Job Summary
- Join the great Henkel Application Security team, with strong focus on applying secure software development practices across Henkel worldwide
- As an AppSec engineer, you can influence secure development principles and culture across the organization and advance our DevSecOps approach
- You will analyze code vulnerabilities (e.g. SAST, leaked secrets, …) and guide development teams on their questions and remediation
- You will pilot security scanner features/settings and test them out inside of pipelines and pull request
- You will collaborate with development teams and application owners on the integration of security scanners in Azure DevOps and GitHub, review their effectiveness and improve business cases to adapt to new threats
- You set out secure development requirements in concepts and policies, in line with best practice, technology trends and cyberthreats
- You can learn from excellent team members and make yourself an industry expert
Key Responsibilities
Skill Requirements
Your Skills
- Bachelor's degree or above in IT, IT-Security, or related fields
- At least 6 years of relevant professional experience in Application Security or a similar role
- Extensive experience in secure coding and fixing common application vulnerabilities
- Experience in software development – ideally with hands-on programming in Python, YAML, or CI/CD pipelines
- Experience in related IT topics e.g. CI/CD pipelines, Azure DevOps, software engineering, web technologies, Azure cloud
- Experience in relevant IT-Security topics e.g. SAST, secret scanning, secure development, pen testing, OWASP Top 10
- Robust organization skills and dependable working style over owned topics like vulnerability management
- Great team player, with self-organization and hands-on mentality
- Compassionate about supporting development teams and application owners
- Relevant security certifications are appreciated
- Proficient oral and written English language skills