Security & Privacy Lead

2 weeks ago


Belgrade, Central Serbia Constructor Knowledge Full time $125,000 - $175,000 per year

About Aracor
Aracor is on a mission to build a world-class product that will redefine dealmaking. Our AI-native platform helps in-house legal teams manage thousands of pages of documents with greater speed and precision, uncovering key insights and risks in seconds.

The Role

We are looking for a Security & Privacy Lead to take ownership of our company and product security practices from the ground up. We work with highly sensitive legal data and leverage advanced AI to automate what slows deals down and uncover hidden insights. Security, privacy, and compliance are at the core of our mission – we must meet rigorous standards so that even the most demanding customers trust our platform with their confidential information.

Responsibilities

  • Architect & Implement Security: Design, implement, and maintain a comprehensive security architecture for the Aracor platform. This includes network and cloud infrastructure security, container/orchestration security, and application-level controls for a multi-tenant environment.
  • Data Protection & Privacy: Develop and enforce data protection mechanisms to safeguard sensitive legal data.
  • Secure Software Development Lifecycle: Establish a secure SDLC within the engineering team. Define and roll out secure coding standards and best practices, perform design and code reviews with a focus on security, and integrate security testing tools into our CI/CD pipelines.
  • Threat Modeling & Risk Assessment: Proactively conduct threat modeling and security reviews for new features (including our AI components) to identify potential risks early. Work closely with engineers to design solutions that mitigate threats and meet compliance requirements without slowing down development.
  • Penetration Testing & Incident Response: Plan and oversee regular vulnerability assessments and penetration tests. Take ownership of remediation efforts for any findings, and establish incident response processes and monitoring tools.
  • LLM and Data Privacy Controls: Guide the implementation of privacy-preserving machine learning practices. For any AI models we use, ensure no sensitive data is inadvertently leaked or retained. Verify that document processing pipelines are secure and that all content processing adheres to privacy standards.
  • Compliance & Audit Readiness: Work towards making our platform and processes compliant with SOC 2 Type II, ISO 27001, GDPR, HIPAA and other relevant frameworks. Implement technical controls and documentation to pass security audits and help develop policies that align with these standards. You'll act as a key liaison during security assessments or customer due diligence, demonstrating our controls and addressing any concerns.
  • Cross-Team Collaboration: Collaborate closely with the product management and engineering teams to embed security into every phase of product development. Provide security guidance in architecture discussions and code implementations. Champion a security-first mindset through regular training, knowledge sharing, and by staying up to date on emerging threats and best practices that we can adopt.

Qualifications

  • Experience: 5+ years of experience in cybersecurity or application security engineering, with a track record of securing cloud-based products or platforms. You have designed and implemented security controls for complex systems and understand the challenges of protecting sensitive data in a production setting.
  • Technical Skills: Deep knowledge of security best practices across software, data, and infrastructure. Hands-on experience with cloud, network/web application security, and cryptography/encryption techniques.
  • Secure SDLC & AppSec: Proven ability to integrate security into the development lifecycle – from threat modeling and secure design to code review, static/dynamic analysis, and runtime testing. You are comfortable using security tools and frameworks to identify and fix vulnerabilities and can help engineers remediate issues in code.
  • Compliance Knowledge: Working understanding of compliance and data protection standards such as SOC 2, ISO 27001, GDPR, and HIPAA. You know what controls and evidence are needed to meet these standards. Direct experience leading or contributing to a successful certification or audit is a plus.
  • Privacy & Data Security: Strong awareness of data privacy principles and strategies for protecting PII. Experience implementing features like data anonymization, encryption/key management, audit logging, and monitoring access patterns for abuse. Bonus if you have experience securing AI systems or handling data for AI models in a privacy-sensitive way.
  • Startup Mindset: Ability to thrive in a fast-paced, ambiguous startup environment. You are proactive and self-directed, capable of creating a security roadmap and executing it with minimal guidance. You take ownership of outcomes and are willing to wear multiple hats to get the job done.
  • Communication & Leadership: Excellent communication skills with the ability to explain complex security topics in clear, concise terms to engineers and non-technical stakeholders alike. You can influence and drive change without formal authority.

