Lead Security Architect

Vor 5 Tagen


Munich, Bayern, Deutschland commercetools Vollzeit

The Opportunity:

As we expand our engineering team beyond 100 professionals, we are establishing a tech leadership pathway to facilitate further growth. In the role of Principal Engineer for Product Security, you will have the unique opportunity to define this position and cultivate the tech leadership culture alongside the Director of Tech Leadership.

In this capacity, you will tackle complex technical challenges associated with our innovative product. Our commerce APIs manage sensitive information, including customer accounts and transactions. The Merchant Center, our backend management tool, features an intricate permission structure built upon our APIs. Your efforts will empower our product teams to adopt security measures early in the development process, ensuring they can create secure services within a multi-cloud framework.

Your Mission:

  • Develop a standardized security framework and operational best practices, particularly for new services and teams.
  • Guide our product teams in conducting risk assessments, threat modeling, and designing secure applications, including API-first products.
  • Evaluate requirements and application designs, assisting product teams in addressing any deficiencies.
  • Facilitate the integration of SAST, DAST, and SCA tools into the development lifecycle.
  • Organize external penetration testing and support teams in remediating identified vulnerabilities.
  • Collaborate with development teams to resolve security challenges and enhance overall security posture.
  • Rapidly investigate new attack vectors to help teams implement effective security controls to mitigate risks.
  • Assist teams during audits of our certifications.
  • Identify educational needs and skills gaps, promoting security knowledge sharing across the organization with the help of our internal knowledge management team.
  • Initiate improvements that impact multiple teams to enhance our Product Security, while also bringing your colleagues' ideas to fruition.
  • Lead communication efforts within the organization regarding long-term initiatives, ensuring successful adoption.
  • Work closely with Product Management, fellow Principal Engineers, the Head of Engineering, as well as legal and compliance teams.
  • Contribute to the evolution of our technical vision and advocate for it within the organization.

What you need to succeed:

  • A robust technical background with a proven history in a hands-on Product Security role (5+ years).
  • Experience enhancing Product Security in a leadership capacity (2+ years).
  • Proficiency in Secure Architecture design reviews and Threat Modeling.
  • Familiarity with integrating Security at various stages of the Software Development Life Cycle (SDLC).
  • Experience with Static Analysis and Secure Code Review implementations for early detection of security vulnerabilities in the SDLC.
  • Strong knowledge of Linux systems, Kubernetes, Terraform, Vault, and API/web application security.
  • Relevant Security Certifications such as CISSP, CCSP, Certified Kubernetes Security Specialist, or GCP/AWS/Azure security certification.
  • Practical experience in DevSecOps, including proficiency in at least one scripting language (JavaScript, Go, etc.).
  • Ability to analyze security issues alongside related organizational challenges.
  • Project management experience, particularly for initiatives involving multiple teams.
  • Experience working in an Agile environment with a strong customer focus.
  • Experience in setting up and conducting training sessions.
  • Excellent written and verbal communication skills.
  • Proficiency in English to operate effectively in an international setting.
  • Strong self-assessment capabilities.
  • A passion for sharing knowledge and a commitment to continuous self-improvement and learning about leadership, new technologies, and concepts.

We care about your growth and well-being

Competitive Compensation Package: A generous compensation structure that includes salary, a competitive stock option package, and various benefits and perks.

Workation: Opportunity to work up to 60 days per year in a different country.

Learning & Development Budget

Academy: Regular training sessions, access to Coursera and Babbel training courses.

Our Benefits: Explore them by office.

Flexibility: Whether you are a morning person or a night owl, we believe in outcomes and motivated employees.

Mindset & Growth: A diverse workplace with an open, international culture and a focus on learning.

Come grow with us

We celebrate diversity and are proud to be an equal opportunity employer. We hire exceptional individuals from a wide range of backgrounds, not just because it is the right thing to do, but because it strengthens our company.

commercetools is committed to fostering a diverse environment and is proud to be an equal opportunity employer. We evaluate candidates based on their competencies, potential, approach to learning and self-development, and passion, without regard to age, color, national origin, religion, gender, gender identity or expression, sexual orientation, familial status, genetics, or disability.



  • Munich, Bayern, Deutschland T-Systems International GmbH Vollzeit

    Aufgabe Als SDV Lead In Car Security Architect & Developer (w/m/d) erstellst du zusammen mit deinem Team umfassende Security Lösungen für das Software Defined Vehicle. Hierzu gehören unter anderem: Die schwerpunktmäßige Konzeption von Security relevanten Fahrzeugfunktionen Du bist im Bereich der Architektur stark und unterstützt dein Team "hands-on"...


  • Munich, Bayern, Deutschland ZEISS Vollzeit

    Elevate Your Career as a Lead Global Security ArchitectStep beyond conventional boundaries and redefine the potential of your career. At ZEISS, you will find yourself in a contemporary environment brimming with opportunities for professional growth, where expertise and collaboration are paramount.Our unique ownership structure is aligned with the long-term...


  • Munich, Bayern, Deutschland ZEISS Group Vollzeit

    Your Role The Business Information Security (InfoSec) Enablement team at ZEISS Group plays a pivotal role in ensuring that our corporate information security aligns with business objectives. This function is dedicated to empowering ZEISS Business Segments and Units to execute their strategic initiatives with a focus on security by design, meeting the...


  • Munich, Bayern, Deutschland ZEISS Group Vollzeit

    Your Role The Business Information Security (InfoSec) Enablement team at ZEISS Group is dedicated to enhancing corporate information security with a strong focus on business support and enablement. This global function is responsible for assisting ZEISS Business Segments and Units in implementing a strategic agenda that incorporates security by design,...


