PPRO logo
PPROPosted 1 month ago

Staff Security Engineer

HybridBerlin, State of Berlin, Germany

Full TimeSenior LevelMedium

Job Summary

Lead technical direction for the Security Engineering team, acting as the external interface to partner with Engineering and Product teams to embed security across the software development lifecycle. Design and build reusable Security as Code artifacts, own cloud security posture on AWS and GCP by conducting risk assessments and architecture reviews, and establish hardening standards. Maintain Infrastructure as Code codebases and CI/CD pipelines while developing automations for CSPM and CNAPP. Conduct threat modelling across applications and cloud systems, create SIEM detection rules, and drive penetration testing initiatives. Establish security standards and best practices, consult stakeholders, and explore AI solutions to solve emerging security challenges.

Required Qualifications

  • Act as technical lead for the Security Engineering team, setting technical direction and coaching and mentoring engineers
  • Serve as the external interface for the team, partnering with Engineering and Product teams to unblock them and embed security into all stages of the software development lifecycle
  • Design and build reusable Security as Code artifacts and patterns that reduce developer friction while improving security outcomes
  • Own the security of our cloud environment across AWS and GCP: conduct risk assessments and architecture reviews, design secure solutions, and write hardening standards and security guidelines
  • Maintain and expand our Infrastructure as Code codebases and CI/CD pipelines, and develop automations for cloud security posture management (CSPM) and our Cloud Native Application Protection Platform (CNAPP)
  • Conduct threat modelling across applications, services and cloud systems, and create detection rules for our SIEM
  • Provide expert application, product and cloud security guidance, and drive security assessments and penetration testing initiatives
  • Establish and share security standards and best practices across teams, consulting stakeholders and making data-driven decisions
  • Explore how AI can solve security problems, and drive proactive improvements from emerging security trends and technologies
  • Results-oriented, highly collaborative, pragmatic and proactive, and with a continuous improvement mindset
  • A natural technical leader: able to guide, coach and mentor engineers, lead cross-team collaborations, and act as a trusted interface between security and the wider engineering organization
  • Strong interpersonal and communication skills, able to unblock teams and foster security awareness throughout the company
  • Deep experience across both application/product security and cloud security, with a strong background in software development
  • Experience designing and building scalable security controls, architecture and services, taking strategic decisions and having a wide impact
  • Strong expertise in cloud (preferably AWS, and GCP) and container security (Kubernetes, Docker)
  • Deep understanding of DevSecOps and CI/CD security controls, with hands-on experience in Infrastructure as Code (preferably Terraform), CI/CD pipelines (preferably GitHub Actions) and scripting (Python, bash)
  • Fluency with AI coding tools and curiosity about applying AI to security problems
  • Developer mindset and empathetic approach to find innovative win-win solutions
  • Excellent communication and collaboration skills and fluent proficient in English

Desired Qualifications

  • Security qualifications a bonus

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce