At a Glance
- Tasks: Lead product security initiatives and solve complex technical challenges.
- Company: Join commercetools, a pioneer in innovative commerce solutions.
- Benefits: Comprehensive health benefits, learning opportunities, and equity participation.
- Why this job: Make a real impact on product security in a dynamic, hybrid environment.
- Qualifications: 5+ years in product security with leadership experience and strong technical skills.
- Other info: Diverse and inclusive workplace with excellent career growth potential.
The predicted salary is between 48000 - 72000 £ per year.
About Commercetools
Real innovation starts with a strong foundation, and at commercetools, that comes from the perfect balance of our product and our people. Behind every leap forward is a collective of builders, explorers, doers, makers, and problem-solvers. Together they are the engine of commerce innovation today. At commercetools, we power the next era of commerce for our customers.
Your Impact
As our Principal Engineer Product Security, you’ll support the Engineering team by solving challenging technical problems for an ambitious product and enabling teams to "shift left" to build secure services on multi-cloud infrastructure. You will:
- Formulate, evangelise, and drive adoption of the product security strategy
- Assess, advise on, and increase the security maturity posture
- Create a standardised security architecture and operational best practices
- Help track and drive remediation of security and technology risks
- Educate product teams on risk assessments, threat modelling, and building secure api-first applications
- Review requirements and designs to help product teams address shortcomings
- Embed security tooling into the development process
- Contribute to the review of external penetration tests and help teams prioritise fixes
- Collaborate with product teams to improve overall security and resolve specific issues
- Facilitate or lead customer conversations regarding product security
- Triage and investigate new attack vectors to determine risk mitigation
- Drive security and quality initiatives across the organization and support certification audits
- Collaborate with Product Management, Principal Engineers, and legal/compliance teams
- Identify skills gaps and facilitate knowledge sharing across the organization
This role is hybrid, with three days a week spent in our Berlin, London or Valencia office.
What Sets You Apart
You’re a creative problem-solver who is wired to find solutions. You confidently dive into complex challenges and have a talent for making them simple for others. Your curiosity drives you to constantly grow and contribute to an environment of trust and teamwork. What matters most is the mindset you bring to the work. You bring:
- A strong technical background and 5+ years of proven track record in hands-on Product Security
- 2+ years of experience improving Product Security in a leadership role
- Experience with customer-facing security roles and influencing roadmaps in matrix organizations
- Experience in a scale-up environment with ambitious and competing priorities
- Expertise in formulating, elaborating, and clarifying requirements or priorities
- Experience with Secure Architecture design reviews and Threat Modeling
- Experience infusing security into various levels of the SDLC
- Experience with Static Analysis and Secure Code Review implementations
- Sound knowledge of Linux systems, Kubernetes, Terraform, Vault, API, and web application security
- Project management experience for projects affecting multiple teams
- Experience working within an Agile environment with a strong customer focus
- Experience setting up and running trainings or onboardings
- Clear written and verbal communication in fluent English
AI Aptitude: A genuine curiosity for using AI tools to work smarter and more effectively, paired with a drive to learn and put them into practice in your role.
Nice to Have:
- Security Certifications such as CISSP, CCSP, Certified Kubernetes Security Specialist, or GCP/AWS/Azure security certifications
- An eagerness to constantly improve and learn about leadership and new technologies
Because work and life are connected, our benefits are too. We’ve designed them to give you the security, flexibility, and opportunities you need to focus on what matters most.
- Comprehensive health benefits for you and your dependents, including access to OpenUp for personalized mental health support
- Learning and development opportunities including an annual learning budget, access to self-paced learning platforms and language training, personalized coaching, mentorship, and leadership programs
- Family Leave Plus gives you additional fully paid weeks of parental leave on top of government-provided leave
- Our equity participation program allows you to share in our success
We proudly welcome applicants of every race, color, religion, gender identity, sexual orientation, age, and any other part of your identity that makes you who you are. As an equal opportunity employer, we believe that our strength lies in our diversity, and we invite you to be a part of our global community.
At commercetools, we are proud to be an equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements.
Principal Engineer, Product Security London, England, United Kingdom (Hybrid) employer: commercetools GmbH
Contact Detail:
commercetools GmbH Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Principal Engineer, Product Security London, England, United Kingdom (Hybrid)
✨Tip Number 1
Network like a pro! Reach out to folks in your industry on LinkedIn or at local meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repo showcasing your projects and contributions. This gives potential employers a taste of what you can do, especially in tech roles.
✨Tip Number 3
Prepare for interviews by practising common questions and scenarios related to product security. We recommend doing mock interviews with friends or using online platforms to boost your confidence.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team.
We think you need these skills to ace Principal Engineer, Product Security London, England, United Kingdom (Hybrid)
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Principal Engineer, Product Security role. Highlight your relevant experience in product security and how it aligns with our mission at commercetools. We want to see how you can contribute to our innovative culture!
Showcase Your Problem-Solving Skills: We love creative problem-solvers! In your application, share specific examples of how you've tackled complex challenges in product security. This will help us understand your approach and how you can drive security initiatives within our teams.
Be Clear and Concise: When writing your application, clarity is key. Use straightforward language and avoid jargon where possible. We appreciate a well-structured application that gets straight to the point, showcasing your skills and experiences effectively.
Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team at commercetools!
How to prepare for a job interview at commercetools GmbH
✨Know Your Stuff
Make sure you brush up on your technical knowledge, especially around product security. Be ready to discuss your experience with secure architecture design reviews and threat modelling, as these are key areas for the role.
✨Showcase Your Problem-Solving Skills
Prepare examples of how you've tackled complex challenges in previous roles. Highlight your creative problem-solving abilities and how you've simplified issues for others, as this aligns perfectly with what they’re looking for.
✨Understand the Company Culture
Familiarise yourself with commercetools' culture of experimentation and collaboration. Be prepared to discuss how you can contribute to this environment and share your unique perspective on building secure services.
✨Ask Insightful Questions
Prepare thoughtful questions that show your interest in the role and the company. Inquire about their current security initiatives or how they envision the future of product security at commercetools. This demonstrates your engagement and curiosity.