Product Security Engineer | Cyber Security & Secure Software Development (m/w/d)
Core
Establishing and evolving the Secure Software Development Lifecycle (SSDLC) for critical energy infrastructure software.
Role type
Product Security Engineer (Application Security)
Builds
Secure software products for the energy sector
Domain
Energy industry + Application Security
Deliverable
production ML models | product features
Required skills
Secure Software Development Lifecycle (SSDLC), Threat Modeling, Risk Analysis, SAST/DAST/SCA integration, SBOM management, CVE monitoring, Secure Coding, DevSecOps, OWASP, CVSS, C/C++/Java/Python
Preferred skills
IEC 62443 standard knowledge, Dependency-Track experience
Technologies
SAST, DAST, Software Composition Analysis, SBOM, Dependency-Track, CI/CD pipelines
Responsibilities
Develop and establish SSDLC per IEC 62443-4-1, conduct threat modeling and security risk analysis, integrate security tools into CI/CD pipelines, manage Software Bills of Materials (SBOM), monitor and assess CVEs, analyze and document security findings, consult development teams on secure coding and DevSecOps, collaborate with architecture and quality teams to improve product security
Seniority
Mid-Senior, hands-on IC