
Product Security Engineer (m./f./div.)
Keenfinity Group6 hours ago
Ovar, PortugalMid Level / Senior
Responsibilities
- Provide security guidance across new products, technologies, and the product development lifecycle.
- Lead threat modeling exercises and collaborate with engineering teams on product security assessments.
- Perform application security assessments, secure code reviews, and vulnerability testing across web, backend, native, device, product, and infrastructure codebases.
- Operate and tune SAST, DAST, and SCA tooling, triage findings, and track vulnerabilities through remediation.
- Design security automation and manage the product security pipeline tooling.
- Assess AWS environments, IAM policies, infrastructure, and cloud deployments against security best practices.
- Support vulnerability detection, incident detection, and incident response processes.
- Operate and support PKI, certificate issuance and lifecycle management, and cryptographic services.
- Maintain security documentation and standards and advise teams on secure coding and remediation.
Requirements
- 3–5 years of experience in product, application, or offensive security.
- Degree in Computer Science, Cybersecurity, or a related field, or equivalent experience.
- Hands-on vulnerability assessment experience.
- Application security experience, including secure code review and SAST, DAST, and SCA tooling.
- Experience with threat modeling methodologies such as STRIDE.
- Working knowledge of secure SDLC, DevSecOps, and CI/CD security integration.
- Cloud security knowledge, particularly AWS, including core services, IAM, and cloud security best practices.
- Solid understanding of PKI, digital certificates, and applied cryptography.
- Ability to use scripting and automation, such as Python, to build and scale security tooling.
- Familiarity with incident detection and response processes.
- Strong communication skills for working with development and project teams.
- Preferred qualifications include penetration testing experience, embedded or IoT device experience, exposure to the EU Cyber Resilience Act, AI security experience, cloud security certifications, and certifications such as OSCP, GIAC, or CEH.
Benefits
- Flexible work conditions with 2 days of home office.
- Health insurance and an on-site medical office offering nutrition, psychology, physiotherapy, and general clinic services.
- On-site canteen and free parking.
- Sports and health activities, including a gym.
- Technical and foreign-language training opportunities and certifications.
- Career progression and continuous professional development opportunities.
- Exchange opportunities with colleagues around the world.
- Discounts through partnerships and products.
- Equal-opportunity workplace with support available for people with disabilities.
About Keenfinity Group
Keenfinity Group builds security, safety, and professional communications systems for enterprise, public-sector, and venue customers, spanning video surveillance, access control, intrusion detection, public address/voice alarm, conference solutions, and pro audio, plus electronics manufacturing services. Headquartered in Munich, it became an independent company after a 2025 carve-out from Bosch and now operates in Triton’s portfolio; its audio portfolio includes the Bosch, Electro-Voice, Dynacord, RTS, and Telex brands. The group reported fiscal 2025 revenue above €1 billion.