
Principal Engineer, Product Security (m/f/x)
commercetools1 month ago
Berlin, GermanyStaff+
Responsibilities
- Formulate, evangelize, and drive adoption of the product security strategy.
- Assess and improve the organization’s security maturity posture.
- Create standardized security architecture and operational best practices.
- Track and drive remediation of security and technology risks.
- Educate product teams on risk assessments, threat modeling, and secure API-first applications.
- Review requirements and designs and embed security tooling into the development process.
- Review external penetration tests and help prioritize fixes.
- Collaborate with product teams to resolve security issues and improve overall security.
- Facilitate or lead customer conversations regarding product security.
- Triage and investigate attack vectors and determine risk mitigation.
- Drive security and quality initiatives and support certification audits.
- Identify skills gaps and facilitate knowledge sharing, training, and onboarding across the organization.
Requirements
- 5+ years of hands-on Product Security experience.
- 2+ years of experience improving Product Security in a leadership role.
- Experience with customer-facing security roles and influencing roadmaps in matrix organizations.
- Experience in a scale-up environment with competing priorities.
- Experience with secure architecture design reviews and threat modeling.
- Experience integrating security throughout the SDLC.
- Experience implementing static analysis and secure code reviews.
- Knowledge of Linux systems, Kubernetes, Terraform, Vault, API security, and web application security.
- Practical DevSecOps experience and proficiency in at least one scripting language such as JavaScript or Go.
- Project management experience for projects affecting multiple teams.
- Experience working in an Agile environment with a strong customer focus.
- Experience setting up and running training or onboarding programs.
- Fluent English with clear written and verbal communication.
- Preferred qualifications include security certifications such as CISSP, CCSP, Certified Kubernetes Security Specialist, or GCP, AWS, or Azure security certifications.
- Curiosity about using AI tools and willingness to learn new technologies and leadership practices.
Benefits
- Comprehensive health benefits for employees and dependents, including personalized mental health support through OpenUp.
- Annual learning budget, self-paced learning platforms, language training, personalized coaching, mentorship, and leadership programs.
- Additional fully paid parental leave through Family Leave Plus.
- Equity participation program.
- Hybrid work arrangement with three days per week in the Berlin, London, or Valencia office.