Senior Security Engineer
Deepintent · Banja Luka, Republic of Srpska, Bosnia and Herzegovina · 2026-07-01
About this role
<div class="content-intro"><p>DeepIntent is leading the healthcare advertising industry with data-driven solutions built for the future. From day one, our mission has been to improve patient outcomes through the artful use of advertising, data science, and real-world clinical data. For more information visit, <a href="https://www.DeepIntent.com">www.DeepIntent.com</a>.&nbsp;</p></div><p><strong>Location: Banja Luka, Bosnia and Herzegovina (primary) or Belgrade, Serbia</strong></p> <p><strong>What You’ll Do:</strong><strong><br></strong></p> <p>As a Senior Security Engineer, you will own the security architecture and enforcement across our infrastructure. Our infrastructure relies heavily on a Linux ecosystem, and as we scale our cloud footprint and AI initiatives, this layer is becoming increasingly security-sensitive. You will be embedded directly with the teams operating these systems, bridging the gap between high engineering velocity and secure-by-design architecture. Your core mandate is to protect production, harden our Linux environments, establish AI guardrails, and build secure access patterns without creating&nbsp; process overhead. This role will report to the Sr Director, Infrastructure and Networking and will be a hybrid role based out of Banja Luka, Bosnia.&nbsp;&nbsp;</p> <ul> <li>Linux Hardening &amp; Threat Detection: Secure our underlying Linux infrastructure and container runtimes. Deploy, tune, and manage our SIEM for continuous threat detection, file integrity monitoring, and host-based intrusion detection (HIDS) across our fleet.</li> <li>Identity &amp; Access Control: Design and enforce secure access patterns. Ruthlessly eliminate shared accounts, long-lived credentials, and overly broad permissions across the organization.</li> <li>Cloud &amp; Infrastructure Governance: Own the security posture across our cloud environments. Implement secure infrastructure-as-code practices using Terraform and Terraform workflow.</li> <li>AI &amp; Agentic System Security: Establish infrastructure-level guardrails for AI tooling and agentic systems, including tool permission boundaries, secrets exposure prevention, data egress controls, audit logging, approval workflows for sensitive actions, and controls against prompt-injection-driven misuse of internal systems.</li> <li>Secure CI/CD &amp; Supply Chain: Protect our production deployment paths against supply-chain attacks.</li> <li>Policy-as-Code &amp; Preventive Guardrails: Build and maintain automated security controls into Terraform, Terraform Workflow, Git repository, and CI/CD workflows.</li> <li>Vulnerability Management: Drive faster CVE response times and vulnerability closures across our infrastructure. Reduce the ad hoc security burden currently spread across the engineering team.</li> <li>Incident Response &amp; Compliance: Serve as the clear owner for external security reports, responsible disclosures, and audits, reducing the ad-hoc burden on the broader engineering team.</li> <li>Work closely with the Platform Engineering Services Team regarding Kubernetes, Container &amp; Runtime Security: Own security controls for containerized and cloud-native environments, including image hardening, runtime detection, network policies, workload identity, and secure container build standards.</li> <li>Work closely with all Engineering teams in eliminating security threats.</li> </ul> <p><strong>Who You Are:</strong></p> <ul> <li>Bachelor’s degree in Computer Science, Cyber Security, or a similar technical field, or equivalent practical experience, with 5+ years of proven experience in a cyber security-focused Security Engineer role</li> <li>Deep Linux Expertise: Extensive experience securing, hardening, and operating Linux-based infrastructure and containerized environments</li> <li>Cloud-Native Security: Experience securing Kubernetes or similar orchestration platforms, container images, runtime behavior, service mesh or network policies, and workload identity patterns.</li> <li>Identity-First Security: Strong understanding of SSO, MFA/passkeys, RBAC, just-in-time access, privileged access management, OIDC federation, and elimination of static credentials.</li> <li>Policy-as-Code: Ability to translate security requirements into automated controls.</li> <li>SIEM &amp; Endpoint Security: Hands-on experience configuring and maintaining SIEM for centralized logging, vulnerability detection, and active response.</li> <li>Cloud &amp; IaC Proficiency: Hands-on experience architecting security in mainstream cloud environments, and deep familiarity with Terraform, Ansible, and Git.</li> <li>AI Security Awareness: Practical understanding of LLM and agentic AI risks, including prompt injection, excessive agency, tool abuse, data leakage, insecure plugin/tool integrations, and secure approval boundaries.</li> <li>Security Ownership: Comfortable defining security metrics, driving remediation across teams, prioritizing risk pragmatically, and communicating trade-offs clearly to engineering leaders.</li> <li>Pragmatic Approach: You focus on automated guardrails, robust monitoring, and secure default paths rather than manual checklists and roadblocks.</li> </ul> <p><strong>Our benefits include:</strong></p> <ul> <li>Flexible working hours</li> <li>3-4 days of extra days off per year when we celebrate our successes globally</li> <li>Constant learning and development opportunities</li> <li>Yearly bonuses…
Skills asked for
- data science
- linux
- terraform
- ci/cd
- kubernetes
- ansible
- llm
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.