Product Security Engineer

🔥 18 hours ago

🇵🇱 Poland – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Aras Corporation

Aras Corporation

501 - 1000 employees

Founded 2000

🏭 Manufacturing

💼 Consulting

📦 Logistics

Manufacturing • Consulting • Logistics

Aras Corporation is a software company specializing in Product Lifecycle Management (PLM) and digital transformation solutions. It offers the Aras Innovator platform, a low-code development environment that supports digital thread, interoperability, and supplier collaboration across industries such as aerospace, automotive, and high tech. Aras focuses on enhancing product quality, compliance management, and sustainable product design. The company's solutions enable rapid application development, improve production timelines, and support enterprise engineering management systems. Aras is dedicated to providing innovative and adaptable PLM platforms for managing complex product lifecycles efficiently.

📋 Description

• Design, develop, and maintain secure CI/CD pipelines using Jenkins, Kubernetes, Azure, and cloud-native technologies • Integrate security controls and automated security testing into the software delivery lifecycle • Implement and manage SAST, DAST, SCA, secrets detection, IaC scanning, container security, and software supply chain security controls • Drive security automation initiatives to reduce manual effort and accelerate secure software delivery • Document and verify existing security mitigations and identify additional mitigations required for products • Work with product development teams to guide mitigation development • Contribute to security tests and verification protocols; assist with security verification and validation efforts • Collaborate with product, development, and cloud engineering teams to embed security requirements throughout the SDLC • Conduct security reviews of applications, infrastructure, CI/CD workflows, and deployment architectures • Support threat modeling, risk assessments, and secure design reviews • Help establish security baselines, hardening standards, and secure deployment practices • Develop automation solutions using Python, PowerShell, Bash, or Groovy • Provide expertise in Agile • Participate in daily standups, sprint planning, retrospectives, and collaborative design sessions • Respond to incidents, triage issues, and communicate with the Product Development team daily • Evaluate new tools, technologies, and approaches to improve security effectiveness and developer experience • Partner with software engineers, cloud architects, DevOps teams, and security stakeholders to identify, prioritize, and remediate security risks at scale

🎯 Requirements

• 4+ years of hands-on experience with Jenkins or similar CI/CD platforms • 3+ years of software development, automation, or scripting experience using Python, PowerShell, Bash, or equivalent languages • Experience integrating security tooling into CI/CD pipelines, including SAST, DAST, SCA, container scanning, and secrets management • Working knowledge of cloud security principles and services in Azure and/or AWS • Understanding of containerized environments and Kubernetes security concepts • Experience collaborating with engineering teams in Agile development environments • Strong analytical, troubleshooting, and problem-solving skills • Self-motivated with the ability to work independently and manage multiple priorities • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or equivalent practical experience • Preferred: Experience with Infrastructure as Code (Terraform, Bicep, CloudFormation) • Preferred: Experience with Azure DevOps pipelines and security integrations • Preferred: Familiarity with software supply chain security practices and frameworks (SBOM, SLSA, Sigstore, provenance validation) • Preferred: Experience securing Kubernetes and cloud-native platforms • Preferred: Familiarity with AI-assisted development tools and secure AI engineering practices • Preferred: Knowledge of NIST SSDF, OWASP SAMM, OWASP ASVS, and CIS Benchmarks • Highly desirable certifications: Microsoft Certified: Azure Security Engineer Associate; Microsoft Certified: DevOps Engineer Expert; Certified Kubernetes Security Specialist (CKS); Certified Kubernetes Administrator (CKA)

🏖️ Benefits

• Full-time employment • Remote work for candidates located in Poland

Apply Now

Similar Jobs

🕒 4 days ago

Genesis Tech

1001 - 5000

📣 Marketing

💼 Consulting

📦 Logistics

Offensive Security Engineer conducting web, mobile, Active Directory and cloud penetration tests for Genesis’s global product IT ecosystem. Building automation and AI-agent workflows for offensive security.

Android

AWS

Azure

Cloud

Google Cloud Platform

iOS

Java

JavaScript

PHP

Python

TypeScript

🕒 4 days ago

MWDN

51 - 200

💼 Consulting

📦 Logistics

🏥 Healthcare

Security Researcher investigating browser, mobile, and AI-driven fraud signals. Supporting MWDN’s IAM cybersecurity client with detection research, experiments, and SDK requirements.

Android

Cyber Security

iOS

Java

JavaScript

Kotlin

Objective-C

Python

Swift

TypeScript

🕒 August 19

Callstack

51 - 200

💼 Consulting

📣 Marketing

IT Security Officer securing systems, devices, identities, and data at Callstack, a cross-platform development consultancy. Managing cybersecurity, infrastructure, compliance, incident response, and security awareness.

AWS

Azure

Cloud

Cyber Security

DNS

Firewalls

Google Cloud Platform

Linux

MacOS

🕒 August 19

Attio

11 - 50

💼 Consulting

📣 Marketing

☁️ SaaS

Security Engineering Lead building Product Security for Attio’s AI-native CRM. Securing customer data, leading incident response, and hiring the security team.

🕒 August 17

Interact Software

201 - 500

🏢 Enterprise

☁️ SaaS

⚡ Productivity

Cyber Security Engineer building automated security capabilities for Interact’s enterprise intranet platform. Improving Splunk, cloud controls, and incident response through engineering and automation.

Cloud

Cyber Security

Firewalls

Splunk