Staff Security Engineer

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Copenhagen, Capital, DNK
Remote
Senior level
Sports
The Role
Lead platform security, identity, and network enablement: design paved-road tooling for image scanning, SBOMs, CVE response, CI/CD workload identity (OIDC), unified multi-cloud VPN/networking, audit logging, and GRC evidence pipelines; run penetration-test contracting and hand off capabilities with runbooks, owners, and escalations while mentoring engineers.
Summary Generated by Built In
Veo is a global leader in AI-based sports camera technology. Our innovative, fully automatic camera solution enables sports teams to record matches and training sessions without a camera operator. We’re democratizing the world of sports by granting video analysis for teams on all levels—a privilege that used to be only for the few. More than 40,000 clubs in 90+ countries record their games every week.

But what truly sets us apart? Our people. We’re a diverse group of innovative thinkers, creators, and problem-solvers who believe in delivering an incredible product—and having fun while doing it.

The Opportunity

Veo's security surface is unusual. We train models on-premise on dedicated GPU infrastructure, run the product across AWS and GCP, and operate a fleet of tens of thousands of cameras deployed at clubs and venues worldwide. That is a scope most SaaS security engineers never touch: physical devices in the field, heavy on-prem compute, and multi-cloud production, all in one role.

We are forming a Security Enablement Team that makes it easier for every engineering and IT team at Veo to build, ship, and operate secure systems. As the most senior engineer on the team, you will own the technical direction of the platform security, identity, and network security slice, partnering with the teams that own these systems so security is built in from the start. As an enablement function, the team does not run these systems day to day. We build the paved roads, tooling, and patterns that let the owning teams operate securely by default.

You will join during a pivotal moment. We are standing the team up, defining what good looks like across platform security, identity, and network security, and rolling out the first paved roads for image scanning, SBOM generation, CVE response, CI/CD identity, and a unified internal network across our datacenters (GCP, AWS) and offices (Miami, Berlin, and Copenhagen). You'll have direct impact on how 100+ engineers write, review and ship secure systems.

What You Will Do

    You will join a focused platform security team and operate as its most senior engineer. Everything below follows the same pattern. We design the paved road, prove it works, and hand it to the team that will own it. We share ownership, pair on complex work, and rotate responsibilities, and we expect this role to set the bar.

  • Design and build the paved roads for image scanning, SBOM generation, and CVE response, running inside the pipelines teams already use, with findings routed to the owners who can fix them under tracked SLAs
  • Lead the design, reviews, and tooling for a unified internal network and VPN across GCP, AWS, and our Miami, Berlin, and Copenhagen offices, while the team that owns the network keeps running it
  • Work with the auth service maintainers on identity and access, including MFA rollouts, removal of shared accounts, and cleanup of long-lived tokens, so the patterns stay theirs to own
  • Make workload identity the paved road for CI/CD, using OIDC between GitHub Actions and AWS or GCP, packaged so teams can migrate themselves
  • Build audit logging as a shared capability that teams plug into rather than reinvent
  • Turn GRC controls into technical implementations, with evidence pipelines that produce auditable output without manual follow-up
  • Own the contracting cycle for external penetration tests and build the intake, classification, and tracking system that routes findings to named owners, while the owning teams remediate
  • Hand each capability off cleanly, with a runbook, a named owner, and an escalation path, and run office hours where product and platform teams can get a security review or a paved-road question answered
  • Mentor the rest of the team and raise the security bar across Builders
  • As the team matures, you will help shape our multi-environment network architecture, our identity and access patterns, and the long-term security posture of the product.

     

What You Could Bring

    This is a deliberately merged platform security and identity role. You do not need to be world class at both. You likely have several years of production infrastructure and security experience behind you, and you are deep and credible in one of these areas and ready to grow into the other.

    That depth tends to show up in several of the following:

  • Platform security: you have run vulnerability scanning, CVE management, and image scanning at scale, and you know the operational reality of getting CVEs fixed, beyond standing up the tooling
  • Identity and auth: you have worked hands-on inside an auth codebase, rolled out MFA on live systems, and managed token lifecycles in CI/CD with OIDC and workload identity
  • Network security at scale: you have designed and run a unified internal network across multiple cloud providers and offices, with a VPN approach that holds up
  • Platform-as-product mindset: you have built internal security tooling that other teams chose to adopt, with guard rails built into the tools developers already use and manual review as a last resort, and you gathered feedback and measured the impact
  • Infrastructure as Code: strong experience with Terraform, Crossplane, or similar
  • Nice to have: GitOps tools such as Flux or ArgoCD, Cilium, Kubernetes security at scale, and experience building security into a GRC evidence pipeline.

