
Product Security Engineer
Posted Aug 26

Posted Aug 26
This is a fully remote position, open to applicants in Poland.
• Design, develop, and maintain secure CI/CD pipelines utilizing Jenkins, Kubernetes, Azure, and cloud-native technologies.
• Integrate security controls and automated security testing within the software delivery lifecycle.
• Implement and manage SAST, DAST, SCA, secrets detection, IaC scanning, container security, and software supply chain security measures.
• Drive initiatives for security automation to minimize manual effort and expedite secure software delivery.
• Document and assess current security mitigations while identifying additional necessary mitigations for products.
• Collaborate with product development teams to guide the creation of mitigation strategies.
• Contribute to security testing and verification protocols; assist in security verification and validation efforts.
• Work alongside product, development, and cloud engineering teams to incorporate security requirements throughout the SDLC.
• Conduct security assessments of applications, infrastructure, CI/CD workflows, and deployment architectures.
• Assist in threat modeling, risk assessments, and secure design reviews.
• Help establish security baselines, hardening standards, and secure deployment practices.
• Develop automation solutions using Python, PowerShell, Bash, or Groovy.
• Provide expertise within Agile methodologies.
• Participate in daily standups, sprint planning, retrospectives, and collaborative design sessions.
• Address incidents, triage issues, and maintain daily communication with the Product Development team.
• Evaluate new tools, technologies, and strategies to enhance security effectiveness and improve developer experiences.
• Collaborate with software engineers, cloud architects, DevOps teams, and security stakeholders to identify, prioritize, and remediate security risks at scale.
• Minimum of 4 years of hands-on experience with Jenkins or comparable CI/CD platforms.
• At least 3 years of experience in software development, automation, or scripting with Python, PowerShell, Bash, or similar languages.
• Experience integrating security tools into CI/CD pipelines, including SAST, DAST, SCA, container scanning, and secrets management.
• Proficient understanding of cloud security principles and services within Azure and/or AWS.
• Familiarity with containerized environments and Kubernetes security concepts.
• Proven experience collaborating with engineering teams in Agile development settings.
• Strong analytical, troubleshooting, and problem-solving capabilities.
• Self-driven with the ability to work independently and manage multiple priorities effectively.
• Bachelor’s degree in computer science, Information Technology, Cybersecurity, or equivalent practical experience.
• Preferred: Experience with Infrastructure as Code (Terraform, Bicep, CloudFormation).
• Preferred: Familiarity with Azure DevOps pipelines and security integrations.
• Preferred: Understanding of software supply chain security practices and frameworks (SBOM, SLSA, Sigstore, provenance validation).
• Preferred: Experience in securing Kubernetes and cloud-native platforms.
• Preferred: Familiarity with AI-assisted development tools and secure AI engineering practices.
• Preferred: Knowledge of NIST SSDF, OWASP SAMM, OWASP ASVS, and CIS Benchmarks.
• Highly desirable certifications include Microsoft Certified: Azure Security Engineer Associate; Microsoft Certified: DevOps Engineer Expert; Certified Kubernetes Security Specialist (CKS); Certified Kubernetes Administrator (CKA).
• Full-time employment.
• Remote work opportunities for candidates based in Poland.
Day Translations, Inc.
Business Wire
Universidad Internacional de La Rioja
Veeam Software
Get handpicked remote jobs straight to your inbox weekly.