Security Engineer - PenTest (m,f,x)

Full Time
Berlin, Germany
3 months ago
The role

We're seeking a new addition to our team, dedicated to upholding HelloFresh's reputation as a trusted entity. We need an individual who possesses a fervor for security and a hunger for tackling novel obstacles. As an Application Security Engineer, you'll engage in diverse strategies to consistently refine and enhance HelloFresh's security landscape.

What you’ll do
  • Perform or conduct threat modeling, secure code reviews, security architecture and design reviews
  • Development of security automation tools
  • Work on enhancing and tuning our SCA, SAST, and DAST tooling
  • Support product and development teams in reproducing, triaging, and addressing security vulnerabilities
  • Promote Shift-Left, DevSecOps culture, and contribute to security champions program by evangelizing security across the organization by mentoring and training other engineers
  • Autonomously address security issues necessitating innovative techniques or novel approaches.
What you’ll bring
  • Proven proficiency in one modern scripting language like Python, Go, and being able to perform code reviews to find security flaws with both manual and automated approach
  • Decent exposure to Terraform, Docker, Kubernetes, CI/CD, Artifactory, and secrets management in microservices-based architectures
  • Experience in designing and implementing security controls specific to modern development and deployment stack
  • Experience working with Developers, DevOps, and Engineering teams in a dynamic environment to promote/implement the DevSecOps program throughout the organization
  • Ability to work with APIs and Plugins to integrate security tools into established CI/CD pipelines
  • Knowledge of some basic security libraries and tools, such as static analysis tools and proxying/pentesting tools
  • Knowledge of, and aptitude for, describing typical security holes and how to fix them (e.g. OWASP Top 10, ASVS, MSVS, etc)
  • Security by default and security by design mindset
  • Experience in coordination with technical and non-technical stakeholders
What we offer

Join one of Europe's fastest-growing tech powerhouses in a dynamic phase of expansion.

  • Immerse yourself in a diverse global community of 90+ nationalities.
  • Enjoy a competitive compensation package that goes beyond the norm, with perks like a HelloFresh- subsidized Pension Scheme , Berlin relocation support, and a Hybrid working model.
  • Elevate your lifestyle with exclusive discounts on your weekly HelloFresh box and office meals.
  • Plus, we've got your well-being covered with mental health support, transportation perks, and working-parent-friendly benefits. From our 24/7 gym access ,wellbeing platforms like Headspace and Spill , to sabbatical leave options, HelloFresh is not just a workplace; it's a lifestyle of perks and possibilities!