Job
- Level
- Lead
- Location
- Darmstadt
- Working Model
- Onsite
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
Job Summary
In this role, you focus on security in the development process, conduct training sessions, implement security requirements, manage vulnerabilities, and coordinate external testing to ensure application security.
Job Technologies
Your role in the team
- Security in the Development Process
- Threat modeling, derivation of security requirements, and guidelines for code reviews.
- Training sessions for developers.
- Security testing during and after development (static and dynamic).
- Review of libraries/components as well as maintenance of a Software Bill of Materials.
- Continuous vulnerability management: from reporting to remediation and deployment.
- Security architecture of the product
- Selection and application of cryptographic procedures.
- Secure handling of secrets (e.g., keys, passwords) as well as key management.
- Creation and maintenance of hardening guidelines.
- Coordinate external security tests and track findings through to verification.
- Preparation for security incidents
- Emergency plans, drills, and regulated communication with clients and the public.
- Responsible disclosure of vulnerabilities (Disclosure process/VDP).
- Data protection from the very beginning
- Collaboration with Legal/Data Protection; support with tenders and security questionnaires.
- Practical Information Security Management
- Further development of a lean ISMS (e.g., along ISO/IEC 27001 or with a view to SOC-2 audits) with a focus on practical and efficient processes.
- Framework & Resources
- Resources: Budget for security tooling, external penetration tests, and possibly ISO consulting.
- Reporting line: direct to executive management; close collaboration with development and support.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Practical experience in Secure SDLC measures and common security audits as well as automation.
- Solid knowledge of authentication and authorization as well as secure platform key stores (Windows, macOS, Android, iOS).
- Risk-based prioritization and clear, target audience-appropriate communication internally and with corporate clients.
- Very good German and English, both written and spoken.
- Nice to have
Experience
- Several years of experience in application security or security engineering (desktop, mobile, or server).
- Experience with ISO/IEC 27001 and SOC 2 as well as coordinated vulnerability disclosure.
- Experience with CI/CD processes.
- Experience in maintaining software bill of materials.
This text has been machine translated. Show original
What we offer
- Great scope for design and responsibility with a direct impact.
- Short decision-making paths and a friendly, appreciative togetherness in a small team.
- Modernly equipped workplaces with height-adjustable desks, ergonomic chairs, and state-of-the-art hardware, including a relaxation room, billiard room, and a kitchen with a dining area.
- Central location in Darmstadt city center - directly at Herrngarten - with excellent transportation connections.
- Flexible working hours (core hours 10:00 AM - 4:00 PM).
- 30 days of vacation.
- Above-average salary - depending on experience and responsibility.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Topics You Will Work On
Job Locations
About Your Employer
AceBIT GmbH
AceBIT GmbH, based in Darmstadt, is a software company specializing in password and credential management. Its main product, Password Depot, is available on various platforms and targets both businesses and private users. Since its founding in 1998, the company has built an excellent reputation in the IT security industry.
Description
- Company Type
- Established Company
- Working Model
- Onsite
- Industry
- Internet, IT, Telecommunication