aras
aras
New

Product Security Engineer (m/f/d)

Brak informacji o wynagrodzeniu
SeniorFull-time
#435417·Dodano 3 dni temu·1
Źródło: aras
⚠️Uwaga: ta oferta może już nie być aktualna. Sprawdź na stronie pracodawcy, czy rekrutacja jest nadal otwarta.
Aplikuj teraz

Tech Stack / Keywords

JenkinsKubernetesAzurePythonPowerShellBashGroovyAWSTerraformAzure DevOps

Firma i stanowisko

Aras is a leading provider of digital thread solutions for product lifecycle management (PLM) and engineering AI. The company serves large manufacturers in industries including automotive, industrial equipment, aerospace and defense, high tech, and life sciences with its AI-native, low-code platform called Aras Innovator.

Wymagania

  • 4+ years of hands-on experience with Jenkins or similar CI/CD platforms.
  • 3+ years of software development, automation, or scripting experience using Python, PowerShell, Bash, or equivalent languages.
  • Experience integrating security tooling into CI/CD pipelines including SAST, DAST, SCA, container scanning, and secrets management.
  • Working knowledge of cloud security principles and services in Azure and/or AWS.
  • Understanding of containerized environments and Kubernetes security concepts.
  • Experience collaborating with engineering teams in Agile development environments.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Self-motivated with ability to work independently and manage multiple priorities.
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or equivalent practical experience.

Preferred Qualifications:

  • Experience with Infrastructure as Code (Terraform, Bicep, CloudFormation).
  • Experience with Azure DevOps pipelines and security integrations.
  • Familiarity with software supply chain security practices and frameworks (SBOM, SLSA, Sigstore, provenance validation).
  • Experience securing Kubernetes and cloud-native platforms.
  • Familiarity with AI-assisted development tools and secure AI engineering practices.
  • Knowledge of security frameworks such as NIST SSDF, OWASP SAMM, OWASP ASVS, and CIS Benchmarks.

Certifications:

  • Microsoft Certified: Azure Security Engineer Associate
  • Microsoft Certified: DevOps Engineer Expert
  • Certified Kubernetes Security Specialist (CKS)
  • Certified Kubernetes Administrator (CKA)

Obowiązki

DevSecOps Engineering:

  • Design, develop, and maintain secure CI/CD pipelines using Jenkins, Kubernetes, Azure, and cloud-native technologies.
  • Integrate security controls and automated security testing into the software delivery lifecycle.
  • Implement and manage SAST, DAST, SCA, secrets detection, IaC scanning, container security, and software supply chain security controls.
  • Drive security automation initiatives to reduce manual effort and accelerate secure software delivery.
  • Document and verify existing security mitigations and identify additional needs.
  • Collaborate with product development teams to guide mitigation development.
  • Contribute to security tests and verification protocols; assist in security verification and validation efforts.

Product Security:

  • Collaborate with product, development, and cloud engineering teams to embed security requirements throughout the SDLC.
  • Conduct security reviews of applications, infrastructure, CI/CD workflows, and deployment architectures.
  • Support threat modeling, risk assessments, and secure design reviews.
  • Help establish security baselines, hardening standards, and secure deployment practices.

Engineering & Collaboration:

  • Develop automation solutions using Python, PowerShell, Bash, or Groovy.
  • Provide expertise in Agile practices.
  • Participate in daily standups, sprint planning, retrospectives, and collaborative design sessions.
  • Continuously evaluate new tools, technologies, and approaches to improve security effectiveness and developer experience.
aras

aras

9 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz