Unlock Full Resume Report

New offer - be the first one to apply!

September 9, 2026

Product Security Engineer (m/f/d)

Senior • Remote

Kraków, MA, Poland

Quick Facts

Product Security Engineer (m/f/d)

Description

Aras is expanding its Product Security team and is seeking a Product Security Engineer with strong DevOps expertise to help secure products, cloud platforms, and the software development lifecycle. The role focuses on designing, implementing, and maintaining secure CI/CD pipelines, integrating security controls throughout development, and promoting a security-first engineering culture across product and cloud teams.

Responsibilities

DevSecOps Engineering

  • Design, develop, and maintain secure CI/CD pipelines using Jenkins, Kubernetes, Azure, and cloud-native technologies.
  • Integrate security controls and automated security testing into the software delivery lifecycle.
  • Implement and manage SAST, DAST, SCA, secrets detection, IaC scanning, container security, and software supply chain security controls.
  • Drive security automation initiatives to reduce manual effort and accelerate secure software delivery.
  • Document and verify the existing security mitigations and identify if additional mitigations are required for products.
  • Work with product development teams to guide mitigation development.
  • Contribute to the development and implementation of security tests and verification protocols.
  • Assist in conducting security verification and validation efforts.

Product Security

  • Collaborate with product, development, and cloud engineering teams to embed security requirements throughout the SDLC.
  • Conduct security reviews of applications, infrastructure, CI/CD workflows, and deployment architectures.
  • Support threat modeling, risk assessments, and secure design reviews.
  • Help establish security baselines, hardening standards, and secure deployment practices.

Engineering & Collaboration

  • Develop automation solutions using Python, PowerShell, Bash, or Groovy.
  • Provide expertise in Agile.
  • Participate in daily standups, sprint planning, retrospectives, and collaborative design sessions.
  • Continuously evaluate new tools, technologies, and approaches to improve security effectiveness and developer experience.

Requirements

  • 4+ years of hands-on experience with Jenkins or similar CI/CD platforms.
  • 3+ years of software development, automation, or scripting experience using Python, PowerShell, Bash, or equivalent languages.
  • Experience integrating security tooling into CI/CD pipelines, including SAST, DAST, SCA, container scanning, and secrets management.
  • Working knowledge of cloud security principles and services in Azure and/or AWS.
  • Understanding of containerized environments and Kubernetes security concepts.
  • Experience collaborating with engineering teams in Agile development environments.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Self-motivated with the ability to work independently and manage multiple priorities.
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or equivalent practical experience.

Benefits

  • Security controls are seamlessly integrated into engineering workflows with minimal developer friction.
  • Vulnerabilities are identified and remediated earlier in the SDLC.
  • Security testing and compliance checks are automated wherever possible.
  • Product teams actively embrace DevSecOps and secure-by-design principles.
  • Security becomes an engineering accelerator rather than a deployment bottleneck.

Similar jobs you might like