About this role
Are you passionate about securing cloud-native applications and driving best-in-class security practices? We are looking for a Product Security Expert to join our dynamic team and help us build secure, resilient systems!
• ✅ Proven experience in software security, DevSecOps, or application security engineering. • 🔄 Familiarity with SDLC and secure operational practices. • 🛠️ Expertise with security tools & methodologies: SAST, DAST, vulnerability scanners (Tenable/Nessus, Rapid7, Aquasec/Trivy, Black Duck, CheckMarx, Fortify, Coverity). • 📊 Experience with SIEM systems like Splunk or Elastic. • 📝 Comfortable using Jira or similar ticketing systems. • 🛡️ Strong understanding of compliance standards (ISO 27001, SOC 2, PCI-DSS). • Analytical and problem-solving skills, able to turn complex findings into actionable plans. • ⚡ Experience moderating Threat Modelling workshops, familiarity with STRIDE. • 🐳 Deep knowledge of cloud-native development, containers & Kubernetes. • 🐍 Development experience in Javascript and/or Python and/or Golang. • ☁️ Exposure to major cloud providers (AWS, Azure, GCP) or with OpenStack. • 🖥️ Nice to have: familiarity with physical datacenter infrastructure (storage, network, hypervisors like KVM).
• 🔍 Conduct security and risk assessments across applications and systems to identify vulnerabilities. • Collaborate with our security colleagues to set up Frontier AI scanning capability, analye technical findings, manage backlog (including false positives), and improve our security posture. • 📋 Create, manage, and resolve Jira backlogs for security issues, exceptions, and risk items. • 🛠️ Support rollout and implementation of SDLC, including documentation, exception handling, and compliance alignment. • ⚙️ Work with dev & ops teams to integrate security into CI/CD pipelines (SAST, DAST, dependency scanning, compliance-as-code). • 📚 Help develop and maintain security policies, standards, and procedures aligned with ISO 27001, SOC 2, PCI-DSS. • 🛡️ Configure and optimize security tools & vulnerability scanners to improve detection and efficiency. • 🏗️ Co-lead threat modeling & risk assessment workshops to evaluate architectural and operational risks. • ✍️ Provide clear documentation and explain complex security concepts to stakeholders. • Collaborate with architects, service owners, and SAP Global Security & Compliance contacts to create security concepts for critical projects.
• 👥 An opportunity to work in small, dynamic team with a startup mindset — all within a large international company. • 🏡 Flexibility to work from home or from our modern office in Budapest. • 💬 A supportive, collaborative, and motivational work environment where ideas truly matter. • 💡 Be part of innovation — contribute to the development of cutting-edge applications. • ⏰ Full-time role with flexible working hours. • 💼 Enjoy a wide range of benefits and the stability that comes with working for a reputable, global organization.
Kindly upload your Cv in English. 1. Hr call with the recruiter. 2. Technical interview with the hiring team. 3. Final interview with project team.
#LI-SK1