We are looking for an R&D Security Specialistto join one of our teams - theIT Security team.
YOUR DAILY CHALLENGES
- Collaborates closely with developers and product teams to help prioritise identified security issues and tasks within the development lifecycle;
- Analyses results from tools likeSnykand assesses risks (e.g. usingCVSS) to support informed decisions on what should be fixed when and why;
- Participates in defining and maintaining security practices including code reviews source code protection measures and internal awareness activities;
- Contributes to developing and maintaining security-related documentation policies and procedures;
- Coordinates with members of the central security team and the local technical lead to ensure alignment on security initiatives;
- Supports and encourages security awareness among peers e.g. by engaging in initiatives similar toSecurity Championsinside development teams;
- While the position involves communication and coordination it does not include managerial responsibilities. The focus is on technical expertise and accountable contribution not on team management.
OUR EXPECTATIONS
- Minimum of2 years of experienceas a software developer DevOps engineer QA engineer with security interest or as an Application Security specialist;
- Understanding of how R&D and software development environments operate includingAgile methodologiesbacklog managementJira andCI/CD pipelines;
- Familiarity with core security concepts including theOWASP Top 10dependency management andsecure coding practices;
- Experience with or interest in tools such asSnykCheckmarxSonarQube or similar;
- Ability to analyse vulnerabilities and communicate priorities to various stakeholders;
- Understanding of relevant security frameworks and regulations such asGDPRCVSS andsecure SDLC;
- Fluency in German (written and spoken) at C1C2 levelis a mandatory requirement;
- Fluent in English;
- Bachelors degree in computer science studies.
CONSIDERED A PLUS
- Experience withweb application firewalls (WAFs)XDRcloud or application monitoring orAPI security;
- Hands-on experience withpenetration testingtools or workflows;
- Previous involvement inSecurity Champions internal training or peer knowledge-sharing initiatives;
- Certifications such asCISSPCSSLPCompTIA Security or similar.
WHAT YOU WILL GET
- Opportunity to work on meaningful products;
- A supportive environment to express your ideas and challenge you to be your best;
- An organisational culture thatstimulates informal relationships and open communication;
- Access to conferences internal and external training and self-learning systems;
- Opportunity to shape your role and contribution to the organisation;
- A variety of choices for internal events & activities to bond with other colleagues within the organisation;
- Greatbenefits and financial package.
We are looking for people with creative minds and enthusiasm to join us in developing whats new whats next and what best serves our customers needs.
Well be happy to welcome you to our team!
Required Experience:
Unclear Seniority