Grįžti į skelbimus
Alliance for Recruitment

Lead Product Security Engineer

6
5800 - 8000 €/mėn.
Prieš mokesčius

Job description:

You will lead security across application, cloud, and everything in between. Rather than splitting AppSec and CloudSec across two teams, we want a single senior owner who can reason across the whole stack and make the secure path the default path. You will act as a force multiplier for engineering, working alongside platform/SRE, detection/IR, and GRC. You lead the seams they individually miss.

Key responsibilities:
- Define and drive the secure-by-design strategy across the SDLC, with paved-road guardrails so engineers ship safely and quickly
- Lead threat modeling for new services, significant changes, and high-risk features across application logic and cloud architecture
- Own AppSec testing in CI/CD (SAST, SCA, secrets, IaC scanning) and software supply chain security (dependency risk, SBOMs, build integrity, provenance)
- Own cloud security posture and workload protection in Azure (CNAPP/CSPM/CWP), workload identity, secrets, and least privilege (CIEM)
- Embed security into IaC and Policy-as-Code, and lead the design of network segmentation, private endpoints, and Zero Trust boundaries in partnership with platform/SRE
- Run risk-based vulnerability management across app and cloud, prioritized by reachability, exploitability, and exposure
- Grow a security champions program, reusable patterns, and training so security scales beyond you
- Provide security evidence and assurance for DORA (ICT risk, third-party/supply-chain risk, operational resilience, TLPT)
 

Requirements:

- Deep hands-on security experience across the SDLC, with a track record of building or substantially scaling a security program
- Primary depth in either application security or cloud security, and credible hands-on competence in the other
- Strong command of modern AppSec fundamentals: OWASP Top 10 (2025), API Security Top 10, authn/authz, OAuth2/OIDC (FAPI 2.0 a plus)
- Hands-on Azure security: CNAPP/CSPM/CWP, Entra ID, secrets management, cloud IAM
- IaC (Bicep/Terraform), security in CI/CD, and scripting (Python, PowerShell, or similar)
- Software supply chain security: dependency risk, SBOM, build/pipeline integrity, provenance
- Risk-based vulnerability management and the judgment to prioritize what actually matters
- DORA or equivalent regulatory familiarity (NIS2, PCI DSS, ISO 27001, NIST CSF)
- Strong communication and influence, able to drive change without direct authority and explain risk to engineers, leadership, and auditors

Nice to have
- Exposure to AI/LLM application security (OWASP LLM Top 10)
- Container and Kubernetes security (AKS, pod security, admission control, image hardening)
- Multi-cloud awareness (AWS/GCP)
- Deep network/infrastructure security architecture
- Financial services, fintech, or open-banking background
- SIEM and detection experience


Miestas:
Vilnius
Nuotolinis darbas:
Ne
Laikas:
Visa darbo diena
Galioja iki:
28/08/2026

Kandidatuokite į skelbimą