NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs
1 day ago
Apply with autofill
Apply with autofill
Aras·1 day ago
1 day ago

Product Security Engineer (m/f/d)

PolandFull-timeMid · 2-5 yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at aras

How you compare FREE

?
Your scoreYour score: not yet known
→
62
Top 10%Top 10%: 62 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in Poland.

Must-have skills for this role

  • jenkins
  • kubernetes
  • sast
  • dast

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Design, develop, and maintain secure CI/CD pipelines using Jenkins, Kubernetes, Azure, and cloud-native technologies.
  • Integrate security controls and automated security testing into the software delivery lifecycle.
  • Implement and manage SAST, DAST, SCA, secrets detection, IaC scanning, container security, and software supply chain security controls.
  • Drive security automation initiatives to reduce manual effort and accelerate secure software delivery.
  • Document and verify the existing security mitigations and identify if additional mitigations are required for our products.
  • Work with product development teams to guide mitigation development.
  • Contribute to the development and implementation of security tests and verification protocols. Assist in conducting security verification and validation efforts.
  • Collaborate with product, development, and cloud engineering teams to embed security requirements throughout the SDLC.
  • Conduct security reviews of applications, infrastructure, CI/CD workflows, and deployment architectures.
  • Support threat modeling, risk assessments, and secure design reviews.
  • Help establish security baselines, hardening standards, and secure deployment practices.
  • Develop automation solutions using Python, PowerShell, Bash, or Groovy.

What they're looking for

  • 4+ years of hands-on experience with Jenkins or similar CI/CD platforms.
  • 3+ years of software development, automation, or scripting experience using Python, PowerShell, Bash, or equivalent languages.
  • Experience integrating security tooling into CI/CD pipelines, including SAST, DAST, SCA, container scanning, and secrets management.
  • Working knowledge of cloud security principles and services in Azure and/or AWS.
  • Understanding of containerized environments and Kubernetes security concepts.
  • Experience collaborating with engineering teams in Agile development environments.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Self-motivated with the ability to work independently and manage multiple priorities.
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or equivalent practical experience.

Nice to have

  • Experience with Infrastructure as Code (Terraform, Bicep, CloudFormation).
  • Experience with Azure DevOps pipelines and security integrations.
  • Familiarity with software supply chain security practices and frameworks (SBOM, SLSA, Sigstore, provenance validation).
  • Experience securing Kubernetes and cloud-native platforms.
  • Familiarity with AI-assisted development tools and secure AI engineering practices.
  • Knowledge of security frameworks such as NIST SSDF, OWASP SAMM, OWASP ASVS, and CIS Benchmarks.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Aras is a leading provider of digital thread solutions for product lifecycle management (PLM) and engineering AI. As one of the fastest growing PLM companies, our AI-native, low-code platform enables the rapid delivery of flexible solutions that connect teams across disciplines and functions to critical product data and agentic AI throughout the product lifecycle and extended value chain.

The world's largest manufacturers leverage Aras Innovator to manage complex product lifecycles, accelerate innovation, improve operational efficiency, and bring products to market faster. We collaborate with companies in some of the world's most innovative industries, including automotive, industrial equipment, aerospace and defense, high tech, and life sciences.


Aras is expanding its Product Security team and is seeking a Product Security Engineer with strong DevOps expertise to help secure our products, cloud platforms, and software development lifecycle. This role will be responsible for designing, implementing, and maintaining secure CI/CD pipelines, integrating security controls throughout the development process, and driving a security-first engineering culture across product and cloud teams.


Part of the responsibilities would be the response to incidents, triage of found issues and communication with Product Development team on daily basis. As part of the Product Security organization, you will partner closely with software engineers, cloud architects, DevOps teams, and security stakeholders to identify, prioritize, and remediate security risks at scale. You will play a key role in advancing Aras' Security maturity. This position requires strong technical expertise, excellent communication skills, and hands-on experience integrating SAST, DAST, SCA, container security, and cloud security controls into modern CI/CD environments.



