> Markdown version of [/jobs/ext/2699880-security-engineer](https://www.wearedevelopers.com/jobs/ext/2699880-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Psi Software Ag - **Location:** Berlin, Germany (Remote available) - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Software System Penetration Testing, Cloud Computing, Cyber Security, Continuous Integration, Open Source Technology, Open Web Application Security, Software Engineering, Software Vulnerability Management, Software Security, Kubernetes, Docker, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://www.adzuna.de/details/5867176882 ## About the Role * Professional Experience: You have several years of professional experience in product security, application security, or security engineering, including proven experience in a cross-functional, team-independent role. * Secure by Design: You have in-depth knowledge of Secure-by-Design principles and secure software development processes (sSDLC).yse43 * Threat Modeling: Practical experience with threat modeling (e.g., STRIDE) and risk assessment methods is second nature to you. * Security Champions Program: Ideally, you have experience setting up a Security Champions Program or a comparable influencer model. * Vulnerability Management: You have experience in vulnerability management: CVE assessment, SBOM (CycloneDX / SPDX). * Security Testing: You have a solid understanding of security testing tools (SAST, DAST, SCA) and their integration into CI/CD pipelines, and can define a tooling strategy based on this knowledge. * Standards & Compliance: You have a solid understanding of relevant standards and regulations, particularly IEC 62443, the Cyber Resilience Act, ISO 27001, and the OWASP Top 10. * Persuasiveness: You know how to persuade others and win teams over to the cause of security without having disciplinary authority. * Communication: You possess excellent communication skills to explain complex security topics in a way that non-security professionals can understand. * Language Skills: You are fluent in English; knowledge of German is a plus. * Industry Experience: Ideally, you have experience in the KRITIS sector, the energy industry, or similarly regulated industries. * Champion Programs: Knowledge of setting up a security champion program or similar champion models is a plus. * Audits & Certifications: Ideally, you have experience supporting certification or audit processes (IEC 62443-4-1, ISO 27001). * Cloud & Container Security: Knowledge of cloud and container security (Kubernetes, Docker, hardening baselines) is desirable. * Certifications: Relevant certifications (e.g., CSSLP, GIAC, OSCP) are welcome but not required. ## Description * PSI Software SE Grid & Energy Management * IT Security * Full-time Tasks that will inspire you As a software developer for critical infrastructure in the energy sector, we develop products whose security plays a decisive role in ensuring the reliability of entire networks. With the Cyber Resilience Act and our certification to IEC 62443-4-1, security is evolving from a technical feature to a regulatory requirement for market access. We are filling a key position that holds technical responsibility for security in the product development of our "Grid & Energy Management (GEM)" product development. You will not work in a single development team but rather as a cross-functional enabler (m/f/d) for approximately 300 developers at locations in Germany and Poland. The role reports directly to the SVP of Engineering and offers high visibility and creative freedom. Your guiding principle is empowerment and setting standards across the entire development organization, rather than day-to-day hands-on implementation in the code. Secure Software Development Lifecycle (sSDLC): * You define, establish, and measure sSDLC practices as mandatory standards across all GEM product development teams. * You define security gates in the CI/CD pipeline and are responsible for their design and enforcement. Security Champions Program: * You will build a network of designated Security Champions within the agile teams and provide technical leadership for this group. * You will develop training programs and playbooks and empower the Champions to work independently within their teams. Threat Modeling & Security Governance: * You provide methodologies, templates, and training for threat modeling and review security-critical models together with our Solution Architect. * You will advise Solution Architects and Product Management on security-related architecture and roadmap decisions. Vulnerability & SBOM Management: * You are responsible for the product vulnerability management process, including CVE triage and the prioritization of mitigation measures. * You define policies and thresholds for SBOM creation as well as the assessment of open-source and third-party components. * You ensure process capability for the CRA's regulatory reporting requirements. Regulatory Evidence Management: * You are responsible for the security-related evidence required for certification according to IEC 62443-4-1 and for CRA-compliant technical documentation. * You support customer audits on the product development side. Management of Security Testing: * You define the tooling strategy for SAST, DAST, and dependency scanning and oversee their implementation. * You commission and manage external penetration tests and are responsible for tracking up on the findings. Interfaces: * You will work closely with Solution Architects, Product Management, Operations & Support, and company-wide Security Governance (CISO), and provide advisory support for product-related security incidents., Note: Depending on the specific (project) assignment, work may be required at customer sites involving critical infrastructure (KRITIS). In such cases, an extended security clearance (Ü2 - preventive personnel sabotage protection) is required by law pursuant to Section 9 in conjunction with Section 1(4) of the SÜG. Willingness to undergo this screening is an explicit requirement. The SÜG relevance in each individual case is assessed by the sabotage protection officer prior to the respective client assignment. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs)