01Why security is the next hire

Security engineering at Capmo

The record of what happened on site is worth defending.

Contracts, defects, change orders, correspondence — for thousands of projects across D-A-CH. Now we're putting agents on top of it. That combination is exactly the kind of target that rewards a serious defender.

  1. 01

    In-house research harnesses, running 24/7.

    Not an annual pentest report. We build our own harnesses that hammer the product continuously: LLM-driven fuzzing of APIs and permission boundaries, agentic red-team runs that chain findings the way a real attacker would, and regression suites so a bug class dies once and stays dead.

  2. 02

    A threat model written for agents, not just users.

    Brain lets agents read across a decade of project records. That makes prompt injection an authorisation problem, tool calls a privilege boundary, and retrieval a data-exfiltration path. Tenant isolation, provenance and least-privilege tool access are design constraints, not hardening tickets.

  3. 03

    Detection that keeps up with generated code.

    Every engineer ships with coding agents daily, so review moved upstream. Security has to move with it: guardrails in CI, secrets and supply-chain checks in the pipeline, evals that fail a model change the way tests fail a code change, and signal in production that tells us when something is genuinely off.

02The role

We're hiring in Security Engineering

You'd own the threat model for an AI system built on a decade of construction records, and build the harnesses that attack it before anyone else does. Munich or Berlin, hybrid. English is the working language; the domain is stubbornly German.

Ten percent of Europe's GDP, an AI layer being built on top of it, and nobody guarding it yet. Come take a look.

Open roles →← Back to engineering