onsite
Software Security Engineer - d.velop AG
Security Engineer
Lead security initiatives for cloud-native applications, ensuring robust protection across the development lifecycle using Python, Node.js, and AWS. Drive threat modeling, automated security testing, and continuous compliance in a fast‑paced DevSecOps environment.
About the role
Key Responsibilities
- Design, implement, and maintain secure software solutions across the full development lifecycle.
- Conduct threat modeling, code reviews, and penetration tests to identify and remediate vulnerabilities.
- Integrate security controls into CI/CD pipelines, automating scans and compliance checks.
- Collaborate with DevOps, QA, and product teams to embed security best practices in agile workflows.
- Stay current with emerging security threats, tools, and regulatory requirements, providing guidance to stakeholders.
Requirements
- Proven experience as a security engineer or similar role, with hands‑on expertise in Python, Node.js, and AWS services.
- Strong knowledge of security frameworks (e.g., OWASP Top 10, NIST), vulnerability assessment tools, and penetration testing techniques.
- Hands‑on experience with CI/CD tools (Jenkins, GitLab CI, GitHub Actions) and automated security testing.
- Excellent problem‑solving skills and the ability to communicate complex security concepts to technical and non‑technical audiences.
- Relevant certifications (e.g., OSCP, CISSP, AWS Security Specialty) are a plus.
Skills
pythonnodejsawspenetration testingcicd