Principal Engineer in Product Security at commercetools solving technical challenges for an ambitious product. Collaborating with teams to build secure services on multi-cloud infrastructure.
Responsibilities
Formulate, evangelise, and drive adoption of the product security strategy
Assess, advise on, and increase the security maturity posture
Create a standardised security architecture and operational best practices
Help track and drive remediation of security and technology risks
Educate product teams on risk assessments, threat modelling, and building secure api-first applications
Review requirements and designs to help product teams address shortcomings
Embed security tooling into the development process
Contribute to the review of external penetration tests and help teams prioritise fixes
Collaborate with product teams to improve overall security and resolve specific issues
Facilitate or lead customer conversations regarding product security
Triage and investigate new attack vectors to determine risk mitigation
Drive security and quality initiatives across the organization and support certification audits
Collaborate with Product Management, Principal Engineers, and legal/compliance teams
Identify skills gaps and facilitate knowledge sharing across the organization
Requirements
A strong technical background and 5+ years of proven track record in hands-on Product Security
2+ years of experience improving Product Security in a leadership role
Experience with customer-facing security roles and influencing roadmaps in matrix organizations
Experience in a scale-up environment with ambitious and competing priorities
Expertise in formulating, elaborating, and clarifying requirements or priorities
Experience with Secure Architecture design reviews and Threat Modeling
Experience infusing security into various levels of the SDLC
Experience with Static Analysis and Secure Code Review implementations
Sound knowledge of Linux systems, Kubernetes, Terraform, Vault, API, and web application security
Practical experience in DevSecOps and proficiency in at least one scripting language like JavaScript or Go
Project management experience for projects affecting multiple teams
Experience working within an Agile environment with a strong customer focus
Experience setting up and running trainings or onboardings
Clear written and verbal communication in fluent English.
Benefits
Comprehensive health benefits for you and your dependents, including access to OpenUp for personalized mental health support
Learning and development opportunities including an annual learning budget, access to self-paced learning platforms and language training, personalized coaching, mentorship, and leadership programs
Family Leave Plus gives you additional fully paid weeks of parental leave on top of government-provided leave, so you can spend more time with your new addition
Our equity participation program allows you to share in our success
Offensive Security Engineer tackling end - to - end penetration testing across applications and systems for Bunnings. Collaborating with teams to enhance organizational security posture.
Cyber Security graduate supporting KPMG's Cyber Security Consulting team in New Zealand. Gaining hands - on experience with real client engagements and enhancing cyber resilience.
Senior Security Risk Specialist at nbn safeguarding people and assets. Identifying and reporting security risk while supporting risk treatment across the organization.
VP, Security Engineering Programs & Controls leading modernization of Information Security Engineering control landscape. Ensuring control coverage and standardization across all Security Engineering functions.
Cloud Engineer supporting the U.S. Air Force Cloud One Architecture. Responsibilities include managing cloud security across platforms like AWS, Azure, and GCP.
Mid - level Information System Security Officer providing technical support to Navy Cyber Warfare Developmental Group. Ensuring security and integrity of information systems and network configurations.
Software Engineer developing Upwind Sensor for Windows OS in Cloud Security Platform. Collaborating with cross - functional teams to solve complex engineering issues and improve solutions.
Senior Manager Information Security driving governance and compliance for identity security platform. Leading risk management initiatives and supporting customer engagement in a hybrid work setup.
Information Security Consultant managing security standards implementation at LUZA Group in Lisbon, Portugal. Handling analysis of risk and supporting audits while working in a hybrid model.
Senior Cybersecurity Analyst at Boeing performing advanced cybersecurity assessments and risk evaluations for third - party vendors. Focusing on automation, lean processes, and collaborating with key stakeholders across departments.