Product Security Engineer (m/f/d)

Brak informacji o wynagrodzeniu
SeniorFull-time·B2B·Umowa o pracę
#424512·Dodano 2 dni temu·0
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

JenkinsCI/CD platformsSASTDASTKubernetesAzurePythonPowershell

Wymagania

  • 4+ years of hands-on experience with Jenkins or similar CI/CD platforms.
  • 3+ years of software development, automation, or scripting experience using Python, PowerShell, Bash, or equivalent languages.
  • Experience integrating security tooling into CI/CD pipelines, including SAST, DAST, SCA, container scanning, and secrets management.
  • Working knowledge of cloud security principles and services in Azure and/or AWS.
  • Understanding of containerized environments and Kubernetes security concepts.
  • Experience collaborating with engineering teams in Agile development environments.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to work independently and manage multiple priorities.
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or equivalent practical experience.

Preferred Qualifications:

  • Experience with Infrastructure as Code like Terraform, Bicep, or CloudFormation.
  • Experience with Azure DevOps pipelines and security integrations.
  • Familiarity with software supply chain security practices and frameworks (SBOM, SLSA, Sigstore, provenance validation).
  • Experience securing Kubernetes and cloud-native platforms.
  • Familiarity with AI-assisted development tools and secure AI engineering practices.
  • Knowledge of security frameworks such as NIST SSDF, OWASP SAMM, OWASP ASVS, and CIS Benchmarks.

Certifications:

  • Microsoft Certified: Azure Security Engineer Associate
  • Microsoft Certified: DevOps Engineer Expert
  • Certified Kubernetes Security Specialist (CKS)
  • Certified Kubernetes Administrator (CKA)

Obowiązki

DevSecOps Engineering:

  • Design, develop, and maintain secure CI/CD pipelines using Jenkins, Kubernetes, Azure, and cloud-native technologies.
  • Integrate security controls and automated security testing into the software delivery lifecycle.
  • Implement and manage SAST, DAST, SCA, secrets detection, IaC scanning, container security, and software supply chain security controls.
  • Drive security automation initiatives to accelerate secure software delivery.
  • Document and verify security mitigations for products.
  • Collaborate with product development teams to guide mitigation development.
  • Develop and implement security tests and verification protocols.

Product Security:

  • Collaborate with product, development, and cloud engineering teams to embed security requirements throughout the SDLC.
  • Conduct security reviews of applications, infrastructure, CI/CD workflows, and deployment architectures.
  • Support threat modeling, risk assessments, and secure design reviews.
  • Help establish security baselines, hardening standards, and secure deployment practices.

Engineering & Collaboration:

  • Develop automation solutions using Python, PowerShell, Bash, or Groovy.
  • Provide expertise in Agile methodologies.
  • Participate in daily standups, sprint planning, retrospectives, and design sessions.
  • Continuously evaluate new tools and technologies to improve security effectiveness and developer experience.

Inne informacje

Available to candidates located in Poland.

Please be informed that the data controller is Aras Corporation (hereinafter "controller"). You have the right to request access to your personal data, their rectification, erasure or restriction of processing, the right to object to processing, as well as the right to data portability and to lodge a complaint to the supervisory authority. Personal data will be processed for the purpose of the recruitment process. Provision of data to the extent resulting from the Act of 26 June 1974 Labour Code is mandatory. In the remaining scope, providing data is voluntary. Refusal to provide mandatory data may result in the impossibility to carry out the recruitment process. The Administrator processes mandatory data on the basis of a legal obligation incumbent upon him/her, while with regard to additional data, the basis for processing is consent. Personal data will be processed until the recruitment procedure is completed and for the period of the possibility of asserting potential claims, and in the case of consent to participate in future recruitment procedures - until the withdrawal of such consent. Consent to the processing of personal data can be withdrawn at any time. The recipient of the data is the Just Join IT service and other entities to whom we have entrusted the processing of data in connection with recruitment.

Aras Software

Aras Software

Pracodawca

Aplikuj teraz