{
    "componentChunkName": "component---src-templates-post-js",
    "path": "/jobs/565815/",
    "result": {"data":{"selectedJobQuery":{"guid":"565815","title":"Security Engineer - (Application Security/DevSecOps) (f/m/d) at Delivery Hero SE (Berlin, Germany)","content":"<p><strong>Want to be a Hero? - Join one of the leading global online food ordering and delivery platforms!</strong></p><br /><p>We are looking for a <strong>Security Engineer - (Application Security/DevSecOps) (f/m/d) </strong>to join our team and reinvent on-demand delivery with us. If you're a creative problem solver who is eager to deliver solutions and hungry for a new adventure, an international workplace is waiting for you in the heart of Berlin!</p><br /><p><strong>Your Mission:</strong></p><br /><ul><br /><li><br /><p>The DevSecOps Engineer will support the integration of the security solutions in other SaaS, PaaS, IaaS and on-premise components to foster a high-security posture for our hybrid infrastructure.</p><br /></li><br /><li><br /><p>Develop and integrate new modules in the security management system.</p><br /></li><br /><li><br /><p>This function is moreover responsible for the monitoring and the implementation of automation for the security solutions as well as the definition of measures based on these activities.</p><br /></li><br /><li><br /><p>Champion security with development teams to make their code more secure, primarily through manual code/architecture review.</p><br /></li><br /><li><br /><p>Perform security assessments on a wide range of developed applications services and networks.</p><br /></li><br /><li><br /><p>Conduct security-centric code reviews of new and legacy applications and services to identify security vulnerabilities.</p><br /></li><br /><li><br /><p>Collaborate with the responsible engineers to resolve identified security weaknesses.</p><br /></li><br /><li><br /><p>Create, implement and maintain security automation tools as required.</p><br /></li><br /><li><br /><p>Develop secure coding resources for engineers ranging from wiki articles to master classes covering both standardized topics like OWASP Top 10 to custom tailored content to address common issues.</p><br /></li><br /><li><br /><p>Provide security event analysis and escalation for identified threats.</p><br /></li><br /></ul><br /><p><br> </p><br /><p><strong>Your Heroic Skills:</strong></p><br /><p><strong>Must Haves:</strong></p><br /><ul><br /><li><br /><p>Full DevSecOps practice integrating Github/Gitlab based version control, automated builds, and release management CI/CD.</p><br /></li><br /><li><br /><p>Working knowledge in Security Management Systems (e.g. ServiceNow, Archer) </p><br /></li><br /><li><br /><p>Proficiency and break code in languages including Python, Java, C/C++ and PHP.</p><br /></li><br /><li><br /><p>Experience in security tooling &amp; technologies (e.g. IDS, AWS or GCP security configurations/setup, Linux security configurations/setups, etc.)</p><br /></li><br /><li><br /><p>Familiarity with one or more cloud vendor services and management tools (AWS, GCP) and DevSecOps processes i.e. code pipeline.</p><br /></li><br /><li><br /><p>+2 years experience in agile development.</p><br /></li><br /><li><br /><p>+2 years of experience PostgrestSQL, MongoDb or similar.</p><br /></li><br /><li><br /><p>+2 years of experience of deployment and management of public cloud security services (AWS, GCP) like VPC Service Controls, Shielded VMs, CAs, CMKs, Security Hub, Cloudwatch, Cloudtrail, Secrets Manager and IAM.</p><br /></li><br /><li><br /><p>Experience in security tooling &amp; technologies (e.g. IDS, AWS or GCP security configurations/setup, Linux security configurations/setups, etc.)</p><br /></li><br /><li><br /><p>Designing and implementing system integration patterns in the public cloud (AWS,GCP), network and service security, and CICD pipelines and Infrastructure as Code (IaC) including Cloudformation and Terraform.</p><br /></li><br /><li><br /><p>Working knowledge of common application and network security assessment tools and techniques such as nmap, nessus, burpsuite, etc. </p><br /></li><br /><li><br /><p>Experience with vulnerability management (identifying, tracking, prioritizing, and collaboration with responsible teams to resolve).</p><br /></li><br /><li><br /><p>Extensive experience working with distributed systems, including deep understanding of UDP &amp; TCP protocols.</p><br /></li><br /><li><br /><p>Knowledge of network and web related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols).</p><br /></li><br /><li><br /><p>Security implementation experience (OWASP, SAST, DAST&hellip;etc.)</p><br /></li><br /><li><br /><p>Network stack/protocols, SSO, oAUTH2 and DNS.</p><br /></li><br /><li><br /><p>Experience working with both internal and external stakeholders</p><br /></li><br /><li><br /><p>Enjoys working in an accomplishment-oriented, fast-paced environment.</p><br /></li><br /><li><br /><p>Fluency in English (verbal and written).</p><br /></li><br /></ul><br /><br /><p><strong>Nice to Have:</strong></p><br /><ul><br /><li><br /><p>AWS or GCP certification is a plus.</p><br /></li><br /><li><br /><p>Experience working with network security and analysis tools such as IDS/IPS, sniffers, WAFs, firewall ACLs is a plus.</p><br /></li><br /><li><br /><p>Working history of performing security assessments in cloud environments is a plus.</p><br /></li><br /><li><br /><p>Experience of working in a federated organization.</p><br /></li><br /><li><br /><p>Certifications like OSCP, OSCE are also a plus.</p><br /></li><br /></ul>","applyUrl":"https://careers.deliveryhero.com/global/en/job/JR0020929/Security-Engineer-Application-Security-DevSecOps-f-m-d","link":"https://stackoverflow.com/jobs/565815/security-engineer-application-security-delivery-hero-se?a=33KV9cYdsFig&so_medium=Talent&so_source=TalentApi","categories":["python","devsecops","archer","servicenow","application-security"],"companyLogo":"delivery-hero-se.png","isoDate":"2022-01-11T13:56:42.000Z","author":{"name":["Delivery Hero SE"]},"country":"Germany"}},"pageContext":{"guid":"565815"}},
    "staticQueryHashes": ["823517391"]}