What We Offer

  • Impact & Ownership: A lead role at the forefront of an AI-driven product poised to disrupt the legal industry. You'll have significant influence over technology and product direction, with your work directly shaping our success.
  • Growth Opportunities: Autonomy to make technical decisions and build a team from the ground up. As we scale, you can grow into a senior engineering leadership position with greater scope and responsibility.
  • Remote-First Culture: Work from anywhere. We value results over hours and trust our team to manage their work in the environment where they're most productive.
  • Mission-Driven Team: Join a tight-knit team of passionate experts (legal professionals, AI researchers, and seasoned entrepreneurs) driven by a bold vision. We're moving fast, learning every day, and excited to have you shape the journey with us.


  • Belgrade, Central Serbia Wargaming Full time €60,000 - €80,000 per year

    Job OverviewWe are looking for anApplication Security Engineerto join our security team and help us safeguard millions of players and the services they rely on. In this role, you will be responsible for identifying and mitigating security risks across web applications, infrastructure, and internal tools. You will work closely with developers, operations, and...


  • Belgrade, Central Serbia Wargaming Full time €60,000 - €80,000 per year

    Job OverviewWe are looking for an Application Security Engineer to join our security team and help us safeguard millions of players and the services they rely on. In this role, you will be responsible for identifying and mitigating security risks across web applications, infrastructure, and internal tools. You will work closely with developers, operations,...


  • Belgrade, Central Serbia SupportYourApp Full time $70,000 - $120,000 per year

    Passionate about the world of tech? What if you had a chance to be a part of the world's leading SaaS, Software, or Hardware solutions? Join our team as L2 Electrotechnical Support Engineer today and thrive in a multicultural and multilingual environment while enjoying your home office. Unlock your potential by mastering new skills and achieving...


  • Belgrade, Central Serbia Ardagh Group Full time €104,000 - €130,878 per year

    Ardagh Metal Packaging Serbia is looking forNational Accounting Managerto join our teamProfessional accounting recording, classifying, examining and analyzing financial transactions in accordance with defined regulations required. Preparation of financial data, records and payment of all obligations and taxes on time in accordance with local and group...


  • Belgrade, Central Serbia SupportYourApp Full time $70,000 - $120,000 per year

    Passionate about the world of tech? What if you had a chance to be a part of the world's leading SaaS, Software, or Hardware solutions? Join our team as a Lead Verification Support Agent for a luxury brand and thrive in a multicultural and multilingual environment while enjoying your home office. Unlock your potential by mastering new skills and achieving...

  • Cyber Security

    2 weeks ago


    Belgrade, Central Serbia Bosch Srbija Full time $90,000 - $120,000 per year

    Company DescriptionDo you want to shape beneficial technologies with your ideas? Whether in mobility solutions, consumer goods, industrial technology, or energy and building technology – with us, you will have the chance to improve quality of life all across the globe.As part of Bosch Power Tools, you will help set global standards with innovative products...


  • Belgrade, Central Serbia Rivian Full time $150,000 - $200,000 per year

    About RivianRivian is on a mission to keep the world adventurous forever. This goes for the emissions-free Electric Adventure Vehicles we build, and the curious, courageous souls we seek to attract.As a company, we constantly challenge what's possible, never simply accepting what has always been done. We reframe old problems, seek new solutions and operate...


  • Belgrade, Central Serbia UNIQA osiguranje Srbija Full time €45 - €55 per year

    As one of the leading insurance companies, we know that together we can achieve more. At UNIQA, we are therefore the community for a better life. We use our individual skills to shape the future together. The SEE region, namely Bosnia and Herzegovina, Bulgaria, Croatia, Montenegro, Romania and Serbia, is the 3rd largest group of companies in UNIQA Customer &...


  • Belgrade, Central Serbia G4S Full time €70,000 - €120,000 per year

    In 2021, G4S, a London-based global security company, was acquired by Allied Universal, a leading security and facility services company that provides proactive security services and cutting-edge smart technology to deliver tailored, integrated security solutions. This acquisition expands Allied Universal's footprint and infrastructure on a global and local...


  • Belgrade, Central Serbia Holycode Full time €60,000 - €80,000 per year

    We at Holycode are currently looking for an Information Security Officer to join our team, Carauktion. We are seeking someone who can dedicate themselves full-time for the first 6–12 months, and then transition into a part-time role to provide ongoing support and oversight. Carauktion was founded in 2004 because of the need of the automotive industry and...