IT Security Engineer (m/f/d) – Application Security, SBOM & CRA
You bring security into everyday development: from the first commit to a CRA-ready release – with VamiAppSec and VamiDAST.
Your responsibilities
- Integrate SAST, SCA, secrets, IaC and DAST scans (including Semgrep, Trivy, Grype, Gitleaks, Checkov and VamiDAST) into our clients' CI/CD pipelines
- Triage and assess findings, run reachability analyses and advise development teams on remediation
- Generate SBOMs (CycloneDX/SPDX), monitor vulnerabilities and prepare reporting obligations under CRA Art. 14
- Security reviews and assessments along OWASP ASVS, MASVS and SAMM, complemented by threat modeling
- Evolve VamiAppSec together with the product team
Your profile
- Several years of experience in application security, DevSecOps or security-focused software development
- In-depth knowledge of the OWASP Top 10 and ASVS, secure development processes and at least one programming language (e.g. Python, Java, TypeScript or Go)
- Hands-on experience with CI/CD (GitHub Actions, GitLab CI or Azure DevOps) and container and cloud environments
- Excellent German (at least C1) and good English
- A plus: knowledge of the CRA, IEC 62443-4-1 or ISO/SAE 21434 and certifications such as OSWE, GWEB or CSSLP
Application SecurityOWASP ASVSSASTDASTSBOMCRADevSecOps