Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
- PSI Software SE Grid & Energy Management
- IT Security
- Full-time
Tasks that will inspire you
As a software developer for critical infrastructure in the energy sector, we develop products whose security plays a decisive role in ensuring the reliability of entire networks. With the Cyber Resilience Act and our certification to IEC 62443-4-1, security is evolving from a technical feature to a regulatory requirement for market access.
We are filling a key position that holds technical responsibility for security in the product development of our “Grid & Energy Management (GEM)” product development. You will not work in a single development team but rather as a cross-functional enabler (m/f/d) for approximately 300 developers at locations in Germany and Poland. The role reports directly to the SVP of Engineering and offers high visibility and creative freedom. Your guiding principle is empowerment and setting standards across the entire development organization, rather than day-to-day hands-on implementation in the code.
Secure Software Development Lifecycle (sSDLC):
- You define, establish, and measure sSDLC practices as mandatory standards across all GEM product development teams.
- You define security gates in the CI/CD pipeline and are responsible for their design and enforcement.
Security Champions Program:
- You will build a network of designated Security Champions within the agile teams and provide technical leadership for this group.
- You will develop training programs and playbooks and empower the Champions to work independently within their teams.
Threat Modeling & Security Governance:
- You provide methodologies, templates, and training for threat modeling and review security-critical models together with our Solution Architect.
- You will advise Solution Architects and Product Management on security-related architecture and roadmap decisions.
Vulnerability & SBOM Management:
- You are responsible for the product vulnerability management process, including CVE triage and the prioritization of mitigation measures.
- You define policies and thresholds for SBOM creation as well as the assessment of open-source and third-party components.
- You ensure process capability for the CRA’s regulatory reporting requirements.
Regulatory Evidence Management:
- You are responsible for the security-related evidence required for certification according to IEC 62443-4-1 and for CRA-compliant technical documentation.
- You support customer audits on the product development side.
Management of Security Testing:
- You define the tooling strategy for SAST, DAST, and dependency scanning and oversee their implementation.
- You commission and manage external penetration tests and are responsible for tracking up on the findings.
Interfaces:
- You will work closely with Solution Architects, Product Management, Operations & Support, and company-wide Security Governance (CISO), and provide advisory support for product-related security incidents., Note: Depending on the specific (project) assignment, work may be required at customer sites involving critical infrastructure (KRITIS). In such cases, an extended security clearance (Ü2 - preventive personnel sabotage protection) is required by law pursuant to Section 9 in conjunction with Section 1(4) of the SÜG. Willingness to undergo this screening is an explicit requirement. The SÜG relevance in each individual case is assessed by the sabotage protection officer prior to the respective client assignment.
Requirements
- Professional Experience: You have several years of professional experience in product security, application security, or security engineering, including proven experience in a cross-functional, team-independent role.
- Secure by Design: You have in-depth knowledge of Secure-by-Design principles and secure software development processes (sSDLC).yse43
- Threat Modeling: Practical experience with threat modeling (e.g., STRIDE) and risk assessment methods is second nature to you.
- Security Champions Program: Ideally, you have experience setting up a Security Champions Program or a comparable influencer model.
- Vulnerability Management: You have experience in vulnerability management: CVE assessment, SBOM (CycloneDX / SPDX).
- Security Testing: You have a solid understanding of security testing tools (SAST, DAST, SCA) and their integration into CI/CD pipelines, and can define a tooling strategy based on this knowledge.
- Standards & Compliance: You have a solid understanding of relevant standards and regulations, particularly IEC 62443, the Cyber Resilience Act, ISO 27001, and the OWASP Top 10.
- Persuasiveness: You know how to persuade others and win teams over to the cause of security without having disciplinary authority.
- Communication: You possess excellent communication skills to explain complex security topics in a way that non-security professionals can understand.
- Language Skills: You are fluent in English; knowledge of German is a plus.
- Industry Experience: Ideally, you have experience in the KRITIS sector, the energy industry, or similarly regulated industries.
- Champion Programs: Knowledge of setting up a security champion program or similar champion models is a plus.
- Audits & Certifications: Ideally, you have experience supporting certification or audit processes (IEC 62443-4-1, ISO 27001).
- Cloud & Container Security: Knowledge of cloud and container security (Kubernetes, Docker, hardening baselines) is desirable.
- Certifications: Relevant certifications (e.g., CSSLP, GIAC, OSCP) are welcome but not required.
Benefits & conditions
- Team events
- Flexible work hours
- Corporate benefits
- Remote work
- Development & Training
About the company
PSI Software SE Grid & Energy Management Berlin, , 10719
The PSI Group develops software products to optimize energy and material flows for utilities and industry. As an independent software manufacturer with over 2,300 employees, PSI has been a technology leader since 1969 in process control systems that ensure sustainable energy supply, production, and logistics by combining AI methods with industry-proven optimization techniques. These innovative industry-specific products can be operated by the customer on-premises or in the cloud.
The Grid & Energy Management business unit specializes in the development of software solutions for the energy sector. Our portfolio includes intelligent solutions for grid operators in the electricity, gas, heat, oil, and water sectors. Our focus is on modern grid control systems and energy trading software for the energy market.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The 12 Best Jobs for Software Engineers
The Ultimate Software Engineer Career Path Guide for 2023
Where To Find Software Engineering Jobs
Is Software Engineering Over-Saturated?