Staff Security Engineer

Veeamsoftware · Prague, Czechia · Engineering

Posted 2026-07-30

Apply for this role →

About the Role

We’re looking for a Staff Security Engineer to define and drive the authentication and authorization architecture for Veeam Data Cloud (VDC), our cloud-native SaaS platform. This role is centered on evaluating, defining, and evolving our authorization model - including RBAC and API access control across VDC services and teams. You’ll partner closely with product and platform engineering to ensure access is consistently designed, implemented, and enforced across the product.  We provide secure data protection services on AWS, Azure, and GCP, integrating with platforms like Microsoft 365 and Salesforce for customers in regulated industries

What You’ll Do

Define end-to-end security architecture for identity and authorization across VDC (control plane and data plane)

Evaluate and define authorization standards for multi-tenant SaaS, including RBAC/ABAC patterns, API authorization, and consistent permission modeling across services

Define role/permission models for customer users, customer admins, internal support/admin access, and service-to-service authorization

Design and standardize identity and authorization for agents and connectors running in customer environments (token/scopes, least privilege, rotation)

Define shared security capabilities like tenant isolation, policy enforcement, and rate limiting

Set standards for secure logging and telemetry for authentication and authorization

Turn repeat security issues into reusable guardrails and shared services

Support compliance work (e.g., SOC 2, FedRAMP-style, IRAP) through lasting design improvements

Be hands-on in implementation: write code, perform code reviews, and submit PRs to VDC repositories; at times, embed with product teams to deliver authorization changes end-to-end

Join design reviews and help teams adopt standard security patterns

What You’ll Bring

Proven background as a Security Architect / Senior Security Engineer / Software Engineering for cloudnative, multitenant SaaS

Strong, hands-on expertise integrating and operating Okta, Auth0, and/or Keycloak from a software engineering perspective (SDKs/APIs, OIDC/OAuth flows, token handling, automation)

Strong software engineering background: proficiency in one or more of C#/.NET, Go, Java, Python, or TypeScript

Deep knowledge of authorization concepts and implementation: RBAC, permission modeling, policy enforcement, OAuth2/OIDC, JWT, mTLS, workload identities, tenant isolation, and secure API design

Strong Azure security architecture knowledge (Entra ID, AKS, networking, monitoring, hardening)

Experience turning vulnerability patterns for AAA into scalable platform solutions

Strong communication skills in English; comfortable in distributed teams

Bonus Skills

Building shared authn/authz libraries, policy engines, or security control plane services

Secure logging/telemetry design and data sanitization

Multicloud/hybrid identity experience

What You’ll Get

25 vacation days, 4 sick days, 21 paid medical leave days, plus 4 extra global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares

Premium private medical insurance for employees and dependents

Daily meal vouchers for restaurants and groceries (180 CZK per working day)

Flexible cafeteria platform with thousands of lifestyle benefit options

Multisport Card for gym and wellness, with family add-on options

Annual public transport reimbursement up to a set limit

Corporate mobile plan with optional family tariff

Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops and learning events like our annual Global Day of Learning

#LI-TK1

Apply for this role →

← Back to all jobs