- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 8 hours ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
Envision yourself playing a crucial role in ensuring the security and reliability of our application, safeguarding the data of over 1,000,000 Lexware Office users. At the Web-App Security group, you'll face exciting and challenging problems, continuously learn emerging technologies, and develop valuable skills in a domain that is increasingly essential.
Team & Responsibilities
As a member of our Security Enablement team, you will support development teams in embedding security from planning through deployment. You'll be involved in integrating security controls, analyzing vulnerabilities, and responding to security-related queries.
Specifically, you will:
- Directly influence the enhancement of application security for a product used by more than 400,000 small and micro-businesses across Germany on a daily basis.
- Collaborate closely with feature teams to address security questions during conception, implementation, and operation phases, diving deep into technical details.
- Develop and maintain security mechanisms that span multiple teams.
- Enjoy opportunities for exploration and innovation, such as participating in "Hacking Days" and occasional after-work sessions.
- Work within an agile, modern environment utilizing practices like DevOps, Scrum, or Kanban.
Required Skills and Experience
- Strong knowledge and extensive experience in web application and cloud security, preferably with AWS.
- Proficient in securing modern web applications, including configuration, building, and releasing processes (Infrastructure as Code, CI/CD pipelines, Software Development Life Cycle).
- Ability to assess vulnerabilities within the context of the application and formulate actionable recommendations.
- Experience with Java web applications and JavaScript (TypeScript) web clients.
- Understanding of dependency management tools such as NPM and Gradle.
- Development experience with the ability to evaluate when automation is appropriate, writing Bash or Python scripts or other necessary tools accordingly.
- Familiarity with Threat Modeling concepts; skilled at collaboratively designing threat models and thinking like an adversary to identify potential risks.
- Excellent communication skills to convey vulnerabilities and security advice clearly and effectively to feature teams.
- Bonus: Prior experience in Incident Response.
- Exceptional German language skills (minimum C2 level) and strong English proficiency, as German is the language used within teams.
Work Culture and Team
- We practice team-based recruiting, with candidate interviews conducted by our Security Enablement team.
- Our colleagues have diverse interests, such as virtual machine experimentation, vulnerability research and Capture the Flag events, Linux administration, strength training, cooking, music, and coffee appreciation.
Additional Information
- Flexible work arrangements are supported, allowing remote work besides office presence.
- The role emphasizes a hands-on, constructive approach combining security expertise with collaboration and innovation.
- Job ID reference: REF347E.