Security Engineer
We're looking for a Security Engineer to join our core Engineering team. In this role, you'll be a
- on builder, responsible for the security of our product, cloud infrastructure, and software development lifecycle. You'll drive
-
- end projects, from integrating security automation into our CI/CD pipelines to architecting security controls for our platform. We're looking for someone who thrives in an open Dev
Ops culture and wants to contribute innovative solutions that enable our engineers to build and ship secure products quickly and safely.
Responsibilities
- Integrate and automate security controls throughout the entire software development lifecycle (SDLC), including CI/CD pipelines.
- Develop and maintain security tooling and scripts to automate repetitive tasks and security operations.
- Collaborate with platform and engineering teams to design, implement, and secure
- native infrastructure using Infrastructure as Code (Ia
C). - Drive the "shift-left" security strategy by embedding security best practices and tools directly into developer workflows.
- Design and architect security solutions that scale with our product and platform, covering areas like secrets management, identity and access management (IAM), and runtime security.
- Conduct threat modeling, risk assessments, and vulnerability analysis on our products and infrastructure.
Requirements
- Hands-on experience with cloud security principles and best practices, preferably with AWS or Google Cloud Platform.
- Experience with designing and implementing security solutions in a
- native environment. - Strong programming and scripting skills (Python preferred) to build security automation and tooling.
- Experience with modern security tools such as SAST, DAST, SCA, and vulnerability scanners integrated into CI/CD.
- Knowledge of container and orchestrator security (e. g. , Kubernetes).
- Familiarity with Infrastructure as Code (Ia
C) tools like Terraform or Cloud
Formation. - Strong understanding of Dev
Ops methodologies and how to embed security into the development workflow. - Experience with threat modeling, penetration testing, or bug bounty programs.
- Informações detalhadas sobre a oferta de emprego
Empresa: Bitsight Localização: Porto
Porto, Porto District, PortugalPublicado: 22. 8. 2025
Vaga de emprego atual
Seja o primeiro a candidar-se à vaga de emprego oferecida!