  • Munich, Bayern, Deutschland ZEISS Group Vollzeit

    Your Role The Business Information Security (InfoSec) Enablement team at ZEISS Group is dedicated to fostering a robust security framework that aligns with our global business objectives. This team plays a pivotal role in empowering ZEISS Business Segments and Units to implement security measures that are integrated into their operational strategies,...


  • Munich, Bayern, Deutschland ZEISS Group Vollzeit

    Your Role The Business Information Security (InfoSec) Enablement team at ZEISS Group is dedicated to enhancing corporate information security with a strong focus on business support and enablement. This global initiative aims to assist ZEISS Business Segments and Units in implementing a strategic agenda that prioritizes security by design, aligning with...


  • Munich, Bayern, Deutschland Mattermost Vollzeit

    Company OverviewMattermost is a leader in secure, workflow-oriented collaboration, catering to technical and operational teams that require top-tier security and trust. Our clientele spans across various sectors including technology, public service, national defense, and financial services, featuring some of the largest organizations globally.Position...


  • Munich, Bayern, Deutschland Mattermost Vollzeit

    Company OverviewMattermost is a leading provider of secure, workflow-centric collaboration solutions tailored for technical and operational teams that require stringent security and trust standards. Our clientele spans various sectors, including technology, public services, national defense, and financial institutions, featuring organizations from tech...


  • Munich, Bayern, Deutschland Mattermost Vollzeit

    About MattermostAt Mattermost, we deliver secure, workflow-oriented collaboration solutions tailored for technical and operational teams that require top-tier security and trust standards. Our clientele spans various sectors, including technology, public service, national defense, and financial services, featuring organizations from major tech firms to the...

  • Team Leader

    Vor 5 Tagen


    Munich, Bayern, Deutschland Lufthansa Group Security Operations GmbH Vollzeit

    Job Title: Team Leader - Operational Security SpecialistAbout the Role:We are seeking a highly skilled and experienced Team Leader to join our Operational Security team at Lufthansa Group Security Operations GmbH. As a Team Leader, you will be responsible for leading a team of security professionals and ensuring the highest level of security and order across...

  • Team Leader

    vor 2 Wochen


    Munich, Bayern, Deutschland Lufthansa Group Security Operations GmbH Vollzeit

    Job Title: Team Leader - Operational Security SpecialistAbout the Role:We are seeking a highly skilled and experienced Team Leader to join our Operational Security team at Lufthansa Group Security Operations GmbH. As a Team Leader, you will be responsible for leading a team of security professionals and ensuring the highest level of security and order across...


  • Munich, Bayern, Deutschland commercetools Vollzeit

    The Opportunity: As we expand our engineering team beyond 100 members, we are establishing a tech leadership pathway that will facilitate our growth. In the role of Principal Engineer for Product Security, you will have the unique opportunity to define this position and cultivate the tech leadership culture alongside the Director of Tech Leadership. In...


  • Munich, Bayern, Deutschland commercetools Vollzeit

    The Opportunity: As we expand our engineering team beyond 100 members, we are establishing a tech leadership pathway that will facilitate our growth. In the role of Principal Engineer for Product Security, you will have the unique opportunity to define this position and cultivate the tech leadership culture alongside the Director of Tech Leadership. In...

  • Security Architect

    Vor 7 Tagen


    Munich, Bayern, Deutschland FERCHAU - Niederlassung München IT Vollzeit

    About FERCHAU - Niederlassung München ITWe are a leading IT consulting company that connects people and technologies to deliver innovative solutions for our clients. Our team of experts is passionate about shaping the future of technology and driving business success.Job SummaryWe are seeking a highly skilled Security Architect to join our team in Munich....

  • Security Architect

    Vor 5 Tagen


    Munich, Bayern, Deutschland FERCHAU - Niederlassung München IT Vollzeit

    About FERCHAU - Niederlassung München ITWe are a leading IT consulting company that connects people and technologies to deliver innovative solutions for our clients. Our team of experts is passionate about shaping the future of technology and driving business success.Job SummaryWe are seeking a highly skilled Security Architect to join our team in Munich....


  • Munich, Bayern, Deutschland commercetools Vollzeit

    About the Role:We are seeking a highly skilled Principal Security Architect to join our team at commercetools. As a key member of our tech leadership team, you will play a critical role in shaping our security architecture and driving the adoption of secure practices across the organization.Key Responsibilities:Create and maintain a comprehensive security...


  • Munich, Bayern, Deutschland commercetools Vollzeit

    About the Role:We are seeking a highly skilled Principal Security Architect to join our team at commercetools. As a key member of our tech leadership team, you will play a critical role in shaping our security architecture and driving the adoption of secure practices across the organization.Key Responsibilities:Create and maintain a comprehensive security...


  • Munich, Bayern, Deutschland Mattermost Vollzeit

    About MattermostMattermost is a pioneering provider of secure, workflow-focused collaboration solutions tailored for technical and operational teams that require top-tier security and trust standards. Our clientele spans various sectors, including technology, public services, national defense, and financial services, encompassing both major tech corporations...


  • Munich, Bayern, Deutschland Giesecke+Devrient GmbH Vollzeit

    Mit unserer Expertise schaffen wir Raum für Ideen, die die Welt bewegen.Application Security Architect SAP (m/w/d)G+D macht das Leben von Milliarden von Menschen weltweit sicherer. Wir schaffen Vertrauen im digitalen Zeitalter, mit integrierten Sicherheitstechnologien in drei Geschäftsbereichen: Digital Security, Financial Platforms und Currency...


  • Munich, Bayern, Deutschland NVISO Vollzeit

    About NVISONVISO is a leading provider of cyber security services to private and governmental organizations. Our mission is to protect European society from potentially devastating cyber attacks.We are committed to offering our clients a highly competitive remuneration package, including financial and non-financial components.Job SummaryWe are seeking a...