yandex
commercetools
Страна
Германия
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
ГибридПолная занятость

Principal Engineer, Product Security

Оценка ИИ

Отличная позиция в топовой технологической компании с сильной инженерной культурой и современным стеком. Предлагается широкий пакет бенефитов, включая опционы и бюджет на обучение, а также возможность реально влиять на стратегию безопасности продукта.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует редкого сочетания глубоких технических знаний (K8s, Terraform, Go/JS) и лидерских качеств для управления стратегией безопасности в масштабируемой организации. Высокая сложность обусловлена необходимостью внедрять практики 'shift left' и взаимодействовать с клиентами на уровне Principal-инженера.

Анализ зарплаты

Медиана115 000 €
Рынок100 000 € – 140 000 €
Оценка ИИ

Предлагаемая роль Principal уровня в Мюнхене обычно оплачивается выше среднего по рынку. Учитывая масштаб компании commercetools, можно ожидать конкурентоспособную зарплату, дополненную значительным пакетом акций (equity).

Сопроводительное письмо

I am writing to express my strong interest in the Principal Engineer, Product Security position at commercetools. With over five years of hands-on experience in product security and a proven track record of leading security initiatives in scale-up environments, I am confident in my ability to drive your 'shift left' strategy and enhance the security maturity of your multi-cloud infrastructure. My background in Kubernetes, Terraform, and secure API-first application design aligns perfectly with your technical stack and ambitious product goals.

Throughout my career, I have successfully bridged the gap between complex security requirements and engineering execution by fostering a culture of threat modeling and automated security tooling within the SDLC. I am particularly drawn to commercetools' culture of experimentation and your 'best idea wins' philosophy. I look forward to the possibility of leveraging my expertise in DevSecOps and stakeholder management to support your engineering teams and ensure the continued trust of your global customer base.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в commercetools уже сейчас

Присоединяйтесь к лидеру в сфере headless commerce и станьте архитектором безопасности для глобальных enterprise-решений!

Описание вакансии

About Commercetools

Real innovation starts with a strong foundation, and at commercetools, that comes from the perfect balance of our product and our people. Behind every leap forward is a collective of builders, explorers, doers, makers, and problem-solvers. The kind of people who not only pioneered a more flexible approach to commerce architecture but also shaped the culture of experimentation that approach unlocked. Together they are the engine of commerce innovation today. At commercetools, we power the next era of commerce for our customers. Whether it’s AI-driven solutions that help enterprises make smarter business decisions, bridging digital and physical shopping experiences, or enabling entirely new ways for industries to connect with their customers, we help the world’s most ambitious companies experiment, scale, and grow without limits. Here the best idea wins, not the loudest voice. You will have the tools, trust, and space to not only build the future of commerce, but to build your own.

Your Impact

As our Principal Engineer Product Security , you’ll support the Engineering team by solving challenging technical problems for an ambitious product and enabling teams to "shift left" to build secure services on multi-cloud infrastructure.

You will:

  • Formulate, evangelise, and drive adoption of the product security strategy
  • Assess, advise on, and increase the security maturity posture
  • Create a standardised security architecture and operational best practices
  • Help track and drive remediation of security and technology risks
  • Educate product teams on risk assessments, threat modelling, and building secure api-first applications
  • Review requirements and designs to help product teams address shortcomings
  • Embed security tooling into the development process
  • Contribute to the review of external penetration tests and help teams prioritise fixes
  • Collaborate with product teams to improve overall security and resolve specific issues
  • Facilitate or lead customer conversations regarding product security
  • Triage and investigate new attack vectors to determine risk mitigation
  • Drive security and quality initiatives across the organization and support certification audits
  • Collaborate with Product Management, Principal Engineers, and legal/compliance teams
  • Identify skills gaps and facilitate knowledge sharing across the organization

This role is hybrid, with three days a week spent in our Berlin, London or Valencia office.

What Sets You Apart

You're a creative problem-solver who is wired to find solutions. You confidently dive into complex challenges and have a talent for making them simple for others. Your curiosity drives you to constantly grow and contribute to an environment of trust and teamwork. Great ideas come from many paths, and your unique perspective matters more than checking every box. What matters most is the mindset you bring to the work.

You bring:

  • A strong technical background and 5+ years of proven track record in hands-on Product Security
  • 2+ years of experience improving Product Security in a leadership role
  • Experience with customer-facing security roles and influencing roadmaps in matrix organizations
  • Experience in a scale-up environment with ambitious and competing priorities
  • Expertise in formulating, elaborating, and clarifying requirements or priorities
  • Experience with Secure Architecture design reviews and Threat Modeling
  • Experience infusing security into various levels of the SDLC
  • Experience with Static Analysis and Secure Code Review implementations
  • Sound knowledge of Linux systems, Kubernetes, Terraform, Vault, API, and web application security
  • Practical experience in DevSecOps and proficiency in at least one scripting language like JavaScript or Go
  • Project management experience for projects affecting multiple teams
  • Experience working within an Agile environment with a strong customer focus
  • Experience setting up and running trainings or onboardings
  • Clear written and verbal communication in fluent English

AI Aptitude: A genuine curiosity for using AI tools to work smarter and more effectively, paired with a drive to learn and put them into practice in your role.

Nice to Have: \* Security Certifications such as CISSP, CCSP, Certified Kubernetes Security Specialist, or GCP/AWS/Azure security certifications 

  • An eagerness to constantly improve and learn about leadership and new technologies

Our Benefits

Because work and life are connected, our benefits are too. We’ve designed them to give you the security, flexibility, and opportunities you need to focus on what matters most.

🩺 Comprehensive health benefits for you and your dependents, including access to OpenUp for personalized mental health support

📚 Learning and development opportunities including an annual learning budget, access to self-paced learning platforms and language training, personalized coaching, mentorship, and leadership programs

🍼 Family Leave Plus gives you additional fully paid weeks of parental leave on top of government-provided leave, so you can spend more time with your new addition

📈 Our equity participation program allows you to share in our success

For more information on our benefits, visit this page.

Come as you are. Build with us.

Your unique perspective is essential to our success. We are committed to building a team that reflects the world around us because we know it’s the only way to build the future. We celebrate our differences and have created a hiring process that’s fair, inclusive, and designed to let your talent shine.

We proudly welcome applicants of every race, color, religion, gender identity, sexual orientation, age, and any other part of your identity that makes you who you are. As an equal opportunity employer, we believe that our strength lies in our diversity, and we invite you to be a part of our global community.

For more information on our diversity, equity, inclusion, and belonging practices, visit this page.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Linux
  • Terraform
  • Threat Modeling
  • Kubernetes
  • JavaScript
  • Cloud Security
  • DevSecOps
  • Go
  • SDLC
  • Vault
  • SAST
  • API Security

Возможные вопросы на собеседовании

Проверка опыта внедрения процессов безопасности в существующий цикл разработки.

Расскажите о вашем опыте внедрения практик 'shift left' в крупной организации: с какими основными препятствиями вы столкнулись и как их преодолели?

Оценка навыков архитектурного анализа и работы с рисками.

Как вы подходите к проведению Threat Modeling для сложных API-first приложений, работающих в multi-cloud среде?

Проверка технических навыков в области контейнеризации и облачной безопасности.

Какие специфические риски безопасности Kubernetes вы считаете наиболее критичными для SaaS-платформы и как вы предлагаете их минимизировать?

Оценка лидерских качеств и умения влиять на другие команды.

Опишите ситуацию, когда вам нужно было убедить продуктовую команду приоритизировать исправление уязвимостей в ущерб выпуску новых фич. Какую аргументацию вы использовали?

Проверка навыков реагирования на инциденты и анализа векторов атак.

Как вы организуете процесс триажа и расследования новых векторов атак, чтобы определить их потенциальное влияние на продукт?

Похожие вакансии

Atom group
4 000 $ – 5 000 $

Senior Information Security (ИБ)

SeniorУдалённоБеларусь
Information Security · DevSecOps · SDLC · Risk Management · Security Policy · DevOps
+6 навыков
SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
Operation Zero
450 000 ₽ – 900 000 ₽

Исследователь безопасности Android

УдалённоРоссия
Android · Reverse Engineering · Exploit Development · Kernel Research · C++ · ARM Assembly · Java · Ghidra · IDA Pro · Linux Kernel · Kotlin · JavaScript
+12 навыков
NDA
250 000 ₽ – 450 000 ₽

Эксперт по защите периметра (WAF)

УдалённоРоссия
WAF · Wallarm · Positive Technologies Application Firewall · NGFW · IPS · Vulnerability Assessment · Network Security
+7 навыков
Квазар
до 350 000 ₽

DevOps-инженер/ИБ (devops engineer, information security)

УдалённоРоссия
TCP/IP · DNS · DHCP · HTTPS · SMTP · BGP · OSPF · VLAN · NAT · Zero Trust · RBAC · SIEM · Zabbix · ELK · Wazuh · Grafana · Bash · PowerShell · Python · VMware · Proxmox · Hyper-V · KVM · SoC
+24 навыков
Innostaff
Не указана

Сеньор AppSecOps-инженер

SeniorУдалённоБеларусь
AppSecOps · DevSecOps · SAST · DAST · SCA · CI/CD · Cybersecurity · Kubernetes · Docker
+9 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

commercetools
Страна
Германия