Security Engineer (m/w/d)
- Status
- Open
- Remote policy
- Not stated
- Employment type
- Not stated
- Salary
- 45,000-75,000 EUR / year
- Source
- germantechjobs
- First observed
- 2026-09-07 08:29 UTC
- Last seen
- 2026-09-07 08:29 UTC
- Source claims posted
- 2026-09-07 06:38 UTC
- Consecutive misses
- 0 of 3
What the posting says
Salary: 45.000 - 75.000 € per year
Requirements:
Several years of professional experience in product security, application security, or security engineering, including proven experience in a cross-functional, team-independent role.
In-depth knowledge of Secure-by-Design principles and secure software development processes (sSDLC).
Practical experience with threat modeling (e.g., STRIDE) and risk assessment methods.
Ideally, experience setting up a Security Champions Program or a comparable influencer model.
Experience in vulnerability management: CVE assessment, SBOM (CycloneDX / SPDX).
Solid understanding of security testing tools (SAST, DAST, SCA) and their integration into CI/CD pipelines, and ability to define a tooling strategy based on this knowledge.
Solid understanding of relevant standards and regulations, particularly IEC 62443, the Cyber Resilience Act, ISO 27001, and the OWASP Top 10.
Ability to persuade others and win teams over to the cause of security without disciplinary authority.
Excellent communication skills to explain complex security topics in a way that non-security professionals can understand.
Fluent in English; knowledge of German is a plus.
Ideally, experience in the KRITIS sector, the energy industry, or similarly regulated industries.
Knowledge of setting up a security champion program or similar champion models is a plus.
Ideally, experience supporting certification or audit processes (IEC 62443-4-1, ISO 27001).
Knowledge of cloud and container security (Kubernetes, Docker, hardening baselines) is desirable.
Relevant certifications (e.g., CSSLP, GIAC, OSCP) are welcome but not required.
Responsibilities:
Define, establish, and measure sSDLC practices as mandatory standards across all GEM product development teams.
Define security gates in the CI/CD pipeline and be responsible for their design and enforcement.
Build a network of designated Security Champions within the agile teams and provide technical leadership for this group.
Develop training programs and playbooks and empower the Champions to work independently within their teams.
Provide methodologies, templates, and training for threat modeling and review security-critical models together with our Solution Architect.
Advise Solution Architects and Product Management on security-related architecture and roadmap decisions.
Be responsible for the product vulnerability management process, including CVE triage and the prioritization of mitigation measures.
Define policies and thresholds for SBOM creation as well as the assessment of open-source and third-party components.
Ensure process capability for the CRAs regulatory reporting requirements.
Be responsible for the security-related evidence required for certification according to IEC 62443-4-1 and for CRA-compliant technical documentation.
Support customer audits on the product development side.
Define the tooling strategy for SAST, DAST, and dependency scanning and oversee their implementation.
Commission and manage external penetration tests and be responsible for following up on the findings.
Work closely with Solution Architects, Product Management, Operations & Support, and company-wide Security Governance (CISO), and provide advisory support for product-related security incidents.
Technologies:
AI
Architect
CI/CD
Cloud
Docker
Support
Kubernetes
Network
OWASP
Security
More:
We at PSI Group develop software products to optimize energy and material flows for utilities and industry. As an independent software manufacturer with over 2,300 employees, we have been a technology leader since 1969 in process control systems that ensure sustainable energy supply, production, and logistics by combining AI methods with industry-proven optimization techniques. Our innovative industry-specific products can be operated by the customer on-premises or in the cloud. Our Grid & Energy Management business unit specializes in software solutions for the energy sector, with intelligent solutions for grid operators in the electricity, gas, heat, oil, and water sectors, and a focus on modern grid control systems and energy trading software for the energy market. This full-time Security Engineer role is based in Aschaffenburg, Berlin, or Dortmund and sits within PSI Software SE Grid & Energy Management. We offer accident insurance, team events, flexible work hours, corporate benefits, remote work, and development & training.
last updated 36 week of 2026
Quality
- + Salary range stated weight 35%
- x Remote policy stated weight 20%
- x Location stated weight 15%
- + Organisation stated weight 15%
- + Publication date stated weight 15%
Not enough history yet to judge honesty signals.
Timeline
-
*
#613861 2026-09-07 08:29 UTCPublished