Software Engineer and Security Researcher

CommIT
Liebenburg, Germany
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Software Debugging Intrusion Detection and Prevention Cloud Platform System Large Language Models Cyber Threat Analysis Production Code
+2 more
Terraform Vulnerability Analysis

Job description

  • Design, build, and ship product features end-to-end: from security research to architecture and production code to release.
  • Apply cybersecurity expertise to every feature decision: what to detect, how to model risk, what makes a finding actionable, where customers will be misled by noise, and howto translate raw cloud signal into something a security team can trust and act on.
  • Own cloud security capabilities across CSPM and beyond: posture, identity, attack paths, severity/prioritization, detections, and emerging areas of the platform.
  • Drive AI into the development loop. Use coding agents and LLM tools as a core part of how you design, prototype, build, debug, review, and document. Write strong prompts, evaluate outputs critically, and turn AI-generated work into production-quality code and logic.
  • Move fast, with judgment. Make tradeoffs explicit, ship iteratively, and learn from real customer signals.
  • Collaborate closely with product, research, and engineering peers: clear written specs, sharp communication, clean handoffs, customer-facing rationale.

Requirements

  • 5+ years as a software engineer. You design systems, write production code, reason about reliability and edge cases, and own delivery end-to-end.
  • Strong cybersecurity foundation. You understand threats, controls, identity, cloud risk, and why a ā€œfindingā€ is or isn’t worth a customer’s attention. This is what makes your feature decisions land.
  • Hands-on experience developing with AI / AI-driven development. This is a MUST.
  • You have meaningfully shipped work where coding agents, LLM tools, or in-IDE AI assistants were a core part of how you built it. You can speak in detail about what worked, what didn’t, and how you got real leverage out of these tools.
  • Experience with at least one major cloud platform (AWS preferred; Azure or GCP also valid).
  • Comfortable operating at high pace: small batches, fast iteration, willingness to cut scope to ship, calm under pressure.
  • Strong communication: you can explain engineering and security tradeoffs to both technical and non-technical stakeholders.

Nice to Have:

  • Experience building CSPM/CNAPP products, cloud security detection/analytics pipelines, or other top-tier security products.
  • Experience building or fine-tuning AI-powered developer workflows: custom agents, pipelines, evals, internal AI tooling, prompt frameworks.
  • Familiarity with cloud telemetry/log sources and correlating security signals across configuration, identity, and activity.
  • Infrastructure-as-Code (e.g., Terraform) and cloud-native development experience.
  • Prior security research background: vulnerability research, threat research, or detection engineering.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on de.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis Ā· LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Ā· WWC 2022

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea Ā· WWC 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· WWC 2022

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao Ā· LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal Ā· LIVE

Videos

See all

Related articles

See all