ppThe AI orchestration of your wildest imagination. /p pn8n is the open workflow orchestration platform built for the new era of AI. We give technical teams the freedom of code with the speed of no-code, so they can automate faster, smarter, and without limits. Backed by a fiercely inventive community and 500+ builder‑approved integrations, we’re changing the way people bring systems together and scale ideas for impact. /p pSince our founding in 2019, we’ve grown into a diverse team of over 160, working across Europe and the US, connected by a shared builder spirit and with our centre of gravity in Berlin. Along the way, we’ve cultivated a community of more than 650,000 active developers and builders; earned 145k+ GitHub stars, making us one of the world’s Top 40 most popular projects; been ranked as one of Europe’s most promising privately held SaaS startups (4th in Sifted’s 2025 B2B SaaS Rising 100); raised $240m to date, from Sequoia’s first German seed to our recent $180m Series C – bringing us to a $2.5bn valuation; and are grateful for our 94 eNPS score (most companies would call 70 excellent). /p pThat’s the company we’ve built. Now we’d love to see what you can build. If you’re applying, try n8n out – whether you’re technical or not – and share a screenshot of your first workflow with us. The easiest place to start is app.n8n.cloud/register. /p pWe’re in a defining moment of an incredible journey. Come and build with us. /p h3Senior Product Security Engineer – Role /h3 pWe are seeking a Senior Product Security Engineer to join our engineering organization as our first dedicated security hire. In this role, you will take primary ownership of n8n’s product security posture and work closely with the VP of Engineering to establish security as a core pillar of our engineering culture. /p pThis is a foundational role with significant autonomy and influence. You will define priorities, design processes, and implement pragmatic security practices that scale with a fast‑growing, open‑source‑driven SaaS platform. While you will initially operate as a senior individual contributor, this role has the potential to evolve as n8n grows. /p pYou will partner with a 50+ person engineering organization across multiple product areas, acting as both a hands‑on security expert and a trusted advisor who enables teams to ship securely without unnecessary friction. /p h3Key Responsibilities /h3 h3Vulnerability Management Disclosure /h3 ul liOwn and operate n8n’s vulnerability intake and triage process, including the inbox /li liDesign, improve, and run a robust Vulnerability Disclosure Program (VDP) with clear SLAs and escalation paths /li liCoordinate private fixes for high‑severity issues and manage coordinated disclosure timelines /li liCreate and manage GitHub Security Advisories (GHSA) /li liCoordinate bug bounty payouts and researcher communication for validated findings /li liDefine and operate patch and release processes for security fixes, including customer‑specific timelines where required /li /ul h3Security Tooling Assessment /h3 ul liEvaluate, implement, and maintain security tooling across the SDLC (SAST, DAST, dependency scanning, container scanning, SBOMs) /li liOwn configuration, tuning, and triage workflows for existing tools (currently Aikido) /li liPlan and manage third‑party penetration tests, including scoping, vendor coordination,
and remediation tracking /li liConduct internal security assessments and lightweight red‑team or tabletop exercises appropriate to company scale /li /ul h3Incident Response Security Communication /h3 ul liLead coordination of security incidents from detection through resolution /li liDrive incident tracking and remediation workflows in Linear /li liAuthor security advisories and contribute to internal and external post‑incident reviews /li liCommunicate clearly, calmly, and empathetically with customers and users during security incidents, in partnership with engineering and leadership /li /ul h3Security Program Development /h3 ul liDefine and maintain security policies, standards, and public‑facing disclosure documentation /li liManage relationships with security researchers and bug bounty platforms (e.g., HackerOne, Bugcrowd) /li liTrack industry trends, emerging vulnerabilities, and relevant research, proactively applying learnings to n8n’s environment /li liHelp shape longer‑term security strategy and roadmap in collaboration with engineering leadership /li /ul h3Secure SDLC Integration /h3 ul liEmbed security into the software development lifecycle through threat modeling, design reviews, and pragmatic guardrails /li liAdvise engineering teams on secure coding practices and common vulnerability patterns /li liProduce clear, actionable security documentation for internal engineering audiences /li liPartner closely with product and engineering teams across Nodes, AI Core, Cloud, and other areas to ensure security considerations are built in early /li /ul h3What