Software Security Engineer

Cresta Cresta · Vertical AI · Germany · Remote · Technical Operations

Cresta is seeking a Software Security Engineer with 4+ years of experience in application security engineering and cloud security (AWS/GCP) to support the security & compliance team. The role involves implementing product security features, maturing the DevSecOps pipeline, detecting and responding to threats, supporting audits (SOC 2, ISO 27001, PCI-DSS, TISAX, HIPAA), performing security audits, improving vulnerability management, and developing internal tooling. Proficiency in Python and Go is required.

What you'd actually do

  1. Implement and collaborate on product security features
  2. Mature and extend our DevSecOps pipeline.
  3. Detect, defend, and respond to threats to Cresta and its customers
  4. Support SOC 2 Type II, ISO 27001 & 27701, PCI-DSS, TISAX and HIPAA audit processes with technical controls and evidence
  5. Perform security audits of Cresta’s products and cloud infrastructure and drive remediation of security risks

Skills

Required

  • application security engineering
  • cloud security (AWS/GCP)
  • Python
  • Go
  • security audits
  • vulnerability management

Nice to have

  • fast-growing SaaS start-ups

What the JD emphasized

  • HIPAA
  • SOC 2 Type II
  • ISO 27001 & 27001
  • PCI-DSS
  • TISAX