Back to search
SWIAT Linkedin · Posted yesterday

Product Security / DevSecOps Engineer (all genders)

Germany

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

How You Will Create Impact

As a Product Security / DevSecOps Engineer, you are part of SWIAT’s DevOps team and you will strengthen security across SWIAT's software development and IT operations.

You will work closely with our Development teams and take technical ownership of security throughout the software development lifecycle, from architecture and implementation to CI/CD, cloud infrastructure and production operations.

This is a hands-on engineering role. You will establish security practices, implement security tooling and controls, identify vulnerabilities and help our engineering teams build and operate secure financial market infrastructure.


Your Tasks and Responsibilities Include
  1. Establishing and continuously improving our Secure Software Development Lifecycle (SSDLC)
  2. Performing security architecture reviews and threat modelling for applications and infrastructure
  3. Integrating security controls and automated security testing into CI/CD pipelines
  4. Implementing and operating SAST, DAST, Software Composition Analysis (SCA), container and infrastructure scanning
  5. Managing technical vulnerabilities and supporting engineering teams with remediation
  6. Hardening Kubernetes, container, Linux and cloud environments
  7. Reviewing Infrastructure as Code and Kubernetes configurations from a security perspective
  8. Designing and improving IAM, secrets management, KMS/HSM and PKI concepts
  9. Defining and implementing security baselines for applications and infrastructure
  10. Supporting secure software supply chain practices, including dependency management and SBOM
  11. Coordinating penetration tests and supporting remediation of identified findings
  12. Supporting technical investigation and response to security incidents
  13. Advising Development, DevOps and Architecture teams on technical security topics
  14. Increasing security awareness within engineering teams through guidelines, reviews and knowledge sharing
  15. Supporting security-related requirements arising from ISO 27001, DORA and our financial-industry environment


Your Profile and Requirements

Education & Experience

  1. BA/MA in Computer Science, Information Security, Software Engineering or a comparable field, or equivalent professional experience
  2. Several years of hands-on experience in DevSecOps, Product Security, Application Security or Security Engineering
  3. Strong software engineering or DevOps background
  4. Experience securing production environments and modern software delivery pipelines


Skills & Competencies

  1. Secure Software Development Lifecycle and secure coding practices
  2. Threat modelling and security architecture
  3. CI/CD security and security automation
  4. SAST, DAST and Software Composition Analysis
  5. Vulnerability management
  6. Kubernetes and container security
  7. Linux and networking
  8. Cloud security, preferably Azure and/or AWS
  9. IAM and secrets management
  10. Strong understanding of applied cryptography, KMS, HSM and PKI concepts
  11. Infrastructure as Code, preferably Terraform and Ansible
  12. Git-based development and CI/CD environments, preferably Gitlab
  13. Software supply chain security and SBOM concepts
  14. Programming or scripting experience, preferably JavaScript / TypeScript, Python, Go or similar
  15. ISO 27001 and DORA knowledge is a strong advantage
  16. Experience in financial services or regulated environments is a strong advantage
  17. Blockchain and Ethereum/EVM security knowledge is a plus
  18. Good English skills


⚠️ Please be advised that a valid work permit for Germany is required for non-EU citizens. Unfortunately, applications without a valid working permit and sufficient language skills will not be considered.


About SWIAT

SWIAT GmbH is a Frankfurt-based FinTech building next-generation financial market infrastructure using Distributed Ledger Technology (DLT). Our mission is to enable secure, compliant, and efficient issuance, trading, settlement, and servicing of digital and traditional financial assets on a global scale.


What do we do?
  1. Coordinate and operate the SWIAT Network and Platform, a secure and trusted DLT-based financial infrastructure
  2. Enable the issuance and lifecycle management of regulated digital assets
  3. Support the tokenisation and mobilization of traditional financial instruments and collateral
  4. Deliver solutions tailored to banks, financial institutions, and capital market participants
  5. Drive innovation in digital securities, settlement, and collateral management


Place of Work and Compensation

Our office is located in the centre of Frankfurt. We support flexible and hybrid working models and value regular in-person collaboration to maintain strong team connections.

We offer a competitive compensation package together with additional employee benefits.


Did we catch your interest? Apply now and join our mission!
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search