
Product Security Engineer (m/f/d)
Aras Corporation14 days ago
Remote, PolandMid Level
Responsibilities
- Design, develop, and maintain secure CI/CD pipelines using Jenkins, Kubernetes, Azure, and cloud-native technologies.
- Integrate security controls and automated security testing, including SAST, DAST, SCA, secrets detection, IaC scanning, container security, and software supply chain security.
- Drive security automation initiatives and develop automation solutions using Python, PowerShell, Bash, or Groovy.
- Document and verify security mitigations, identify additional mitigations, and guide product development teams through remediation.
- Conduct security reviews of applications, infrastructure, CI/CD workflows, and deployment architectures.
- Support threat modeling, risk assessments, secure design reviews, security verification, and validation efforts.
- Establish security baselines, hardening standards, and secure deployment practices.
- Collaborate with product, software development, cloud engineering, DevOps, and security teams to embed security throughout the SDLC.
- Participate in incident response, issue triage, daily collaboration, sprint planning, retrospectives, and design sessions.
- Evaluate tools and approaches that improve security effectiveness and developer experience.
Requirements
- At least 4 years of hands-on experience with Jenkins or similar CI/CD platforms.
- At least 3 years of software development, automation, or scripting experience using Python, PowerShell, Bash, or equivalent languages.
- Experience integrating SAST, DAST, SCA, container scanning, and secrets management into CI/CD pipelines.
- Working knowledge of cloud security principles and services in Azure and/or AWS.
- Understanding of containerized environments and Kubernetes security concepts.
- Experience collaborating with engineering teams in Agile development environments.
- Strong analytical, troubleshooting, and problem-solving skills, with the ability to work independently and manage multiple priorities.
- Bachelor’s degree in computer science, information technology, cybersecurity, or equivalent practical experience.
- Preferred experience includes Terraform, Bicep, CloudFormation, Azure DevOps pipelines, software supply chain security, Kubernetes and cloud-native platforms, and secure AI engineering practices.
- Preferred knowledge includes SBOM, SLSA, Sigstore, provenance validation, NIST SSDF, OWASP SAMM, OWASP ASVS, and CIS Benchmarks.
- Highly desirable certifications include Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: DevOps Engineer Expert, Certified Kubernetes Security Specialist, or Certified Kubernetes Administrator.
Benefits
- The position is available to candidates located in Poland.
- The role offers collaboration with product, software engineering, cloud architecture, DevOps, and security stakeholders.
- The position emphasizes developer-friendly security automation and secure-by-design engineering practices.