Application Security Engineer (DevSecOps)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Application Security Engineer (DevSecOps): Strengthening and scaling application security practices for an open-source data analytics and AI platform with an accent on supply chain security, vulnerability management, and DevSecOps integration. Focus on conducting penetration tests, implementing security by design in microservices architectures, and ensuring compliance with ISO 27001 and SoC2 standards.
Location: Berlin or Konstanz, Germany. Hybrid or remote options available depending on location. No relocation benefits provided.
Company
is a fast-growing international enterprise software company specializing in low-code data analytics and AI.
What you will do
- Raise software security awareness and lead internal trainings and workshops on topics like OWASP Top Ten.
- Partner with architects and engineering teams to embed security by design early in the SDLC.
- Manage third-party library vulnerabilities using SBOM technologies and coordinate timely remediation.
- Improve automated security tooling and processes in collaboration with DevSecOps and engineering leaders.
- Perform internal penetration tests and coordinate external security audits and issue tracking.
- Collaborate with IT and ISMS teams to maintain ISO 27001 and SoC2 certifications.
Requirements
- Degree in Computer Science or a related field.
- At least five years of experience as an Application Security Engineer.
- Strong technical knowledge of supply chain security, auth standards, and secure coding practices.
- Hands-on experience with DevSecOps and programming.
- Fluency in English (written and spoken).
Nice to have
- Proficiency in German.
Culture & Benefits
- Opportunity to shape the security posture of products used by Fortune 500 companies.
- High level of ownership and influence over security standards.
- Transparent, international work environment with a diverse team from 30+ nationalities.
- Continuous learning opportunities regarding cutting-edge security and AI topics.
- Subsidized gym memberships and sports courses in select locations.
- Flexible working hours to support a healthy work-life balance.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →