Principal Security Engineer
storiogroup
Amsterdam
permanent
Deze vacature komt van Lever
How you embrace curiosity daily.
- Define security principles, standards, patterns, and guardrails that enable engineers to build securely at pace.
- Provide hands on security expertise across APIs, microservices, cloud infrastructure, authentication, authorisation, and software supply chain security.
- Lead threat modelling and security architecture reviews for important products and technology initiatives.
- Partner with engineers, architects, and product teams to identify risks and develop pragmatic solutions.
- Evolve our approach to application security, vulnerability management, and security throughout the development lifecycle.
- Build or enable automation that improves security outcomes while reducing friction for engineering teams.
- Identify emerging security risks, including those introduced by AI, and drive appropriate mitigation.
- Help establish the principles and practices that allow teams to move quickly while managing risk effectively.
- Raise overall security capability across the engineering organisation by mentoring engineers and Security Champions.
- Develop meaningful Product Security metrics and use them to drive continuous improvement.
- Direct the technical direction of Product Security and influence how security is designed, built, and operated across our platform.
- Communicate potential security risks and their impact to engineering and senior stakeholders.
- Enable engineering teams to adopt AI securely and enhance productivity.
- Significant experience in Product Security, Application Security, or Security Engineering in a modern software engineering environment.
- Strong experience with security architecture, threat modelling, and turning security concerns into practical engineering solutions.
- Deep understanding of application and API security, secure development practices, and modern software architectures.
- Experience securing cloud native applications, distributed systems, and embedding security into engineering workflows and the software development lifecycle.
- Strong understanding of software supply chain security, dependency risk, and SBOMs.
- Proven ability to influence multiple engineering teams, define security standards, and communicate effectively with senior technical stakeholders.
- Experience with, or a strong interest in, AI security and using AI to improve security engineering.
- Experience with Infrastructure as Code security, Security Champions, or Bug Bounty programmes.
- Experience or formal qualifications in relevant security or cloud areas.
Deze vacature komt van Lever. Originele vacature bekijken ↗