Product Security Engineer

Jobtailor

Deutschland

Remote

EUR 90.000 - 130.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Erhalte eine Antwort von diesem Arbeitgeber — ein Lebenslauf und ein Anschreiben, die genau auf die Eigenschaften eingehen, die gesucht werden.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Jobtailor is seeking a security-focused engineer to lead reviews of architecture and code, and to model risks in AI-powered products. You will translate findings into practical mitigations and work with engineers to implement secure defaults and automated checks.

The role requires strong software engineering fundamentals and hands-on experience with Python, Go, or TypeScript, plus collaboration across technical and non-technical stakeholders. German market knowledge is a plus.

Qualifikationen

  • Strong software engineering fundamentals and ability to contribute fixes to production codebases.
  • Proficiency in at least one of Python, Go, or TypeScript.
  • Experience leading security reviews or threat models for complex systems.
  • Understanding of various security flaws and web/app security concepts.
  • Experience with multi-tenant SaaS or enterprise software is a plus.

Aufgaben

  • Lead security reviews of architecture, code, and changes.
  • Threat model new AI-powered capabilities and identify trust boundaries.
  • Translate findings into prioritized mitigations for engineers.
  • Investigate vulnerabilities and develop proofs of concept.
  • Collaborate with teams to implement secure defaults and automated checks.
  • Explain technical findings to engineers, product leaders, and executives.

Kenntnisse

Software engineering fundamentals
Python
Go
TypeScript
Security reviews leadership
Threat modeling
Clear communication
Open-source security contributions
Vulnerability assessment

Tools

Kubernetes
Cloud Platforms
APIs
OAuth/OIDC
Containers
SAST
DAST
CI/CD Systems

Jobbeschreibung

  • Lead security reviews of architecture, code, and security-sensitive changes
  • Evaluate risks in AI-powered products, including prompt injection, unsafe tool use, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes
  • Threat model new capabilities by identifying trust boundaries, abuse cases, and high-impact failure modes
  • Translate findings into practical, prioritized mitigations
  • Investigate suspected vulnerabilities and develop proofs of concept
  • Assess exploitability and impact and partner with engineers through remediation
  • Develop secure defaults, approved patterns, reusable controls, review requirements, and automated checks
  • Pair with engineers and document practical security guidance
  • Help product teams develop durable security expertise
  • Explain technical findings, business impact, and remediation options to engineers, product leaders, and executives
Requirements
  • Strong software engineering fundamentals and ability to independently understand, test, and contribute fixes to production codebases
  • Proficiency in at least one of Python, Go, or TypeScript
  • Experience leading security reviews or threat models for complex production systems
  • Understanding of injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain risks
  • Understanding of web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems
  • Ability to reason about untrusted input, authorization, isolation, identity, delegation, and data boundaries
  • Experience driving security improvements involving multiple engineering teams
  • Clear communication with technical and non-technical audiences
  • Experience with SAST, DAST, SCA, custom linters, or policy-as-code (nice to have)
  • Experience securing multi-tenant SaaS, enterprise software, or systems processing sensitive customer data (nice to have)
  • Offensive security experience through penetration testing, red teaming, or security research (nice to have)
  • Experience with vulnerability disclosure or bug bounty programs (nice to have)
  • Open-source security contributions, published research, conference talks, or credited vulnerability discoveries (nice to have)
Core Competencies

Demonstrates expertise in leading security reviews and threat modeling for complex production systems, with a strong foundation in software engineering and proficiency in Python, Go, or TypeScript. Capable of translating technical findings into actionable mitigations while effectively communicating with both technical and non-technical stakeholders.

Highest-signal resume keywords
  • Security Review Leadership
  • Threat Modeling
  • Python Proficiency
  • Web Application Security
  • Vulnerability Assessment
ATS Optimization Keywords
Hard Skills
  • Software Engineering Fundamentals
  • Threat Modeling
  • Injection Flaws Understanding
  • Authorization Flaws Understanding
  • Cryptographic Misuse Understanding
  • SAST
  • DAST
  • CI/CD Systems
  • Penetration Testing
  • Vulnerability Disclosure
Soft Skills
  • Clear Communication
  • Collaboration
Industry Keywords
  • Multi-Tenant SaaS
  • Enterprise Software
  • Security Research
  • Bug Bounty Programs
  • Open-Source Security Contributions
Tools & Technologies
  • Kubernetes
  • Cloud Platforms
  • APIs
  • OAuth/OIDC
  • Containers
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Security Engineer – Sec Ops
Senior Security Engineer – Sec Ops

Jobtailor • Deutschland

Remote
EUR 120.000 - 180.000
VP, Security Technology
VP, Security Technology

Jobtailor • Deutschland

Remote
EUR 150.000 - 230.000
Lead Security Engineer
Lead Security Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Security Automation Engineer
Security Automation Engineer

Jobtailor • Leverkusen

Vor Ort
EUR 80.000 - 130.000
Infrastructure and Cybersecurity Analyst
Infrastructure and Cybersecurity Analyst

Jobtailor • Deutschland

Remote
EUR 90.000 - 125.000
Security and Threat Operations Engineer
Security and Threat Operations Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 120.000
Senior Security Engineer – Cloud Security
Senior Security Engineer – Cloud Security

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 130.000
Principal Info Sec Technologist – Virtual
Principal Info Sec Technologist – Virtual

Jobtailor • Deutschland

Remote
EUR 130.000 - 170.000
Senior Information Security Specialist
Senior Information Security Specialist

Jobtailor • Deutschland

Remote
EUR 70.000 - 110.000
Senior Cyber Security, Microsoft Ecosystem Engineer
Senior Cyber Security, Microsoft Ecosystem Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 120.000