Skip to content
← Back to job listings

Principal Engineer (Product Security)

commercetools · London, United Kingdom

External listingfull-time27 days ago

About The Role

Join our team as a Principal Engineer (Product Security) and play a crucial role in enhancing the security posture of our ambitious product. You will formulate and drive the adoption of our product security strategy, assess and advise on security maturity, create standardized security architecture, and educate product teams on risk assessments and secure application development. You will also collaborate with product teams to improve overall security, facilitate customer conversations regarding product security, and drive security and quality initiatives across the organization. This is a remote-first position with a generous benefits package.

  • Formulate, evangelise, and drive adoption of the product security strategy, and create a standardised security architecture and operational best practices.
  • Assess, advise on, and increase the security maturity posture, and help track and drive remediation of security and technology risks.
  • Educate product teams on risk assessments, threat modelling, and building secure api-first applications, and review requirements and designs to help product teams address shortcomings.
  • You're a creative problem-solver who is wired to find solutions
  • You confidently dive into complex challenges and have a talent for making them simple for others
  • Your curiosity drives you to constantly grow and contribute to an environment of trust and teamwork
  • Great ideas come from many paths, and your unique perspective matters more than checking every box
  • What matters most is the mindset you bring to the work
  • Experience infusing security into various levels of the SDLC
  • Experience with Static Analysis and Secure Code Review implementations
  • Experience setting up and running trainings or onboardings
  • Sound knowledge of Linux systems, Kubernetes, Terraform, Vault, API, and web application security
  • Expertise in formulating, elaborating, and clarifying requirements or priorities
  • Experience in a scale-up environment with ambitious and competing priorities
  • Experience with Secure Architecture design reviews and Threat Modeling
  • Clear written and verbal communication in fluent English
  • Experience working within an Agile environment with a strong customer focus
  • 2+ years of experience improving Product Security in a leadership role
  • A strong technical background and 5+ years of proven track record in hands-on Product Security
  • Practical experience in DevSecOps and proficiency in at least one scripting language like JavaScript or Go
  • Project management experience for projects affecting multiple teams
  • Experience with customer-facing security roles and influencing roadmaps in matrix organizations
  • AI Aptitude: A genuine curiosity for using AI tools to work smarter and more effectively, paired with a drive to learn and put them into practice in your role
  • An eagerness to constantly improve and learn about leadership and new technologies
  • Security Certifications such as CISSP, CCSP, Certified Kubernetes Security Specialist, or GCP/AWS/Azure security certifications

This is an external listing. JobSpring does not represent or verify the employer. Report this listing