Key Responsibilities
DevSecOps Engineering
• Design, develop, and maintain secure CI/CD pipelines using Jenkins, Kubernetes, Azure, and cloud-native technologies.
• Integrate security controls and automated security testing into the software delivery lifecycle.
• Implement and manage SAST, DAST, SCA, secrets detection, IaC scanning, container security, and software supply chain security controls.
• Drive security automation initiatives to reduce manual effort and accelerate secure software delivery.
• Document and verify the existing security mitigations and identify if additional mitigations are required for our products.
• Work with product development teams to guide mitigation development.
• Contribute to the development and implementation of security tests and verification protocols. Assist in conducting security verification and validation efforts.


Product Security
• Collaborate with product, development, and cloud engineering teams to embed security requirements throughout the SDLC.
• Conduct security reviews of applications, infrastructure, CI/CD workflows, and deployment architectures.
• Support threat modeling, risk assessments, and secure design reviews.
• Help establish security baselines, hardening standards, and secure deployment practices.


Engineering & Collaboration
• Develop automation solutions using Python, PowerShell, Bash, or Groovy.
• Provide expertise in Agile.
• Participate in daily standups, sprint planning, retrospectives, and collaborative design sessions.
• Continuously evaluate new tools, technologies, and approaches to improve security effectiveness and developer experience.


Required Qualifications
• 4+ years of hands-on experience with Jenkins or similar CI/CD platforms.
• 3+ years of software development, automation, or scripting experience using Python, PowerShell, Bash, or equivalent languages.
• Experience integrating security tooling into CI/CD pipelines, including SAST, DAST, SCA, container scanning, and secrets management.
• Working knowledge of cloud security principles and services in Azure and/or AWS.
• Understanding of containerized environments and Kubernetes security concepts.
• Experience collaborating with engineering teams in Agile development environments.
• Strong analytical, troubleshooting, and problem-solving skills.
• Self-motivated with the ability to work independently and manage multiple priorities.
• Bachelor’s degree in computer science, Information Technology, Cybersecurity, or equivalent practical experience.


Preferred Qualifications
• Experience with Infrastructure as Code (Terraform, Bicep, CloudFormation).
• Experience with Azure DevOps pipelines and security integrations.
• Familiarity with software supply chain security practices and frameworks (SBOM, SLSA, Sigstore, provenance validation).
• Experience securing Kubernetes and cloud-native platforms.
• Familiarity with AI-assisted development tools and secure AI engineering practices.
• Knowledge of security frameworks such as NIST SSDF, OWASP SAMM, OWASP ASVS, and CIS Benchmarks.


Certifications
One or more of the following certifications are highly desirable:
• Microsoft Certified: Azure Security Engineer Associate
• Microsoft Certified: DevOps Engineer Expert
• Certified Kubernetes Security Specialist (CKS)
• Certified Kubernetes Administrator (CKA)


What Success Looks Like
• Security controls are seamlessly integrated into engineering workflows with minimal developer friction.
• Vulnerabilities are identified and remediated earlier in the SDLC.
• Security testing and compliance checks are automated wherever possible.
• Product teams actively embrace DevSecOps and secure-by-design principles.
• Security becomes an engineering accelerator rather than a deployment bottleneck.

Company

Aras
Poland

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Aras's careers site·first seen 21 Sept 2026·last verified 21 Sept 2026·How we source jobs

Similar jobs

  • Principal Security Engineer at simcorpWarsaw, Poland–match not yet calculated
  • Security Engineer at solvdPoland–match not yet calculated
  • Senior Security Engineer (AI) at Sopra SteriaKatowice, Poland–match not yet calculated
  • Cybersecurity Engineer – Cryptography & Key Management (f/m) at woodwardNiepolomice, Poland–match not yet calculated
  • Analyst - Cybersecurity (Security Administration) at syscoSysco Poland, Poland–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United States
  • Security Engineer jobs in India
  • Security Engineer jobs in United Kingdom
  • Retail Sales Associate jobs in United States