Skip to content

Open nowPosted 50 days ago

Staff Product Security Engineer

Aiven37 open roles

Where
Helsinki, Uusimaa, Finland
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Product Security EngineerAiven · Helsinki, Uusimaa, Finland
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Aiven's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.4%1 day
  2. 3.5%3 days
  3. 7.7%7 days
  4. 13.4%14 days
  5. 34.5%30 days
This job: posted 50 days ago

The posting

We’re a global team of over 400 people, working together to push the boundaries of open-source technology and multi-cloud solutions. Our vision is to help developers, builders, and creators bring their ideas to life with speed and simplicity, by providing a cloud data platform that makes open-source databases, search, streaming, and application infrastructure easily accessible to everyone.

The Role:

We are looking for a Staff Product Security Engineer to join our Product Security team. The role of Aiven’s product security is to identify, report, and assist with the remediation of security vulnerabilities, to manage our bug bounty program, and to provide technical security insights into new products that the Aiven engineering organization is developing. The Staff Product Security Engineer will also work closely with the Identity and Access Management team and Security Operations to ensure the security of our products and infrastructure.

What You'll Do:

  • Vulnerability Management: Triaging and analyzing results from our vulnerability scanners. This includes identifying and documenting false positives to minimize unnecessary remediation efforts. You will work with documentation and other team members to identify risk-based decisions and write responses to audit questions.
  • Network Security Scanning: Participate in the regular review of internal network vulnerability scans. Collaborate with network and system administrators to prioritize and remediate identified vulnerabilities, escalating critical issues as needed.
  • Security Assessment: Independently conduct security testing of our products using a variety of methodologies, including tool-based assessment and manual testing. Report and document findings for internal users. Apply and state industry-standard methodologies for testing to meet audit requirements.
  • Issue triage: You will evaluate issues reported by internal staff, customers, and third parties as to reproducibility, and track information on true positive security vulnerabilities.
  • Remediation validation: You will determine whether engineering changes have fixed security vulnerabilities, and conduct a gap analysis where required.
  • Compliance Support: Contribute to compliance efforts (e.g., PCI DSS, ISO 27001, SOC 2) by assisting in the preparation of reports and documentation related to vulnerability scanning activities. This may involve documenting false positives, validating compensating controls, and ensuring accurate reporting.
  • Scanner Optimization: Contribute to the ongoing improvement of our vulnerability scanning program by identifying and reporting any gaps in scanner coverage. This includes verifying that all intended systems and applications are being scanned and suggesting improvements to scanning configurations.
  • Audit: Assist in execution of 3rd-party audits and penetration tests
  • IAM Automation: Assist with the automation of identity and access management procedures and reporting
  • AI Security: Assess the security of artificial intelligence algorithms in Aiven’s products

What We're Looking For:

We are looking for talented self-starters who want to learn about security and grow into roles such as Software Engineer in Security and Information Security Analyst. We will consider candidates with less security-specific experience but with the desire to learn!

Examples of attributes for success in this role include:

  • A bachelor's or master’s degree in computer science, engineering, information security, information technology, or equivalent training
  • 5+ years of experience in information security or a related field
  • Experience in software development, site reliability engineering, software or IT architecture, business analysis, risk management, and project management are assets
  • Detailed knowledge of security, distributed systems, and microservices architecture
  • Senior certifications in hyperscaler clouds and in security testing; certifications in risk management are beneficial
  • Detailed understanding of risk management and vulnerability management practices, specifically in a multi-cloud environment
  • Relevant experience from modern technologies such as public cloud and networking
  • Experience with programming and software development
  • Fluency in English, verbal and written

Amazing! What’s next:

If you think Aiven is the place for you and that our Values align with yours, send us your resume and we’ll get in touch!

Global Benefits:

Our global benefits are designed to help you thrive and grow, personally and professionally:

  • Participate in Aiven’s equity plan.
  • Balance work and life with our hybrid work policy.
  • Choose the equipment you need to set yourself up for success.
  • Use your Professional Development Plan budget for learning opportunities.
  • Receive holistic wellbeing support through our global Employee Assistance Program.
  • Inquire about our Global Time Off Commitment (Parental and Sick Leave, as well as Personal Time)
  • Enjoy country-specific benefits for our global cast.

How to Recognize and Avoid Employment Scams:

There has been a rise in fake job postings used by scammers to get personal information. At Aiven, all of our emails relating to recruitment come from an @aiven.io, @greenhouse.io or @eu.greenhouse.io domain and all of our interviews are conducted by video call or in person. Our interviews will never occur via text or chat. If you’re unsure of the legitimacy of a job opportunity/offer pertaining to Aiven, please don’t hesitate to reach out to us at [email protected].

Equal Opportunities:

Aiven provides equal employment opportunities to all qualified employees and applicants for employment without regard to age, gender identity, national or ethnic origin, religion, sexual orientation, physical and mental ability, marital and family status or without regard to any other similar personal attributes. Aiven complies with applicable local laws governing non-discrimination in employment in every location in which the company operates. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, transfer, leaves of absence, compensation, training and any other terms and conditions related to employment.

At Aiven we are committed to providing reasonable accommodations for qualified individuals with disabilities or special needs in our working environment and job application procedures. We make all reasonable accommodations for persons with disabilities or who otherwise need support to thrive in the workplace. We are committed to continuously improving workplace accessibility. There is an option to request a discussion in the application process but if you have any questions before applying please write to us at [email protected].

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Aiven's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Aiven's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Aiven's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.