Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
описание
Storio group operates an ecommerce platform.
задачи
Collaborate with engineers, architects, and product teams to turn security challenges into pragmatic solutions
Mentor engineers and Security Champions to embed security within the engineering culture
Build and enable security automation that improves security outcomes while reducing friction for engineering teams
Lead threat modelling and security architecture reviews for key products and technology initiatives
Experiment with and adopt AI tools to automate security engineering workflows and boost productivity
Define security principles, standards, patterns, and guardrails that enable engineers to build securely
Shape the strategic technical direction of Product Security across the platform and engineering organisation
Provide hands-on security expertise across APIs, microservices, AWS cloud infrastructure, authentication, authorisation, and software supply chain security
Identify and mitigate emerging security risks, including those introduced by AI, and communicate potential impact to senior stakeholders
Develop Product Security metrics to drive continuous security posture improvements
требования
5+ Years of experience in Product Security, Application Security, or Security Engineering in a modern software environment
Strong experience in security architecture and threat modelling, with the ability to turn risk into practical engineering solutions
Deep technical knowledge of application and API security, secure development practices, modern software architectures, and cloud-native systems
Experience embedding security controls into engineering workflows, software supply chains (SBOMs), and the software development lifecycle
Excellent communication skills and the ability to build trust and influence engineers, architects, and senior technical leaders without direct authority
Experience with or a strong interest in AI security and using AI tools to advance security engineering
Будет плюсом: Hands-on experience with Infrastructure as Code (IaC) security, scaling Security Champions programs, or managing Bug Bounty programs; relevant industry or cloud security certifications (e.g., CISSP, CSSLP, AWS Security Specialty)