Job
- Level
- Senior
- Job Field
- IT, Application, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Dortmund
- Working Model
- Hybrid, Onsite
Job Summary
You will be responsible for establishing secure software development practices, conducting security reviews, identifying security risks, and working closely with development teams to implement and optimize security measures.
Job Technologies
Your role in the team
- Responsibility for operational and conceptual tasks in the field of Application Security
- Establishment of secure software development practices across all projects
- Conducting security reviews at the code and architecture level
- Identification, analysis, and assessment of security risks (e.g., through threat modeling and threat analyses)
- Development and implementation of application-specific security concepts
- Support in architecture decisions considering security requirements
- Vulnerability Management: Analysis, assessment (e.g., CVEs), and prioritization of measures
- Close collaboration with development teams to sustainably address security vulnerabilities.
- Integration of security into CI/CD processes in the sense of DevSecOps (e.g., automated scans, dependency checks)
- Support in the secure configuration of cloud and Kubernetes environments (e.g., secrets management, access controls, network security)
- Participation in securing containerized applications
- Participation in the implementation of authentication and authorization concepts as well as API security
- Consideration of supply chain security, especially regarding external dependencies and libraries.
- Support and evaluation of penetration tests as well as assistance with the findings analysis and prioritization.
- Analysis of attack scenarios and exploitation methods to derive appropriate countermeasures.
- Participation in the definition and further development of security guidelines and best practices
- Consulting development teams on security-related topics throughout the entire software lifecycle.
- Support in the analysis and handling of security incidents
- Contribution to the continuous improvement of security measures and defense strategies
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Understanding common security standards and best practices (e.g., OWASP Top 10, international security standards)
- Knowledge in Threat Modeling and Risk Analysis (or willingness to acquire these skills)
- Understanding of vulnerability management and handling of Security Advisories/CVEs
- Basic knowledge of cloud technologies and/or Kubernetes and their security requirements
- Knowledge in authentication, authorization, and API security is advantageous.
- Analytical thinking as well as a structured approach to security issues
- Strong communication skills and the ability to collaborate with development teams
- Very good German and good English skills
- For junior profiles: high willingness to learn and interest in further developing in the field of Application Security.
- For experienced profiles: Ability to strategically develop security further and take on responsibility.
Experience
- Initial or advanced experience in conducting security reviews (code and architecture)
- Experience or interest in DevSecOps as well as integration of security into CI/CD pipelines.
- Initial experience with Penetration Testing or a basic understanding of attack methods
This text has been machine translated. Show original
What we offer
- Flexible working hours within a flexitime model and full remote / on-site as needed in the office
- 30 days of vacation per year
- Free access to the LinkedIn Learning platform
- Individual development opportunities and regular feedback discussions
- Company pension scheme
- Fitness area and lounge with kicker and gaming console in the office
- Team events and company parties
- free cold and hot beverages
This text has been machine translated. Show original
Benefits
Food & Drink
Health, Fitness & Fun
Work-Life-Integration
Topics that you deal with on the job
Job Locations
This is your employer
IQVIA
Wien
IQVIA is the world's leading provider of data, technology and analytics solutions that help healthcare customers achieve better outcomes. By working with IQVIA, our clients are able to harness today's most advanced technologies and techniques to drive innovation in healthcare - and human health as a whole. As a result, they are making breakthrough progress in areas like business efficiency and patient care.
Description
- Language
- English
- Company Type
- Established Company
- Working Model
- Full Remote, Hybrid, Onsite
- Industry
- Healthcare, Social Sector