Full-Time

Product Security Engineer

Scalable GmbH

Scalable GmbH

No salary listed

Berlin, Germany

Hybrid

International relocation support available;Opportunity to work from abroad.

Category
IT & Security (1)
Required Skills
Kotlin
Python
Github Actions
Threat modeling
Java
Infrastructure as Code (IaC)
TypeScript
AWS
Requirements
  • Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent practical experience).
  • Profound experience in Application Security, Product Security, or Software Engineering with a security focus.
  • Strong understanding of the OWASP Top 10 and familiarity with verification standards like OWASP Application Security Verification Standard and Mobile Application Verification Standard.
  • Ability to read and review code with familiarity in Kotlin, Java, Python, or TypeScript and comfort discussing code logic with developers.
  • Experience with Burp Suite or similar testing tools; familiarity with CI/CD concepts such as GitHub Actions is a plus.
  • Certifications are nice to have but not required (examples include OSCP, GWAPT, GCPN, CSSLP, or AWS Security Specialty).
  • High empathy for developers and the ability to explain technical findings clearly; strong collaboration and teamwork orientation.
Responsibilities
  • Perform security assessments and code reviews on web applications, mobile applications, and application programming interfaces, using manual testing combined with automated tooling to validate security controls against industry standards.
  • Triage incoming reports from bug bounties, vulnerability disclosures, and external penetration tests, and assist in establishing a formal Bug Bounty program in the future.
  • Assist in integrating security tooling such as static application security testing, dynamic application security testing, and software composition analysis into continuous integration and delivery pipelines (AWS and GitHub), tuning tools for high-fidelity alerts for developers.
  • Partner with senior security engineers and product teams to participate in threat modeling sessions and learn to identify architectural flaws and logic vulnerabilities in the design phase.
  • Collaborate with engineering teams to advocate for secure coding practices and build paved roads consisting of secure defaults and libraries to simplify secure coding in Kotlin and Python.
  • Gain exposure to securing infrastructure-as-code and Amazon Web Services environments to help ensure a resilient microservices architecture.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A