Role Description
Aras is expanding its Product Security team and is seeking a Product Security Engineer with strong DevOps expertise to help secure our products, cloud platforms, and software development lifecycle. This role will be responsible for designing, implementing, and maintaining secure CI/CD pipelines, integrating security controls throughout the development process, and driving a security-first engineering culture across product and cloud teams.
-
Response to incidents, triage of found issues, and communication with Product Development team on a daily basis.
-
Partner closely with software engineers, cloud architects, DevOps teams, and security stakeholders to identify, prioritize, and remediate security risks at scale.
-
Play a key role in advancing Aras' Security maturity.
-
Requires strong technical expertise, excellent communication skills, and hands-on experience integrating SAST, DAST, SCA, container security, and cloud security controls into modern CI/CD environments.
Qualifications
-
4+ years of hands-on experience with Jenkins or similar CI/CD platforms.
-
3+ years of software development, automation, or scripting experience using Python, PowerShell, Bash, or equivalent languages.
-
Experience integrating security tooling into CI/CD pipelines, including SAST, DAST, SCA, container scanning, and secrets management.
-
Working knowledge of cloud security principles and services in Azure and/or AWS.
-
Understanding of containerized environments and Kubernetes security concepts.
-
Experience collaborating with engineering teams in Agile development environments.
-
Strong analytical, troubleshooting, and problem-solving skills.
-
Self-motivated with the ability to work independently and manage multiple priorities.
-
Bachelorβs degree in computer science, Information Technology, Cybersecurity, or equivalent practical experience.
Requirements
-
Experience with Infrastructure as Code (Terraform, Bicep, CloudFormation).
-
Experience with Azure DevOps pipelines and security integrations.
-
Familiarity with software supply chain security practices and frameworks (SBOM, SLSA, Sigstore, provenance validation).
-
Experience securing Kubernetes and cloud-native platforms.
-
Familiarity with AI-assisted development tools and secure AI engineering practices.
-
Knowledge of security frameworks such as NIST SSDF, OWASP SAMM, OWASP ASVS, and CIS Benchmarks.
Certifications
-
Microsoft Certified: Azure Security Engineer Associate
-
Microsoft Certified: DevOps Engineer Expert
-
Certified Kubernetes Security Specialist (CKS)
-
Certified Kubernetes Administrator (CKA)
What Success Looks Like
-
Security controls are seamlessly integrated into engineering workflows with minimal developer friction.
-
Vulnerabilities are identified and remediated earlier in the SDLC.
-
Security testing and compliance checks are automated wherever possible.
-
Product teams actively embrace DevSecOps and secure-by-design principles.
-
Security becomes an engineering accelerator rather than a deployment bottleneck.