
Principal Engineer, Product Security (m/f/x)
commercetools1 month ago
Munich, GermanyStaff+
Responsibilities
- Formulate, evangelize, and drive adoption of the product security strategy.
- Assess and improve the organization’s security maturity posture.
- Create standardized security architecture and operational best practices.
- Track and drive remediation of security and technology risks.
- Educate product teams on risk assessments, threat modeling, and secure API-first application development.
- Review requirements and designs and help teams address security shortcomings.
- Embed security tooling into the development process.
- Review external penetration-test results and help prioritize fixes.
- Collaborate with product teams to improve security and resolve specific issues.
- Facilitate or lead customer conversations regarding product security.
- Triage and investigate new attack vectors and determine risk mitigation.
- Drive security and quality initiatives and support certification audits.
- Identify skills gaps and facilitate organization-wide knowledge sharing and training.
Requirements
- At least 5 years of hands-on Product Security experience.
- At least 2 years of experience improving Product Security in a leadership role.
- Experience with customer-facing security roles, influencing roadmaps in matrix organizations, and working in a scale-up environment.
- Experience with secure architecture design reviews, threat modeling, Static Analysis, secure code review implementations, and infusing security into the SDLC.
- Knowledge of Linux systems, Kubernetes, Terraform, Vault, API security, and web application security.
- Practical DevSecOps experience and proficiency in at least one scripting language such as JavaScript or Go.
- Project management experience on projects affecting multiple teams.
- Experience working in an Agile environment with a strong customer focus and running trainings or onboardings.
- Fluent English with clear written and verbal communication.
- Preferred qualifications include CISSP, CCSP, Certified Kubernetes Security Specialist, or GCP, AWS, or Azure security certifications.
- Curiosity about using AI tools and willingness to learn new technologies and leadership practices.
Benefits
- Comprehensive health benefits for employees and dependents, including access to OpenUp mental health support.
- Annual learning budget, self-paced learning platforms, language training, personalized coaching, mentorship, and leadership programs.
- Additional fully paid parental leave through Family Leave Plus.
- Equity participation program.
- Hybrid work arrangement with three days per week in the Berlin, London, or Valencia office.