Security Engineer - PenTest (m,f,x)
The role
We're seeking a new addition to our team, dedicated to upholding HelloFresh's reputation as a trusted entity. We need an individual who possesses a fervor for security and a hunger for tackling novel obstacles. As an Application Security Engineer, you'll engage in diverse strategies to consistently refine and enhance HelloFresh's security landscape.
What you’ll do- Perform or conduct threat modeling, secure code reviews, security architecture and design reviews
- Development of security automation tools
- Work on enhancing and tuning our SCA, SAST, and DAST tooling
- Support product and development teams in reproducing, triaging, and addressing security vulnerabilities
- Promote Shift-Left, DevSecOps culture, and contribute to security champions program by evangelizing security across the organization by mentoring and training other engineers
- Autonomously address security issues necessitating innovative techniques or novel approaches.
- Proven proficiency in one modern scripting language like Python, Go, and being able to perform code reviews to find security flaws with both manual and automated approach
- Decent exposure to Terraform, Docker, Kubernetes, CI/CD, Artifactory, and secrets management in microservices-based architectures
- Experience in designing and implementing security controls specific to modern development and deployment stack
- Experience working with Developers, DevOps, and Engineering teams in a dynamic environment to promote/implement the DevSecOps program throughout the organization
- Ability to work with APIs and Plugins to integrate security tools into established CI/CD pipelines
- Knowledge of some basic security libraries and tools, such as static analysis tools and proxying/pentesting tools
- Knowledge of, and aptitude for, describing typical security holes and how to fix them (e.g. OWASP Top 10, ASVS, MSVS, etc)
- Security by default and security by design mindset
- Experience in coordination with technical and non-technical stakeholders
Join one of Europe's fastest-growing tech powerhouses in a dynamic phase of expansion.
- Immerse yourself in a diverse global community of 90+ nationalities.
- Enjoy a competitive compensation package that goes beyond the norm, with perks like a HelloFresh- subsidized Pension Scheme , Berlin relocation support, and a Hybrid working model.
- Elevate your lifestyle with exclusive discounts on your weekly HelloFresh box and office meals.
- Plus, we've got your well-being covered with mental health support, transportation perks, and working-parent-friendly benefits. From our 24/7 gym access ,wellbeing platforms like Headspace and Spill , to sabbatical leave options, HelloFresh is not just a workplace; it's a lifestyle of perks and possibilities!