Overview
Cybersecurity Engineer to strengthen product and enterprise security posture through proactive security assessments, threat modeling, secure design, and DevSecOps enablement across the SDLC.
What you'll do
- Conduct penetration testing across web applications, APIs, cloud environments, and supporting infrastructure.
- Lead threat modeling exercises with engineering and architecture teams to identify risks, attack paths, and mitigations early in the SDLC.
- Perform secure design and architecture reviews aligned with security-by-design principles and industry standards.
- Evaluate application, cloud, and infrastructure security controls and provide actionable remediation recommendations.
- Integrate security testing and validation into CI/CD pipelines for automated security checks.
- Support vulnerability management, including validation, risk assessment, remediation guidance, and verification of fixes.
- Develop security automation, tooling, scripts, and continuous improvement for DevSecOps and governance.
What you'll need
- 5+ years of experience in cybersecurity, application security, product security, security engineering, or related fields.
- Demonstrated manual and automated penetration testing experience for web applications, APIs, cloud environments, and supporting infrastructure.
- Experience conducting threat modeling and security architecture reviews using frameworks such as STRIDE and PASTA (also mentions ATT&CK).
- Solid understanding of secure software development practices and common vulnerabilities including OWASP Top 10 and API Security Top 10.
- Proficiency in one or more programming/scripting languages: Python, Java, JavaScript, C#, PowerShell, Go, or similar.
- Experience integrating security practices into the SDLC and DevSecOps/CI/CD pipelines.
- Familiarity with security testing and tooling such as SAST, DAST, and SCA, plus container security and IaC security tools.
Details
- Typical time allocation includes 30–55% product security engineering, 30–55% penetration testing and security validation, and 10–15% security automation/DevSecOps integration/governance/process improvement.
- Willingness to work in a European shift (1pm to 10pm) is required.
Read the full description and apply on the company’s own careers page.