Product Security Engineer (m./f./div.)

SmartRecruiters, Inc.

Aveiro

Hybrid

EUR 42,000 - 64,000

Full time

4 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Flexible work conditions
Health insurance
On-site medical office
Training opportunities
Career progression
Global collaboration
Employee discounts

Job summary

Keenfinity is seeking a mid-level Product Security Engineer to join the VMS Team Ovr. You will guide security across the product lifecycle, performing threat modeling, vulnerability assessments, secure code reviews, and embedding security into development.

The role emphasizes DevSecOps, cloud security (AWS), PKI, and collaboration with engineering to integrate security into CI/CD and IaC. Flexible work and career opportunities offered.

Qualifications

  • 3–5 years in product, application, or offensive security.
  • Degree in Computer Science, Cybersecurity, or related field, or equivalent experience.
  • Hands-on vulnerability assessment experience.
  • Application security experience including secure code review and use of SAST/DAST/SCA tooling.
  • Experience with threat modeling methodologies (e.g., STRIDE).
  • Working knowledge of secure SDLC / DevSecOps and CI/CD security integration.
  • Cloud security knowledge, particularly AWS, IAM and cloud security best practices.
  • Solid understanding of PKI, digital certificates, and applied cryptography.
  • Scripting and automation ability (e.g., Python) to build and scale security tooling.
  • Familiarity with incident detection and response processes.
  • Strong communication skills for working across development and project teams.

Responsibilities

  • Provide security guidance on new products and technologies across the organization.
  • Act as the security lead on development projects, embedding security throughout the product.
  • Support development teams with DevSecOps practices, integrating security into CI/CD pipelines.
  • Foster a shift-left security culture.
  • Guide project teams through secure product lifecycle management and ongoing security support.
  • Collaborate on regular product security assessments and threat modeling exercises.
  • Perform application security assessments and secure code reviews across web, backend, and native codebases.
  • Operate application security tooling (SAST, DAST, SCA), configuring scans and triaging findings.
  • Triage, prioritize, and track identified vulnerabilities through remediation.
  • Design and implement tools and automation to scale security processes.
  • Assess and help secure cloud environments (AWS), reviewing configurations and IAM policies.

Skills

Vulnerability assessment
Threat modeling
DevSecOps
Cloud security
Python scripting
Security tooling

Education

Degree in Computer Science or Cybersecurity

Tools

SAST
DAST
SCA
AWS

Job description

The Keenfinity Group delivers professional communication and security solutions that connect and protect people and assets. Following its carve-out from the Bosch Group in mid-2025, it operates as independent company within the portfolio of European investment firm Triton. The Group’s four Businesses include Audio delivering professional communication products of the globally renowned brands Bosch, Electro-Voice, Dynacord, RTS and Telex, IQSIGHT Video Systems, Radionix Intrusion & Access, and KEENFINITY Electronics Manufacturing Services (EMS). In fiscal year 2025, the group generated revenues of over €1 billion and employed approximately 4,000 people across more than 40 countries.

IQSIGHT delivers visual intelligence for a world uninterrupted, bringing together advanced imaging technology, AI‑powered analytics, and robust cybersecurity to create intelligent and reliable video solutions. The brand transforms cameras into high‑performance visual sensors that enhance security, streamline operations, and support data‑driven decision‑making across industries.

Rooted in engineering excellence, IQSIGHT offers durable cameras, resilient video management software, and edge‑and cloud‑based analytics designed for demanding environments. Its technology enables precise object detection, classification, and scene understanding, supporting applications from smart cities and transportation to retail and critical infrastructure.

Built on trust, quality, and long‑term sustainability, IQSIGHT provides scalable, future‑ready video solutions backed by Bosch’s global expertise.

