Senior Information Security Engineer
Job description
Senior Information Security Engineer at camunda
About the role
Join a focused and collaborative Information Security team at Camunda, a company transforming into an AI-first organization. This hands-on role involves embedding security into our Java-based SaaS platform throughout the entire development lifecycle. You will directly influence customer trust and adoption by enhancing our security tooling and practices.
Key facts
What you'll do
Collaborate with product and engineering teams across all stages of development, from initial design to deployment, to integrate security principles.
Advance our application security tooling and processes by implementing, configuring, and integrating static analysis, dynamic analysis, software composition analysis, and container scanning into our CI/CD pipelines.
Manage application and supply chain vulnerabilities by assessing, prioritizing, and coordinating remediation efforts with relevant teams.
Conduct secure design and architecture reviews, including threat modeling for distributed systems and microservices, to guide teams in making informed risk-based decisions.
Assist in managing and responding to application-layer security incidents, working with cross-functional teams to investigate and learn from events.
Support security audits and customer assurance processes as part of the broader InfoSec team.
Requirements
Demonstrated ability or willingness to use Camunda's product.
Solid background in software engineering and secure coding, with recent practical experience in building and reviewing Java services, working within CI/CD environments, and securely deploying cloud-based applications.
Experience with secure software development lifecycles, architecture reviews, and risk assessments, including threat modeling for distributed and microservices architectures.
Proficiency in vulnerability management and security tooling, including experience implementing and tuning SAST, DAST, SCA, and container scanning tools, evaluating findings, and driving remediation with engineering teams.
Strong collaboration and communication abilities, enabling effective interaction with engineering, support, sales, and other stakeholders, clearly explaining complex security concepts to diverse audiences.
A developer-centric and incident-aware mindset, comfortable supporting security incidents and acting as an enabler for practical, risk-based security improvements.
Nice to have
Experience developing in Python, JavaScript, or TypeScript in addition to Java.
Hands-on experience securing Kubernetes or containerized workloads and modern cloud infrastructure.
Previous work experience in a B2B software company, particularly in high-availability or multi-tenant environments.
Experience delivering security training or workshops to engineering teams.
Skills & tools
Java, CI/CD, SaaS, Cloud-based applications, SAST, DAST, SCA, Container Scanning, Threat Modeling, Microservices, API Security, Vulnerability Management, Kubernetes, Python, JavaScript, TypeScript.
Practical notes
Compensation includes base salary and potential variable targets, with final offers based on skills, experience, and location. Equity is offered through a Virtual Stock Option Plan (VSOP). Benefits include remote work support, home office budget, co-working space access, flexible time off, in-person connection events, health and wellbeing support (including mental wellbeing and lifestyle spending accounts), retirement plans, and professional development budgets. Camunda may utilize AI tools in its hiring process. Camunda is an equal opportunity employer. Be aware of potential scams; Camunda will only contact candidates from @camunda.com email addresses and will not request financial information during the hiring process. Camunda does not accept unsolicited resumes from recruiting and placement agencies.