Security Engineer (Flip Team)

eMAG · Headquarters Flip · Engineering

Posted 2026-09-25

Apply for this role →

Security Engineer (Flip Team)

Flip is Romania's largest platform for refurbished electronics, operating in Romania, Bulgaria, Hungary and Greece. We build and run our own e-commerce platform on Google Cloud, with Java services and React front-ends shipped continuously by our development teams.

We are now creating our first dedicated security role. You will report directly to the CTO and have a real mandate to shape how security is built into the way we develop, deploy and operate our platform. There is no existing security team to slot into: you will set the priorities, build the first controls and processes, and work side by side with our development and infrastructure engineers to make them stick.

This is a builder's role. We are not looking for someone who is already an expert in every corner of security. We are looking for someone with real depth in application security, hands-on security testing, or both; who is curious about the areas they know less well (cloud, detection and incident response, governance).

What you’ll have to do:

Application security and secure development (Java, React, APIs)

Embed security into our development workflow: threat modeling for new features, secure code review, and clear guidance for developers on the OWASP Top 10, authentication/authorization and API security.

Integrate and own security tooling in our CI/CD pipelines: SAST, DAST, dependency scanning and secret detection, tuned so that developers act on the results rather than ignore them.

Be the go-to security partner for our development teams, helping them design and ship secure features without slowing releases.

Security testing and vulnerability management

Run hands-on penetration tests and vulnerability assessments against our web applications, APIs and infrastructure, and coordinate external testing and vulnerability reports.

Own the vulnerability management process end to end: identify, document with clear impact and remediation guidance, prioritize by real risk, follow up with owners, and validate fixes.

Detection, monitoring and incident response

Improve security logging and monitoring across applications and cloud infrastructure, and define alerts for the events that matter (abuse of OTP/SMS flows, credential attacks, unusual access, misconfiguration changes).

Take part in incident response and post-incident reviews, and maintain our incident response procedure and playbooks.

Cloud and infrastructure security (Google Cloud, nice to have)

Review and harden our GCP environment: IAM and least-privilege access, VPC design and network segmentation, Cloud Armor / WAF rules, storage and service exposure.

Secure our container and compute workloads: GKE and Cloud Run configuration, image scanning, Linux hardening, secrets management and KMS usage.

Bring security into Infrastructure as Code and introduce continuous posture monitoring (CSPM-style) so misconfigurations are caught early rather than found in audits.

Security governance (secondary focus, support the CTO and Legal in already implemented activities)

Be the backup technical point of contact for our NIS2 (OUG 155/2024) obligations: help keeping the incident response procedure current, make sure logging and evidence are in place, and help us stay ready to notify when required.

Support security policies and standards, GDPR touchpoints together with Legal, and security requirements from partners and manufacturers.

What makes you a good fit:

Solid grounding in web application security fundamentals: OWASP Top 10, authentication and session handling, authorization, API security.

You can explain a vulnerability and its business impact clearly, in writing and in conversation, to engineers and to non-technical stakeholders.

You prioritize by impact, choose pragmatic solutions over perfect ones, and drive remediation with development and infrastructure teams collaboratively rather than by escalation.

You have concrete examples of security issues you found or controls you built, and can tell us what changed as a result.

Professional working proficiency in English.

3+ years of hands-on experience in security engineering, or in software/infrastructure engineering with a strong, demonstrable security focus.

Linux and networking basics, and scripting in Python, Bash or similar to automate checks and glue tools together.

We expect real depth in at least one of the two areas below and curiosity about the other. If you recognize yourself in most of one and a good part of the other, we want to hear from you:

Application security and DevSecOps: reading and reviewing code (ideally Java and/or JavaScript/TypeScript), threat modeling, and integrating SAST, DAST, dependency and secret scanning into CI/CD in a way developers actually act on.

Security testing: hands-on web, API and infrastructure penetration testing and vulnerability assessment, with clear write-ups and practical remediation guidance.

What makes you stand out:

Direct experience with Google Cloud security services (Cloud Armor, Security Command Center, Secret Manager, KMS, GKE security features).

Cloud and infrastructure security experience: securing a public cloud environment (GCP preferred; AWS or Azure experience transfers well) across IAM, networking and segmentation, secrets and logging, plus container and Kubernetes security fundamentals.

Infrastructure as Code (Terraform) and policy-as-code experience.

Exposure to SIEM, threat detection, EDR/XDR or digital forensics.

Experience with Zero Trust or identity-centric access designs.

Background in e-commerce, payments or fraud-adjacent problems (bot abuse, account takeover, SMS/OTP pumping).

You have been the first or only security person in a team before, and enjoyed it.

Relevant certifications (for example OSCP, GCP Professional Cloud Security Engineer, CKS, CISSP) are a plus, but hands-on experience and concrete results matter more to us.

What we’ve prepared for you:

Medical subscription: Regina Maria or Medicover, with dedicated healthcare packages for employees and preferential options for family members.

A flexible monthly benefits budget through Benefit Edenred, offering autonomy in selecting preferred benefits.

Access to Bookster library, providing a wide range of educational and development resources.

An accelerated learning environment through Prosus Academy, offering access to extensive learning materials and development opportunities.

A dedicated relaxation space, designed to support well-being and informal interaction.

A direct line to the CTO and the room to build Flip's security practice from the ground up.

Apply for this role →

← Back to all jobs