The AI Job Search Engine
Principal Engineer, Product Security(m/w/x)
Formulating security strategy and architecture for commerce industry products, driving risk remediation. 5+ years Product Security experience with 2+ years leadership required. Personalized mental health support, hybrid work model.
Requirements
- Technical background and 5+ years Product Security
- 2+ years Product Security leadership experience
- Customer-facing security and roadmap influence experience
- Experience in scale-up environments
- Expertise in formulating requirements and priorities
- Secure Architecture design and Threat Modeling
- Experience infusing security into the SDLC
- Static Analysis and Secure Code Review
- Knowledge of Linux, Kubernetes, and Terraform
- DevSecOps experience and scripting proficiency
- Project management experience for cross-team projects
- Experience in Agile environments
- Experience running trainings or onboardings
- Fluent written and verbal English communication
- Curiosity and aptitude for AI tools
- Security Certifications like CISSP or CCSP
- Eagerness to improve and learn
Tasks
- Formulate and drive the product security strategy
- Assess and improve the security maturity posture
- Create standardized security architecture and operational practices
- Track and drive remediation of technology risks
- Educate teams on risk assessments and threat modeling
- Build secure api-first applications with product teams
- Review designs to address security shortcomings
- Embed security tooling into the development process
- Prioritize fixes from external penetration tests
- Collaborate with product teams to resolve security issues
- Lead customer conversations regarding product security
- Triage and investigate new attack vectors
- Drive security initiatives and support certification audits
- Partner with Product Management and legal teams
- Identify skills gaps and facilitate knowledge sharing
Work Experience
- 5 years
Education
- Bachelor's degreeOR
- Master's degree
Languages
- English – Business Fluent
Tools & Technologies
- Linux
- Kubernetes
- Terraform
- Vault
- API
- JavaScript
- Go
- CISSP
- CCSP
- Certified Kubernetes Security Specialist
- GCP
- AWS
- Azure
Benefits
Flexible Working
- Hybrid work model
Healthcare & Fitness
- Comprehensive health benefits
Mental Health Support
- Personalized mental health support
Learning & Development
- Annual learning budget
- Self-paced learning platforms
- Language training
Mentorship & Coaching
- Personalized coaching
- Mentorship and leadership programs
Generous Parental Leave
- Additional paid parental leave
Competitive Pay
- Equity participation program
Not a perfect match?
- SAPFull-timeWith HomeofficeSeniorBonn, Walldorf, Berlin, Dresden, München
- NavVis
Senior Cloud Security Engineer(m/w/x)
Full-timeWith HomeofficeSeniorMünchen - EGYM
Application Security Engineer(m/w/x)
Full-timeWith HomeofficeExperiencedMünchen, Berlin - neoshare AG
Head of Offensive & Defensive Security(m/w/x)
Full-timeWith HomeofficeSeniorMünchen, Frankfurt am Main, Berlin - Celonis
Senior Cloud Infrastructure Engineer(m/w/x)
Full-timeWith HomeofficeSeniorMünchen
Principal Engineer, Product Security(m/w/x)
Formulating security strategy and architecture for commerce industry products, driving risk remediation. 5+ years Product Security experience with 2+ years leadership required. Personalized mental health support, hybrid work model.
Requirements
- Technical background and 5+ years Product Security
- 2+ years Product Security leadership experience
- Customer-facing security and roadmap influence experience
- Experience in scale-up environments
- Expertise in formulating requirements and priorities
- Secure Architecture design and Threat Modeling
- Experience infusing security into the SDLC
- Static Analysis and Secure Code Review
- Knowledge of Linux, Kubernetes, and Terraform
- DevSecOps experience and scripting proficiency
- Project management experience for cross-team projects
- Experience in Agile environments
- Experience running trainings or onboardings
- Fluent written and verbal English communication
- Curiosity and aptitude for AI tools
- Security Certifications like CISSP or CCSP
- Eagerness to improve and learn
Tasks
- Formulate and drive the product security strategy
- Assess and improve the security maturity posture
- Create standardized security architecture and operational practices
- Track and drive remediation of technology risks
- Educate teams on risk assessments and threat modeling
- Build secure api-first applications with product teams
- Review designs to address security shortcomings
- Embed security tooling into the development process
- Prioritize fixes from external penetration tests
- Collaborate with product teams to resolve security issues
- Lead customer conversations regarding product security
- Triage and investigate new attack vectors
- Drive security initiatives and support certification audits
- Partner with Product Management and legal teams
- Identify skills gaps and facilitate knowledge sharing
Work Experience
- 5 years
Education
- Bachelor's degreeOR
- Master's degree
Languages
- English – Business Fluent
Tools & Technologies
- Linux
- Kubernetes
- Terraform
- Vault
- API
- JavaScript
- Go
- CISSP
- CCSP
- Certified Kubernetes Security Specialist
- GCP
- AWS
- Azure
Benefits
Flexible Working
- Hybrid work model
Healthcare & Fitness
- Comprehensive health benefits
Mental Health Support
- Personalized mental health support
Learning & Development
- Annual learning budget
- Self-paced learning platforms
- Language training
Mentorship & Coaching
- Personalized coaching
- Mentorship and leadership programs
Generous Parental Leave
- Additional paid parental leave
Competitive Pay
- Equity participation program
About the Company
commercetools
Industry
IT
Description
The company is committed to creating meaningful change in the commerce industry and the communities it engages with.
Not a perfect match?
- SAP
Senior Product Security Engineer(m/w/x)
Full-timeWith HomeofficeSeniorBonn, Walldorf, Berlin, Dresden, München - NavVis
Senior Cloud Security Engineer(m/w/x)
Full-timeWith HomeofficeSeniorMünchen - EGYM
Application Security Engineer(m/w/x)
Full-timeWith HomeofficeExperiencedMünchen, Berlin - neoshare AG
Head of Offensive & Defensive Security(m/w/x)
Full-timeWith HomeofficeSeniorMünchen, Frankfurt am Main, Berlin - Celonis
Senior Cloud Infrastructure Engineer(m/w/x)
Full-timeWith HomeofficeSeniorMünchen