Success Looks Like /h3 pbWithin The First 6–12 Months, You Will Have /b /p ul liEstablished a predictable, trusted vulnerability intake and triage process /li liReduced mean time to remediation for high and critical security issues /li liIntegrated security tooling into CI/CD with minimal friction for engineers /li liSuccessfully led at least one coordinated disclosure or security incident end‑to‑end /li liBuilt strong relationships with engineering teams as a pragmatic, enabling security partner /li /ul h3Requirements – Must-haves /h3 ul li5+ years of experience in product security, application security, or a closely related role (or equivalent demonstrated impact) /li liHands‑on experience with vulnerability management and disclosure workflows /li liStrong understanding of common web application vulnerabilities (e.g., OWASP Top 10) /li liExperience implementing and operating security tooling (SAST, DAST, dependency and container scanning) /li liFamiliarity with coordinated vulnerability disclosure and security advisories /li liProven ability to write clear security documentation and communicate with both technical and non‑technical audiences /li liExperience engaging with security researchers or bug bounty programs /li /ul h3Nice-to-haves /h3 ul liExperience securing SaaS platforms in cloud‑native environments /li liFamiliarity with JavaScript/TypeScript and the Node.js ecosystem /li liExperience working in high‑growth or open‑source‑adjacent companies /li liKnowledge of DevSecOps practices and CI/CD security integration /li liExperience with threat modeling methodologies /li liRelevant security certifications (e.g., OSCP, CISSP, CEH) /li /ul h3Working Style Philosophy /h3 ul liYou prioritize pragmatic risk reduction over rigid controls /li liYou see security as an enabler of product velocity, not a gatekeeper /li liYou are comfortable making trade‑offs and focusing on the highest‑impact risks /li liYou thrive in environments with ambiguity and ownership /li /ul pn8n is an equal‑opportunity employer and does not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, gender identity, age, marital status, veteran status, or disability status. /p pWe can sponsor visas to Germany; for any other country, you need to have existing right to work. /p pOur company language is English. /p pYou care about diversity and inclusion? We do too! Check out our Diversity, Inclusion and Belonging initiatives at /p pLocation disclaimer: If you see multiple job postings for the same role, it is most likely because we’re hiring remotely for this role and posting in different locations to make sure every potential candidate can see the role. Please apply to the location you’re the most likely to work from in the future. /p h3Benefits /h3 ul liCompetitive compensation – We offer fair and attractive pay. /li liOwnership – Our core value is to “empower others,” and we mean it—you’ll get a slice of n8n with equity. /li liWork/life balance – We work hard but ensure you have time to recharge: ul liEurope: 30 days of vacation, plus public holidays wherever you are. /li liUS: 15 vacation days, 8 sick days, plus public holidays wherever you are. /li /ul /li liHealth wellness – ul liEurope: We provide benefits according to local country norms.* /li liUS: Multiple low‑premium, low‑deductible medical plans with coverage for individuals and families—plus a no‑cost premium HDHP option with a pre‑seeded HSA—along with dental and vision coverage. /li /ul /li liFuture planning – ul liEurope: We provide pension contributions according to local country norms.* /li liUS: 401(k) retirement plan with a 4% employer match. /li /ul /li liFinancial security – ul liEurope: We provide benefits according to local country norms.* /li liUS: Company‑paid short‑term and long‑term disability insurance, plus life insurance to support you and your loved ones. /li /ul /li liCareer growth – We hire rising stars who grow with us! You’ll get €1K (or equivalent) per year to spend on courses, books, events, or coaching to level up your skills. /li liA passionate team – We love our product, and we prove it with regular hackathons where we see who can build the coolest thing with it! /li liRemote‑first – Our team works remotely across Europe, with regular off‑sites for team bonding. Some roles, like sales in the US, are hybrid—please check the job description. /li liGiving back – We’re big fans of open source, and you’ll get $100 per month to support projects you care about. /li liAI enablement – We believe in working smarter—everyone gets an unlimited AI budget to explore and use the best tools to boost productivity and creativity. /li liTransparency – We all know what everyone’s working on, how the company is doing—the whole shebang. /li liAn ambitious but kind culture – People love working here—our eNPS for 2024 is 94! /li liCountry‑specific details are provided in your contract. /li /ul /p #J-18808-Ljbffr
📌 Sr Product Security Engineer (Madrid)
🏢 n8n
📍 Madrid