- Location
- Berlin, Berlin
- Type
- Full-time
- Department
- IT
- Seniority
- Lead
- Source
- Personio
Description
Your mission
nebenan.de connects real neighbours under their real names. That only works if people feel safe here. Your mission is to keep our users safe: with technical safeguards built into our platform and API, with product features that help neighbours protect themselves, and in close partnership with our Community Management team.
You look at everything security first. You ask how someone could attack the trust of our users, and you prevent it before it happens. At the same time you think in products, not only in backend systems: a well-placed warning in the interface, a clear reporting flow, or a safer default setting often protects more people than another rule on the server.
Concretely, you will:
Build safety into the platform
Design and implement technical safeguards in our API and backend: abuse detection, rate limiting, verification checks, and the signals that catch fake accounts and scams early.
Ship user-facing safety features. Reporting flows, warnings on suspicious messages, blocking and privacy controls, safer defaults. Safety that users can see and use.
Threat-model new features before they ship. Ask how a bad actor would abuse them, and design the friction and detection against it.
Think security first
Stay current on how attacks on social platforms evolve: account takeover, fake accounts, romance and marketplace scams, phishing and QR lures, spam rings, coordinated harassment.
Lead the response when something is spreading or someone is at risk: decide, act, then close the route it came through.
Decide what we build ourselves and what we buy. Where the market already solves a problem, such as content scanning, evaluate it, buy it and integrate it. Build where the problem is specific to nebenan.
Work as one with Community Management
Our moderation team handles cases day to day. You build the tooling and the standards they work with, so the highest-risk cases move first and similar cases get similar outcomes.
Turn what moderation learns into product and platform improvements, and turn platform signals into better moderation decisions.
Keep us compliant, with evidence
Own the platform-side obligations under the Digital Services Act and GDPR: notice and action, statements of reasons, complaint mechanisms, transparency reporting. Keep the evidence audit-ready as you go. Legal owns the interpretation; you make the platform meet it.
Measure safety honestly: how much harm actually reaches users, how fast we act, and how accurate our decisions are.
Your profile
Several years of experience building and operating production web platforms, ideally with a focus on trust & safety, anti-abuse, fraud prevention or application security
Solid Ruby on Rails experience in production, or clear evidence you pick up a new language and its ecosystem fast and well
Strong SQL and a real understanding of how databases behave; you can find an abuse pattern in the data yourself
A firm grasp of client–server architecture: what the client can and can't be trusted with, where the risk actually lives, and how an API fails under attack
Infrastructure fluency: AWS, logging, observability, queues. You can reason about a system under attack, not only under load.
A security-first mindset: you threat-model by instinct, probe how features can be abused, and stay current on attack vectors against social networks
A user- and product-centric view: you care how safety feels in the interface, and you are comfortable shipping or shaping frontend features (we use React and TypeScript) that help users stay safe
Works well with non-engineers: moderators, product, legal. You can explain a technical risk in plain language and take a moderation insight back into code.
Judgment under pressure: you keep users' safety and freedom in balance, and you decide quickly when someone may be at risk
Uses AI deliberately as leverage: directs and reviews generated code to production quality
Excellent English skills for working in our international team
A plus: German language and German-market moderation context
A plus: hands-on experience of a fraud, scam or impersonation wave at scale
A plus: experience selecting and integrating vendor tooling in a safety or security stack
A plus: a security background in threat modelling, incident response or offensive security
What we offer
Hybrid work model combining office and remote days
A meaningful job – we're creating a great product with real added value for the community
Work in a cheerful and experienced team that exchanges ideas and learns from each other
Insights into the entire work process of our social startup and the nebenan.de foundation
Responsibility and great opportunities to actively contribute
Your nebenan.de SpenditCard – you'll receive an additional income of 35 Euros per month, which you can use for things of your choice
30 days of vacation per year – we also offer the possibility of workation models and a sabbatical
A workplace in Berlin-Kreuzberg and regular events like yoga or Lunch & Learn sessions.
If we’ve captured your interest, apply now and let us know why you’re the perfect fit for the job!
Please submit your application in one PDF file, including curriculum vitae, relevant certificates and references to: [email protected]