Principal Engineer in Product Security at commercetools solving technical challenges for an ambitious product. Collaborating with teams to build secure services on multi-cloud infrastructure.
Responsibilities
Formulate, evangelise, and drive adoption of the product security strategy
Assess, advise on, and increase the security maturity posture
Create a standardised security architecture and operational best practices
Help track and drive remediation of security and technology risks
Educate product teams on risk assessments, threat modelling, and building secure api-first applications
Review requirements and designs to help product teams address shortcomings
Embed security tooling into the development process
Contribute to the review of external penetration tests and help teams prioritise fixes
Collaborate with product teams to improve overall security and resolve specific issues
Facilitate or lead customer conversations regarding product security
Triage and investigate new attack vectors to determine risk mitigation
Drive security and quality initiatives across the organization and support certification audits
Collaborate with Product Management, Principal Engineers, and legal/compliance teams
Identify skills gaps and facilitate knowledge sharing across the organization
Requirements
A strong technical background and 5+ years of proven track record in hands-on Product Security
2+ years of experience improving Product Security in a leadership role
Experience with customer-facing security roles and influencing roadmaps in matrix organizations
Experience in a scale-up environment with ambitious and competing priorities
Expertise in formulating, elaborating, and clarifying requirements or priorities
Experience with Secure Architecture design reviews and Threat Modeling
Experience infusing security into various levels of the SDLC
Experience with Static Analysis and Secure Code Review implementations
Sound knowledge of Linux systems, Kubernetes, Terraform, Vault, API, and web application security
Practical experience in DevSecOps and proficiency in at least one scripting language like JavaScript or Go
Project management experience for projects affecting multiple teams
Experience working within an Agile environment with a strong customer focus
Experience setting up and running trainings or onboardings
Clear written and verbal communication in fluent English.
Benefits
Comprehensive health benefits for you and your dependents, including access to OpenUp for personalized mental health support
Learning and development opportunities including an annual learning budget, access to self-paced learning platforms and language training, personalized coaching, mentorship, and leadership programs
Family Leave Plus gives you additional fully paid weeks of parental leave on top of government-provided leave, so you can spend more time with your new addition
Our equity participation program allows you to share in our success
Staff Software Engineer on Vulnerability Management team at Salesforce, driving security tooling strategy and automation for detecting and remediating vulnerabilities. Collaborate with cross - functional teams while providing mentorship and delivering high - quality engineering solutions.
Data Center Security Officer responsible for conducting patrols and controlling access. Ensuring security and safety in data center facilities while monitoring surveillance and reporting issues.
Senior Security Auditor managing audit program operations for global security audits at NTT DATA. Focusing on coordinating, executing audits, producing reports and tracking remediation.
Security Architect in Transactions domain ensuring cybersecurity for Payments and Financial markets. Collaborating with teams to enhance compliance and security practices.
Modern Infrastructure and Security Architect at MUFG responsible for directing cyber security initiatives. Collaborating with engineers to enhance security features and tools across the organization.
Senior Federal Technical Program Manager driving execution of federal cloud operations. Facilitating engagements between HPE's CSP and MSP teams while ensuring compliance and operational efficiency.
Cloud Cybersecurity Engineer supporting multi - cloud environments for critical missions in alignment with the U.S. Air Force. Roles include overseeing security authorizations and collaborating with government teams.
Program Security Manager overseeing security and compliance for mission applications in the US. Managing security programs and leading facility operations at Aurora and Philadelphia locations.
Information System Security Manager providing cybersecurity and RMF support for DoD systems and applications. Collaborating with military, government, and contractor personnel to ensure national security and systems compliance.
AI Security Engineer focusing on identifying and mitigating AI vulnerabilities. Involves research, development, and implementation of adversarial machine learning algorithms.