Product Security / DevSecOps Engineer (all genders)

SWIAT GmbH
Frankfurt am Main, Germany
2 days ago
Apply on www.adzuna.de
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Kubernetes Security JavaScript (Programming Language) Amazon Web Services Software System Penetration Testing Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Computer Programming Continuous Integration Linux DevOps
+29 more
Identity and Access Management Information Technology Operations Python (Programming Language) Key Management Public Key Infrastructure Ansible Blockchain Secure Coding Security Software Software Engineering Systems Integration TypeScript Software Vulnerability Management Scripting Cloud Platform System Delivery Pipeline Software Security Gitlab Git Kubernetes Information Technology Ethereum CIS Benchmarks Terraform Devsecops Security Orchestration, Automation & Response Static Application Security Testing Golang Dynamic Application Security Testing

Job description

As a Product Security / DevSecOps Engineer, you are part of SWIAT’s DevOps team and you will strengthen security across SWIAT’s software development and IT operations.

You will work closely with our Development teams and take technical ownership of security throughout the software development lifecycle, from architecture and implementation to CI/CD, cloud infrastructure and production operations.

This is a hands-on engineering role. You will establish security practices, implement security tooling and controls, identify vulnerabilities and help our engineering teams build and operate secure financial market infrastructure.

Your Tasks and Responsibilities Include

  • Establishing and continuously improving our Secure Software Development Lifecycle (SSDLC)
  • Performing security architecture reviews and threat modelling for applications and infrastructure
  • Integrating security controls and automated security testing into CI/CD pipelines
  • Implementing and operating SAST, DAST, Software Composition Analysis (SCA), container and infrastructure scanning
  • Managing technical vulnerabilities and supporting engineering teams with remediation
  • Hardening Kubernetes, container, Linux and cloud environments
  • Reviewing Infrastructure as Code and Kubernetes configurations from a security perspective
  • Designing and improving IAM, secrets management, KMS/HSM and PKI concepts
  • Defining and implementing security baselines for applications and infrastructure
  • Supporting secure software supply chain practices, including dependency management and SBOM
  • Coordinating penetration tests and supporting remediation of identified findings
  • Supporting technical investigation and response to security incidents
  • Advising Development, DevOps and Architecture teams on technical security topics
  • Increasing security awareness within engineering teams through guidelines, reviews and knowledge sharing
  • Supporting security-related requirements arising from ISO 27001, DORA and our financial-industry environment

Requirements

  • BA/MA in Computer Science, Information Security, Software Engineering or a comparable field, or equivalent professional experience
  • Several years of hands-on experience in DevSecOps, Product Security, Application Security or Security Engineering
  • Strong software engineering or DevOps background
  • Experience securing production environments and modern software delivery pipelines

Skills & Competencies

  • Secure Software Development Lifecycle and secure coding practices
  • Threat modelling and security architecture
  • CI/CD security and security automation
  • SAST, DAST and Software Composition Analysis
  • Vulnerability management
  • Kubernetes and container security
  • Linux and networking
  • Cloud security, preferably Azure and/or AWS
  • IAM and secrets management
  • Strong understanding of applied cryptography, KMS, HSM and PKI concepts
  • Infrastructure as Code, preferably Terraform and Ansible
  • Git-based development and CI/CD environments, preferably Gitlab
  • Software supply chain security and SBOM concepts
  • Programming or scripting experience, preferably JavaScript / TypeScript, Python, Go or similar
  • ISO 27001 and DORA knowledge is a strong advantage
  • Experience in financial services or regulated environments is a strong advantage
  • Blockchain and Ethereum/EVM security knowledge is a plus
  • Good English skills

️ Please be advised that a valid work permit for Germany is required for non-EU citizens. Unfortunately, applications without a valid working permit and sufficient language skills will not be considered.

Benefits & conditions

SWIAT GmbH is a Frankfurt-based FinTech building next-generation financial market infrastructure using Distributed Ledger Technology (DLT). Our mission is to enable secure, compliant, and efficient issuance, trading, settlement, and servicing of digital and traditional financial assets on a global scale.

What do we do?

  • Coordinate and operate the SWIAT Network and Platform, a secure and trusted DLT-based financial infrastructure
  • Enable the issuance and lifecycle management of regulated digital assets
  • Support the tokenisation and mobilization of traditional financial instruments and collateral
  • Deliver solutions tailored to banks, financial institutions, and capital market participants
  • Drive innovation in digital securities, settlement, and collateral management

Place of Work and Compensation

Our office is located in the centre of Frankfurt. We support flexible and hybrid working models and value regular in-person collaboration to maintain strong team connections.

We offer a competitive compensation package together with additional employee benefits.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.de
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all