
Product Security Engineer at SAP Fioneer. Innovation is and will always be the core of SAP Fioneer, and it is the promise of why we were spun out of SAP: agility, innovation, and delivery. . SAP Fioneer builds on a heritage of outstanding technology and a deep understanding of corporate and consumer demands. At the heart of it all it is simple: We bring financial services to the next level with innovative software solutions and platforms. We are helping companies in the financial services industry to achieve speed, scalability, and cost-efficiency through digital business innovation, cloud technology, and solutions that cover banking and insurance processes end-to-end. . A global company, with rapid growth, innovative people, and a lean organization makes SAP Fioneer a place where you accelerate your future!. Role. As a Product Security Engineer, you will contribute to ensuring the security and integrity of our software products. Your responsibilities will include:. Building Secure Pipelines:. You will assist in designing and implementing secure CI/CD pipelines, utilizing existing automation solutions alongside recognized tools such as GitHub Actions and JFROG Artifactory. You'll work towards integrating security practices at various stages of the development process.. Building Application Security Dashboards: . You will help create and maintain application security dashboards that provide insights into the security posture of our products. This will support informed decision-making and allow for timely responses to potential threats.. Conducting Threat Modeling Sessions: . You will participate in threat modeling sessions to identify potential security threats and vulnerabilities in our products, contributing to proactive mitigation strategies.. Security Reviews of Software Architectures:. You will carry out security reviews of software architectures and collaborate with senior colleagues to ensure that robust security measures are integrated into our products from the outset.. Writing Secure Coding Instructions:. You will participate in developing clear and accessible secure coding guidelines for our development teams, encouraging best practices and ensuring that security is an essential component of our software development lifecycle.. . Minimum of 2-3 years of work experience in the security or 3-4 years of work experience as full-stack developer, with a background in DevSecOps environments.. . Good understanding of the Secure Development Lifecycle (SDLC) and corresponding effective processes.. . Experience in building secure CI/CD pipelines.. . Ability to develop automation solutions for product security processes. . Experience in conducting threat modeling sessions and performing security reviews of software architectures.. . Company Location: Romania.