How We Work

    You'll join a Copenhagen-based Security Enablement Team of three engineers plus a manager. We operate as an enablement function: we build shared tooling and golden paths, and we step in for focused, high-leverage missions where no other team is positioned to deliver. We do not run a SOC and we do not carry a security pager.

    You'll collaborate regularly with the Platform, Product, IT, Firmware, and GRC teams. We work pragmatically and iterate quickly. This role sets the technical direction for the team's quarterly missions. We document decisions, favor simple solutions where possible, and focus on tooling and platform patterns that help teams move faster with confidence.

    If you read that list and matched on three or four items but not all of them, apply anyway. The "deep in one, ready to grow into the other" framing above is not a hedge, it is how we actually hire at this level. We value diversity and inclusion and welcome applicants from all backgrounds.

Our Copenhagen office mirrors our innovative technology – with an indoor ball court, rooftop terrace, and well-equipped gym. We have created a facility that supports connecting disciplines across the business, facilitates creative thinking, and gives the space to engage with colleagues, our global partners, and the entire Veo community.

Values we hold at Veo:

Dare - We take initiative, stay curious, and challenge the status quo in our work.
Own it - We drive impact by identifying opportunities, taking responsibility, and confidently executing.
Level up - We embrace growth, continuously learning and shaping our skills.
Play as a team - We collaborate across a diverse organization, leveraging shared insights for stronger outcomes.
Customer Centric - We deliver value by having close partnerships and a deep understanding of our customers (internally and externally)

We value diversity and inclusion and welcome applicants from all backgrounds, even if your experience doesn’t completely match every qualification listed. What matters most is your creativity, potential, and ability to contribute meaningfully.

Skills Required

  • Several years of production infrastructure and security experience
  • Experience running vulnerability scanning, image scanning, SBOM generation, and CVE management at scale
  • Hands-on identity and auth experience: MFA rollouts, removal of shared accounts, token lifecycle management
  • Workload identity and CI/CD identity experience (OIDC between GitHub Actions and AWS/GCP)
  • Designing and running unified internal network and VPN across multiple clouds and offices
  • Platform-as-product mindset: built internal security tooling and paved roads adopted by teams
  • Infrastructure-as-Code experience (Terraform, Crossplane, or similar)
  • Experience building audit logging as a shared capability and turning GRC controls into technical implementations
  • Manage external penetration testing contracting, intake, classification, and tracking systems
  • Experience with GitOps tools such as Flux or ArgoCD
  • Experience with Cilium
  • Kubernetes security at scale
  • Experience building security into a GRC evidence pipeline
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Santa Monica, CA
154 Employees
Year Founded: 2015

What We Do

Record your sport - without a camera operator. Veo lets you record your sports match without a camera operator. Automatic recording and video-editing enables coaches and players to watch and share their sport. Veo is founded in 2015 in Copenhagen. Our vision is to democratise the video broadcasting and analytics that today only are available for the professional teams. Veo is offered for clubs, players, coaches, scouts, families and fans to give access to quality video. The videos give automised panoramic, ball detector and player detector views. The platform contains analytical and sharing features enabling all users to access and utilise the content.

Similar Jobs

Zeta Global Logo Zeta Global

Platform Engineer

AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Easy Apply
Remote or Hybrid
Copenhagen, Capital, DNK
2429 Employees

Deepgram Logo Deepgram

Account Executive

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
28 Locations
150 Employees

Deepgram Logo Deepgram

Account Executive

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
Remote
27 Locations
150 Employees

Datadog Logo Datadog

Principal Partner Manager - Channels (Nordics)

Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
2 Locations
6500 Employees

Similar Companies Hiring

GameChanger Thumbnail
Computer Vision • Digital Media • Kids + Family • Mobile • Software • Sports
New York City, NY
260 Employees
SRAM, LLC Thumbnail
Fitness • Hardware • Mobile • Software • Sports • Transportation • Esports
Chicago, IL
3800 Employees
DraftKings Thumbnail
Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Boston, MA
6400 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account