data-cloud.html">Veeam Data Cloud (VDC)</a>, our cloud-native SaaS platform. This role is centered on evaluating, defining, and evolving our&nbsp;</span></span><span class="TextRun SCXW263978009 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW263978009 BCX8">authorization model - </span></span><span class="TextRun SCXW263978009 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW263978009 BCX8">including&nbsp;</span></span><span class="TextRun SCXW263978009 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW263978009 BCX8">RBAC</span></span><span class="TextRun SCXW263978009 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW263978009 BCX8">&nbsp;and&nbsp;</span></span><span class="TextRun SCXW263978009 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW263978009 BCX8">API access control&nbsp;</span></span><span class="TextRun SCXW263978009 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW263978009 BCX8">across VDC services and teams.&nbsp;</span><span class="NormalTextRun SCXW263978009 BCX8">You’ll</span><span class="NormalTextRun SCXW263978009 BCX8">&nbsp;partner closely with product and platform engineering to ensure access is consistently designed, implemented, and enforced across the product.</span></span><span class="LineBreakBlob BlobObject DragDrop SCXW263978009 BCX8"><span class="SCXW263978009 BCX8">&nbsp;</span><br class="SCXW263978009 BCX8"></span><span class="LineBreakBlob BlobObject DragDrop SCXW263978009 BCX8"><span class="SCXW263978009 BCX8">&nbsp;</span><br class="SCXW263978009 BCX8"></span><span class="TextRun SCXW263978009 BCX8" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW263978009 BCX8">We provide secure data protection services on AWS, Azure, and GCP, integrating with platforms like Microsoft 365 and Salesforce for customers in regulated industries</span></span></p> <p><strong>What You’ll Do</strong></p> <ul> <li><span data-contrast="auto">Define end-to-end security architecture for&nbsp;</span><span data-contrast="auto">identity and authorization</span><span data-contrast="auto">&nbsp;across VDC (control plane and data plane)</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="auto">Evaluate and define&nbsp;</span><span data-contrast="auto">authorization standards</span><span data-contrast="auto">&nbsp;for multi-tenant SaaS, including&nbsp;</span><span data-contrast="auto">RBAC/ABAC patterns</span><span data-contrast="auto">,&nbsp;</span><span data-contrast="auto">API authorization</span><span data-contrast="auto">, and consistent permission modeling across services</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="auto">Define role/permission models for customer users, customer admins, internal support/admin access, and service-to-service authorization</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="auto">Design and standardize identity and authorization for&nbsp;</span><span data-contrast="auto">agents and connectors</span><span data-contrast="auto">&nbsp;running in customer environments (token/scopes, least privilege, rotation)</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="auto">Define shared security capabilities like </span><span data-contrast="auto">tenant isolation, policy enforcement, and rate limiting</span><span data-ccp-props="{}">&nbsp;</span></li> <li><span data-contrast="auto">Set standards for </span><span data-contrast="auto">secure logging and telemetry</span><span data-contrast="auto"> for authentication and authorization</span><span data-ccp-props="{}">&nbsp;</span></li> <li><span data-contrast="auto">Turn repeat security issues into </span><span data-contrast="auto">reusable guardrails and shared services</span><span data-ccp-props="{}">&nbsp;</span></li> <li><span data-contrast="auto">Support compliance work (e.g., </span><span data-contrast="auto">SOC 2, FedRAMP-style, IRAP</span><span data-contrast="auto">) through lasting design improvements</span><span data-ccp-props="{&quot;335559739&quot;:0}">&nbsp;</span></li> <li><span data-contrast="auto">Be hands-on in implementation: write code, perform code reviews, and&nbsp;submit&nbsp;PRs to VDC repositories; at times, embed with product teams to deliver authorization changes end-to-end</span><span data-ccp-props="{&quot;335559739&quot;:0}">&nbsp;</span></li> <li><span data-contrast="auto">Join design reviews and help teams adopt standard security patterns</span><span data-ccp-props="{}">&nbsp;</span></li> </ul> <p><strong>What You’ll Bring</strong></p> <ul> <li><span data-contrast="auto">Proven background as a </span><span data-contrast="auto">Security Architect / Senior Security Engineer&nbsp;/ Software Engineering</span><span data-contrast="auto"> for </span><span data-contrast="auto">cloudnative, multitenant SaaS</span><span data-ccp-props="{}">&nbsp;</span></li> <li><span data-contrast="auto">Strong, hands-on&nbsp;expertise&nbsp;integrating and operating&nbsp;</span><span data-contrast="auto">Okta</span><span data-contrast="auto">,&nbsp;</span><span data-contrast="auto">Auth0</span><span data-contrast="auto">, and/or&nbsp;</span><span data-contrast="auto">Keycloak</span><span data-contrast="auto">&nbsp;from a software engineering perspective (SDKs/APIs, OIDC/OAuth flows, token handling, automation)</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}">&nbsp;</span></li> <li>Strong software engineering background: proficiency in one or more of C#/.NET, Go, Java, Python, or TypeScript</li> <li><span data-contrast="auto">Deep knowledge of&nbsp;</span><span data-contrast="auto">authorization</span><span data-contrast="auto">&nbsp;concepts and implementation:&nbsp;</span><span