> Markdown version of [/jobs/ext/1209741-software-engineer-and-security-researcher](https://www.wearedevelopers.com/jobs/ext/1209741-software-engineer-and-security-researcher). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer and Security Researcher - **Company:** CommIT - **Location:** Liebenburg, Germany (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Software Debugging, Intrusion Detection and Prevention, Cloud Platform System, Large Language Models, Cyber Threat Analysis, Production Code, Terraform, Vulnerability Analysis - **Published:** July 9, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=f85f32e3c3263aa8 ## About the Role * 5+ years as a software engineer. You design systems, write production code, reason about reliability and edge cases, and own delivery end-to-end. * Strong cybersecurity foundation. You understand threats, controls, identity, cloud risk, and why a "finding" is or isn't worth a customer's attention. This is what makes your feature decisions land. * Hands-on experience developing with AI / AI-driven development. This is a MUST. * You have meaningfully shipped work where coding agents, LLM tools, or in-IDE AI assistants were a core part of how you built it. You can speak in detail about what worked, what didn't, and how you got real leverage out of these tools. * Experience with at least one major cloud platform (AWS preferred; Azure or GCP also valid). * Comfortable operating at high pace: small batches, fast iteration, willingness to cut scope to ship, calm under pressure. * Strong communication: you can explain engineering and security tradeoffs to both technical and non-technical stakeholders. Nice to Have: * Experience building CSPM/CNAPP products, cloud security detection/analytics pipelines, or other top-tier security products. * Experience building or fine-tuning AI-powered developer workflows: custom agents, pipelines, evals, internal AI tooling, prompt frameworks. * Familiarity with cloud telemetry/log sources and correlating security signals across configuration, identity, and activity. * Infrastructure-as-Code (e.g., Terraform) and cloud-native development experience. * Prior security research background: vulnerability research, threat research, or detection engineering. ## Description * Design, build, and ship product features end-to-end: from security research to architecture and production code to release. * Apply cybersecurity expertise to every feature decision: what to detect, how to model risk, what makes a finding actionable, where customers will be misled by noise, and howto translate raw cloud signal into something a security team can trust and act on. * Own cloud security capabilities across CSPM and beyond: posture, identity, attack paths, severity/prioritization, detections, and emerging areas of the platform. * Drive AI into the development loop. Use coding agents and LLM tools as a core part of how you design, prototype, build, debug, review, and document. Write strong prompts, evaluate outputs critically, and turn AI-generated work into production-quality code and logic. * Move fast, with judgment. Make tradeoffs explicit, ship iteratively, and learn from real customer signals. * Collaborate closely with product, research, and engineering peers: clear written specs, sharp communication, clean handoffs, customer-facing rationale. ## Related Videos - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)