Senior Security Engineer
At Lunar, we are democratizing the power of money and changing the way we all bank, pay, and invest. Since starting in Aarhus in 2015, we've grown rapidly and are now a major player in the Nordics, with offices in Copenhagen, Aarhus, and Stockholm 🚀
Lunar is born in the cloud and we intend to stay there. We host our platform in AWS, orchestrate hundreds of microservices on Kubernetes, and move fast in a highly regulated industry. That combination means security isn't a side quest. It is essential to our mission. Lunar is revolutionizing banking with smart use of AI and modern cloud technology.
As a Senior Security Engineer you will be part of Squad Gravity, our dedicated security team based in Aarhus. You will own and drive security across a broad surface; including cloud and endpoint protection, enabling secure use of AI solutions, incident response, compliance, and detection engineering. You won't just advise from the sidelines. You will be hands-on, building the defences, responding to real threats, and shaping the security posture of a Nordic fintech going to the moon.
Squad Gravity is part of the team, not the typical "department of no" that you see in other organisations. Our mission statement is “Building Trust at Scale through Frictionless Security”. As such, your goal is to enable the business, not hinder innovation and fast pace with smart use of AI and modern cloud technology.
What will you do?
Squad Gravity is responsible for security operations, compliance, and resilience at Lunar. The scope is wide, and you will contribute across several areas:
Build Cloud & Infrastructure Security in AWS and Kubernetes.
Endpoint Security: Help manage and harden our endpoint protection stack (Microsoft Defender for Endpoint, InTune/Iru, formerly Kandji). Fine-tune alert policies, and collaborate with vendors.
AI & Automation: Help us understand and address the security implications and explore how AI can make our own security work smarter.
Security Findings Reviews: From assessments of critical vulnerabilities like React2Shell, to RBAC privilege escalation risks in the cloud. Work with tools like Wiz and Microsoft Defender to assess the situation and trigger incidents when necessary.
Detection & Response: Triage security alerts from Wiz, Microsoft Defender, and Falcon Logscale. Lead security incidents end-to-end from initial detection through forensics to post-incident follow-up. Build and maintain detection rules.
Compliance & Policy: Contribute to gap analysis of regulation or compliance frameworks such as DORA, GDPR, PSD2, ISO27001 and similar, SOP authoring, encryption standards, and regulatory questionnaires for payment networks.
Penetration Testing: Coordinate external penetration tests, communicate findings to stakeholders, and drive remediation of results.
Security Culture: Be a visible security partner across the organisation by advising squads, driving risk mitigation initiatives that span multiple teams, reviewing third-party vendor contracts, and helping colleagues understand the "why" behind security decisions.
What are we looking for in you?
You are someone who thrives in a role where no two weeks look the same. You are equally comfortable digging into a Kubernetes RBAC vulnerability as you are drafting an encryption policy or investigating a phishing campaign. You take ownership, communicate clearly, and know when to go deep versus when to move fast.
We know this is a broad role and we don't expect you to be an expert in everything from day one. What matters is that you are strong in some of these areas and genuinely curious to grow in the others:
Cloud Security: Hands-on experience with AWS and Kubernetes security. Ideally, you are not afraid to get your hands dirty and build cloud security solutions yourself using Terraform for AWS and GitOps for Kubernetes.
Endpoint Security: Experience with EDR solutions (e.g., Microsoft Defender), MDM such as Intune/Iru, formerly Kandji).
AI Readiness: You don't need to be an AI engineer, but you are curious about how AI changes the security landscape, both as a threat surface and a tool.
Identity & Access Management: Experience with SAML, OIDC and similar protocols and technologies in a corporate environment. Experience with RBAC, least privilege access models, and identity management in cloud environments and on endpoints.
Security Operations: Experience with security alert triage, incident response, and threat investigation in a cloud-native environment.
Detection Engineering: Building or maintaining detection rules and security monitoring in XDR solutions, CNAPP solutions, SIEM/log aggregation platforms or similar.
Compliance Awareness: Comfort working in a regulated industry. Experience with regulation and frameworks like DORA, GDPR, PSD2, ISO27001, or similar is valuable but not required.
SDLC & AppSec: a background in software engineering is not required, but it helps if you understand modern engineering principles like DevOps and SDLC. It is also a bonus if you are well-versed in Application Security.
Communication & Soft Skills: You can explain security concepts to both engineers and non-technical stakeholders. You have strong soft skills and know how to influence others effectively without being seen as the typical "security gatekeeper".
Curious about the Lunar culture? 💚
Everything at Lunar centers around our core - to challenge. It’s infused into our four values and guides us in how to work together, lead projects, and lead people to reach our mission. Our values aren't just words on a page - they're what make us who we are and shape the vibe of our culture. And trust me, we’re all about the vibe. For a longer read about our culture, click here.
Are you ready to join the journey? Apply now and let's find out more!
While you hold on tight for us to get back to you, curious to see what we’re up to? Follow us on LinkedIn for business announcements and releases 📢, check out our Instagram for an inside scoop on what it’s like to work here 📸, and visit our blog for the latest tech and product insights! 📱🫰
Depending on the regulations in the country where you will be employed, we will ask to see or obtain information about your criminal record.
- Department
- Technology
- Locations
- Aarhus, Denmark
Aarhus, Denmark
About Lunar
We’re a 100% digital bank that helps you manage your money smarter.
Lunar is designed for you. We’re 100% digital, always accessible and we provide everything you need for your daily economy. That means smarter ways to manage your money, more control, easier investment tools, and no hidden fees.
Welcome to the future of banking.
Lunar was founded in 2015, and since then, we have employed more than 400+ skilled people in: Tech, Design, Business Development, HR, Compliance, Banking, Marketing, Communication, Support, and much more.
The journey is only getting started, this is your cue to join it. Apply now!