data-contrast="auto">RBAC</span><span data-contrast="auto">, permission modeling, policy enforcement,&nbsp;</span><span data-contrast="auto">OAuth2/OIDC</span><span data-contrast="auto">, JWT,&nbsp;mTLS, workload identities, tenant isolation, and secure API design</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="auto">Strong </span><span data-contrast="auto">Azure&nbsp;security architecture</span><span data-contrast="auto"> knowledge (Entra ID, AKS, networking, monitoring, hardening)</span><span data-ccp-props="{}">&nbsp;</span></li> <li><span data-contrast="auto">Experience turning vulnerability patterns&nbsp;for&nbsp;AAA&nbsp;into </span><span data-contrast="auto">scalable platform solutions</span><span data-ccp-props="{}">&nbsp;</span></li> <li><span data-contrast="auto">Strong communication&nbsp;skills in English; comfortable in distributed teams</span><span data-ccp-props="{}">&nbsp;</span></li> </ul> <p><strong>Bonus Skills</strong></p> <ul> <li><span data-contrast="auto">Building shared&nbsp;authn/authz&nbsp;libraries, policy engines, or security control plane services</span><span data-ccp-props="{}">&nbsp;</span></li> <li><span data-contrast="auto">Secure logging/telemetry design and data sanitization</span><span data-ccp-props="{}">&nbsp;</span></li> <li><span data-contrast="auto">Multicloud/hybrid identity experience</span><span data-ccp-props="{}">&nbsp;</span></li> </ul> <p><strong>What You’ll Get&nbsp;</strong></p> <ul> <li>25 vacation days, 4 sick days, 21 paid medical leave days, plus 4 extra global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="edf32eb5-9fd0-4c7c-8978-e79d37007503">Premium private medical insurance for employees and dependents</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="9f5cda51-08d8-4760-971e-d9f747f57f7d">Daily meal vouchers for restaurants and groceries (180 CZK per working day)</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="378750df-d64d-4338-975e-c9b4064240d2">Flexible cafeteria platform with thousands of lifestyle benefit options</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="fab46f32-3a73-4a50-8eab-142b44eb8a92">Multisport Card for gym and wellness, with family add-on options</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="e8ec9bf3-2992-4ad0-8128-28f123163245">Annual public transport reimbursement up to a set limit</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="0e65f6ac-21e2-4496-a397-aae4bda50c32">Corporate mobile plan with optional family tariff</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="6e123908-7b82-4cf6-847f-5cfcbf2d13b2">Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops and learning events like our annual Global Day of Learning</li> </ul> <p><span style="font-family: helvetica, arial, sans-serif;">#LI-TK1</span></p><div class="content-conclusion"><div data-pm-slice="1 1 [&quot;ul&quot;,null,&quot;li&quot;,{&quot;style&quot;:null,&quot;checked&quot;:null,&quot;value&quot;:null,&quot;displayValue&quot;:null,&quot;backgroundColor&quot;:null,&quot;color&quot;:null,&quot;listStyleType&quot;:null}]" data-en-clipboard="true"><hr></div> <div data-pm-slice="1 1 [&quot;ul&quot;,null,&quot;li&quot;,{&quot;style&quot;:null,&quot;checked&quot;:null,&quot;value&quot;:null,&quot;displayValue&quot;:null,&quot;backgroundColor&quot;:null,&quot;color&quot;:null,&quot;listStyleType&quot;:null}]" data-en-clipboard="true"><span lang="EN-US" style="font-family: helvetica, arial, sans-serif;"><strong>Veeam Software is an equal opportunity employer</strong> and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.</span></div> <div data-pm-slice="1 1 [&quot;ul&quot;,null,&quot;li&quot;,{&quot;style&quot;:null,&quot;checked&quot;:null,&quot;value&quot;:null,&quot;displayValue&quot;:null,&quot;backgroundColor&quot;:null,&quot;color&quot;:null,&quot;listStyleType&quot;:null}]" data-en-clipboard="true"> <p><span style="font-family: helvetica, arial, sans-serif;">Please note that any personal data collected from you during the recruitment process will be processed in accordance with our&nbsp;<a href="https://www.veeam.com/recruiting-privacy-notice.html">Recruiting Privacy Notice</a>. &nbsp;</span></p> <p><span style="font-family: helvetica, arial, sans-serif;">The Privacy Notice sets out the basis on which the personal data collected from you, or that you provide to us, will be processed by us in connection with our recruitment processes.&nbsp;</span></p> <p><span style="font-family: helvetica, arial, sans-serif;">By applying for this position, you consent to the processing of your personal data in accordance with our&nbsp;<a href="https://www.veeam.com/recruiting-privacy-notice.html">Recruiting Privacy Notice</a>.</span><br><br><span style="font-family: helvetica, arial, sans-serif;"><strong>By submitting your application, you acknowledge that the information provided in your job application and any supporting documents is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification of information may result in disqualification from consideration for employment or, if discovered after employment begins, termination of employment.</strong></span></p> </div> <p><a id="app"></a></p></div>

Related Roles

  • Senior Production Engineer

    Veeam Software

    Pune, India
  • Platform Engineer III

    Veeam Software

    Bangalore, India
  • Platform Engineer III

    Veeam Software

    Pune, India
  • Senior Production Engineer

    Veeam Software

    Remote, United StatesRemote
  • Security Tech Lead

    Veeam Software

    Warsaw, Poland
  • Security Tech Lead

    Veeam Software

    Prague, Czechia