About the role
Job Description
Responsibilities Security guidance & product lifecycle
* Provide security guidance on new products and technologies across the organization. * Act as the security lead on development projects, embedding security throughout the product * development lifecycle. * Support development teams with DevSecOps practices, integrating security into CI/CD pipelines * and fostering a shift-left security culture. * Guide project teams through secure product lifecycle management, and provide ongoing * security support to the product engineering team.
Threat modeling & security assessments
* Collaborate with engineering teams to perform regular product security assessments. * Lead threat modeling exercises to identify and prioritize risks early in design.
Application security (AppSec)
* Perform application security assessments and secure code reviews across web, backend, and * native codebases. * Operate application security tooling (SAST, DAST, SCA), configuring scans, and triaging and * prioritizing findings. * Advise development teams on secure coding practices and remediation of application-layer * vulnerabilities.
Vulnerability testing
* Conduct regular vulnerability testing and scanning across current and legacy devices, products, * and supporting infrastructure. * Triage, prioritize, and track identified vulnerabilities through to remediation.
Security tooling & automation
* Manage the operations and effectiveness of the product security pipeline tooling. * Tune and update tooling to reduce false positives and improve signal quality. * Design and implement tools and automation to scale security processes.
Cloud security
* Assess and help secure cloud environments (AWS), reviewing configurations, IAM policies, and * infrastructure against security best practices. * Support secure deployment of cloud-hosted products and services, and help embed security into * infrastructure-as-code and cloud CI/CD workflows.
Incident detection & response
* Respond to vulnerabilities surfaced through threat detection systems. * Support the incident detection and response processes.
PKI & cryptography
* VMS Team Ovr – Product Security Engineer (mid-level) - Job Description * Operate and support internal and public PKI, certificate issuance, lifecycle management, and * related cryptographic services.
Documentation & standards
* Maintain internal security documentation and standards to ensure security best practices are * followed.
Qualifications
* 3–5 years in product, application, or offensive security. * Degree in Computer Science, Cybersecurity, or a related field, or equivalent experience. * Hands-on vulnerability assessment experience. * Application security experience, including secure code review and use of SAST/DAST/SCA * tooling. * Experience with threat modeling methodologies (e.g., STRIDE). * Working knowledge of secure SDLC / DevSecOps and CI/CD security integration. * Cloud security knowledge, particularly AWS, familiarity with core services, IAM, and cloud * security best practices. * Solid understanding of PKI, digital certificates, and applied cryptography. * Scripting and automation ability (e.g., Python) to build and scale security tooling. * Familiarity with incident detection and response processes. * Strong communication skills for working across development and project teams.
Nice to have
* Penetration testing experience across devices, applications, and infrastructure. * Experience with embedded/IoT devices, video management systems, or network appliances. * Exposure to regulatory frameworks such as the EU Cyber Resilience Act (CRA). * Familiarity with AI security, testing and assessing AI-powered products and features, and using * of AI tools to enhance day-to-day security work. * Cloud security certifications (e.g., AWS Certified Security – Specialty). * Relevant certifications (e.g., OSCP, GIAC, CEH)
Additional Information
Keenfinity benefits includes:
⚖️ Flexible work conditions (2 days of HO)
🧑⚕️ Health insurance and medical office on site (nutrition, psychology, physiotherapy and general clinic)
🍽️ Canteen
🅿️ Free parking lot
🏋️ Sports and health related activities (gym)
📚 Training opportunities (i.e., technical training, foreign languages training) & certifications
📈 Opportunities for career progression and continuous professional development
🌐 Exchange with colleagues around the world
💲 Access to great discounts in partnerships and products
🌍All our positions are open to people with disability
----
At Keenfinity we don’t just build innovative solutions — we shape a smarter, more connected world through technology.
We value different backgrounds, ideas, and experiences and we’re committed to growing, learning, and celebrating success as one team. Everyone is welcome here — we foster an environment where everyone is respected, valued, and encouraged to be their authentic self.
Keenfinity is an equal opportunity employer, offering equal opportunities for all. We welcome applications from people with disabilities and can offer support, if needed. When everyone has a chance to contribute, we all do better.