Job Description
Responsibilities Security guidance & product lifecycle
  • Provide security guidance on new products and technologies across the organization.
  • Act as the security lead on development projects, embedding security throughout the product
  • Support development teams with DevSecOps practices, integrating security into CI/CD pipelines
  • and fostering a shift-left security culture.
  • Guide project teams through secure product lifecycle management, and provide ongoing
  • security support to the product engineering team.
Threat modeling & security assessments
  • Collaborate with engineering teams to perform regular product security assessments.
  • Lead threat modeling exercises to identify and prioritize risks early in design.
Application security (AppSec)
  • Perform application security assessments and secure code reviews across web, backend, and
  • native codebases.
  • Operate application security tooling (SAST, DAST, SCA), configuring scans, and triaging and
  • Advise development teams on secure coding practices and remediation of application-layer
Vulnerability testing
  • Conduct regular vulnerability testing and scanning across current and legacy devices, products,
  • and supporting infrastructure.
  • Triage, prioritize, and track identified vulnerabilities through to remediation.
Security tooling & automation
  • Manage the operations and effectiveness of the product security pipeline tooling.
  • Tune and update tooling to reduce false positives and improve signal quality.
  • Design and implement tools and automation to scale security processes.
  • Assess and help secure cloud environments (AWS), reviewing configurations, IAM policies, and
  • infrastructure against security best practices.
  • Support secure deployment of cloud-hosted products and services, and help embed security into
  • infrastructure-as-code and cloud CI/CD workflows.
  • Respond to vulnerabilities surfaced through threat detection systems.
  • Support the incident detection and response processes.
PKI & cryptography
  • VMS Team Ovr – Product Security Engineer (mid-level) - Job Description
  • Operate and support internal and public PKI, certificate issuance, lifecycle management, and
  • related cryptographic services.
Documentation & standards
  • Maintain internal security documentation and standards to ensure security best practices are followed.
Qualifications
  • 3–5 years in product, application, or offensive security.
  • Degree in Computer Science, Cybersecurity, or a related field, or equivalent experience.
  • Hands‑on vulnerability assessment experience.
  • Application security experience, including secure code review and use of SAST/DAST/SCA
  • tooling.
  • Experience with threat modeling methodologies (e.g., STRIDE).
  • Working knowledge of secure SDLC / DevSecOps and CI/CD security integration.
  • Cloud security knowledge, particularly AWS, familiarity with core services, IAM, and cloud
  • security best practices.
  • Solid understanding of PKI, digital certificates, and applied cryptography.
  • Scripting and automation ability (e.g., Python) to build and scale security tooling.
  • Familiarity with incident detection and response processes.
  • Strong communication skills for working across development and project teams.
Nice to have
  • Penetration testing experience across devices, applications, and infrastructure.
  • Experience with embedded/IoT devices, video management systems, or network appliances.
  • Exposure to regulatory frameworks such as the EU Cyber Resilience Act (CRA).
  • Familiarity with AI security, testing and assessing AI-powered products and features, and using
  • of AI tools to enhance day‑to‑day security work.
  • Cloud security certifications (e.g., AWS Certified Security – Specialty).
Additional Information

Keenfinity benefits includes:

Flexible work conditions (2 days of HO)

Health insurance and medical office on site (nutrition, psychology, physiotherapy and general clinic)

Sports and health related activities (gym)

Training opportunities (i.e., technical training, foreign languages training) & certifications

Opportunities for career progression and continuous professional development

Exchange with colleagues around the world

Access to great discounts in partnerships and products

All our positions are open to people with disability

At Keenfinity we don’t just build innovative solutions — we shape a smarter, more connected world through technology.

We value different backgrounds, ideas, and experiences and we’re committed to growing, learning, and celebrating success as one team. Everyone is welcome here — we foster an environment where everyone is respected, valued, and encouraged to be their authentic self.

Keenfinity is an equal opportunity employer, offering equal opportunities for all. We welcome applications from people with disabilities and can offer support, if needed. When everyone has a chance to contribute, we all do better.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Chief Information Security Officer (CISO) (m/f/div.)
Chief Information Security Officer (CISO) (m/f/div.)

SmartRecruiters, Inc. • Ovar

On-site
EUR 120,000 - 180,000
Health insurance
Medical office on site
Gym access
+5
Chief Information Security Officer (CISO) (m/f/div.)
Chief Information Security Officer (CISO) (m/f/div.)

SmartRecruiters, Inc. • Aveiro

On-site
EUR 150,000 - 190,000
Health insurance
On-site medical support
Training opportunities
Project Management Leader (m/f/div)
Project Management Leader (m/f/div)

Iqsight • Aveiro

Hybrid
EUR 60,000 - 80,000
Health insurance
Training opportunities
Career progression
+1
Senior VS Industrialization Project Manager (m/f/div)
Senior VS Industrialization Project Manager (m/f/div)

SmartRecruiters, Inc. • Ovar

On-site
EUR 30,000 - 38,000
Health insurance
Sports and health activities
Training opportunities
+4
Chief Information Security Officer (Ciso) (M/F/Div.)
Chief Information Security Officer (Ciso) (M/F/Div.)

Bosch Group • Viseu

On-site
EUR 120,000 - 180,000
Flexible work conditions
Hybrid work system
Health insurance and on-site medical
+2
Hardware Test Engineering Internship (m./f,./div.)
Hardware Test Engineering Internship (m./f,./div.)

Keenfinity Group • Ovar

On-site
EUR 10,000 - 17,000
Flex schedule
Health insurance
Canteen
+4
Mechanical Development Internship (m./f./div.)
Mechanical Development Internship (m./f./div.)

SmartRecruiters, Inc. • Portugal

Remote
EUR 13,000 - 14,000
Flexible schedule
On-site medical office
Gym access
+5
Senior VS Industrialization Project Manager (m/f/div)
Senior VS Industrialization Project Manager (m/f/div)

Keenfinity Group • Ovar

On-site
EUR 30,000 - 38,000
Flexible work conditions
Health insurance and medical office on
Canteen
+7
Project Management Leader (m/f/div)
Project Management Leader (m/f/div)

Keenfinity Group • Ovar

Hybrid
EUR 90,000 - 120,000
Hybrid work system
Canteen
Health insurance and on-site medical
+4
Senior VS Industrialization Project Manager (m/f/div)
Senior VS Industrialization Project Manager (m/f/div)

SmartRecruiters, Inc. • Aveiro

On-site
EUR 30,000 - 38,000
Health insurance and on-site medical
Sports and health activities
Training opportunities & certificates
+4