
Senior Infrastructure and Cloud Security Engineer
veo · Copenhagen, Denmark
About The Role
Veo is a global leader in AI-based sports camera technology. Our innovative, fully automatic camera solution enables sports teams to record matches and training sessions without a camera operator. We’re democratizing the world of sports by granting video analysis for teams on all levels—a privilege that used to be only for the few. More than 40,000 clubs in 90+ countries record their games every week.
But what truly sets us apart? Our people. We’re a diverse group of innovative thinkers, creators, and problem-solvers who believe in delivering an incredible product—and having fun while doing it.
The Opportunity
Veo processes thousands of hours of sports video daily, powering AI analysis for teams from grassroots to professional levels. The infrastructure you build will directly enable coaches and athletes worldwide to analyze, train, and compete better.
We're building KickOff, our next-generation GitOps platform. You'll join during a pivotal moment: we're actively migrating services to KickOff, establishing new platform patterns and enabling 100+ engineers to ship faster and more reliably. We also maintain separate on-premises Kubernetes clusters running model training and video processing workloads.
This isn't a "keep the lights on" role. You'll shape platform architecture, drive technical decisions, and directly impact engineering velocity across both cloud and on-prem environments.
What You Will Do
You'll join the Security Enablement Team and focus on the infrastructure and cloud security slice, where office networks, data center networks, and employee access to product systems meet. Everything below follows the same pattern. We design the paved road, prove it works, and hand it to the team that will own it. We share ownership of the team's work, pair on complex problems, and rotate responsibilities. The systems themselves stay with the owning teams, and our job is to make those teams successful.
- Lead the design, reviews, and tooling for our office and data center networks and the VPN that connects them, as part of the network security direction the team sets together. Day-to-day operation and firewall changes stay with the team that owns the network
- Build patterns and tooling for secure cross-site connectivity and endpoint security posture that IT can adopt and run, in a way that supports how Veo engineers actually work
- Build the patterns and automation for workforce identity and access, including SSO hygiene, MFA enforcement for employees, and clean joiner, mover, and leaver flows for access to product systems, with IT owning the day-to-day operation
- Build automated checks that surface drift in cloud configuration and network rules, so the owning teams get a signal and can act on it
- Act on infrastructure and network findings from external penetration tests, routed through the team's shared intake, with the owning teams driving remediation
- Build the first version of cross-cutting capabilities, such as the cross-site VPN or the drift checks, then hand each one to a long-term owner with a written transition that covers the runbook, ownership, and escalation path
- Partner with GRC to build evidence pipelines for IT and access-related controls that produce auditable output without manual follow-up
- Run office hours where IT, platform, and product teams can get a network or access review
As the team matures, you'll help shape how Veo's network and identity stack evolves across our offices and clouds as the company grows.
What You Could Bring
This role deliberately sits where IT, cloud, and security meet. You do not need to be world class at all three. You are strong in one or two and comfortable operating across the rest.
You likely have several years of experience at that intersection. That tends to show up in several of the following
- Solid IT fundamentals: networking, identity, endpoint posture, MFA, and SSO at production scale
- Cloud infrastructure experience: hands-on work on at least one of GCP or AWS, including IAM, networking, and basic Terraform-style IaC
- Workforce identity and access: hands-on experience with SSO and identity providers (Okta, Google Workspace) and clean joiner, mover, and leaver flows
- A security mindset layered on that IT and cloud depth: you instinctively look for misconfigurations, drift, and bad access patterns, without needing to be a dedicated security specialist
- Cross-context comfort: you can work on an office network problem and a product cloud problem in the same week without context-switching pain
- Platform-as-product mindset: you've built internal tooling that real teams adopt, with guard rails built into the tools people already use and manual review as a last resort, and you gathered feedback and measured impact
- Comfort handing work back to a long-term owner once the build phase is done
- Collaboration: you work through discussion and feedback, share context effectively, and write things down.
Nice to have: VPN solutions at scale (Tailscale, Cloudflare Access, WireGuard), endpoint management tooling, and audit log pipelines.
How We Work
You'll join a Copenhagen-based Security Enablement Team of three engineers plus a manager. We operate as an enablement function: we build shared tooling and golden paths, and we step in for focused, high-leverage missions where no other team is positioned to deliver. We do not run a SOC and we do not carry a security pager.
You'll collaborate regularly with the Platform, Product, IT, Firmware, and GRC teams. We work pragmatically and iterate quickly. We document decisions, favor simple solutions where possible, and focus on tooling and platform patterns that help teams move faster with confidence.
If you read that list and matched on most of it but not all of it, apply anyway. People who span IT, cloud, and security are rare, and we do not expect every box ticked. We value diversity and inclusion and welcome applicants from all backgrounds.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
