[Hiring] Senior Information Security Engineer @Camunda
Senior Information Security Engineer @Camunda
Information Technology
Salary usd 143,800 - 2..
Remote Location
Employment Type full-time
Posted YDay

[Hiring] Senior Information Security Engineer @Camunda

YDay - Camunda is hiring a remote Senior Information Security Engineer. πŸ’Έ Salary: usd 143,800 - 231,900 per year πŸ“Location: EST (UTC-5), CET (UTC+1)

Role Description

As a Senior Information Security Engineer (AppSec) at Camunda, you’ll join a small, senior, and highly collaborative InfoSec team that lives our FAITH values – Focus, Ambition, Integrity, Talent and Humor – every day. You’ll work hand-in-hand with our product and engineering teams across the entire SDLC to make sure our platform is designed, built, and shipped securely as we continue to grow. This is a technical, hands-on, developer-centric role where you’ll shape how we build secure Java services in a modern CI/CD, SaaS environment, strengthen our AppSec tooling and practices, and directly influence how customers trust and adopt Camunda. You can be based anywhere that allows you to collaborate effectively within CET to Eastern Time working hours.

What you'll be doing:

  • Partner with engineering teams throughout the SDLC – from early design and architecture discussions, through implementation and testing, to deployment – to embed security by design in our products.
  • Lead and evolve our AppSec tooling and workflows by implementing, tuning, and integrating SAST, DAST, SCA, and container/image scanning into CI/CD pipelines, and making sure findings are actionable for developers.
  • Drive vulnerability management for our applications and supply chain, including triaging and prioritizing issues, coordinating with teams on fix/mitigate/accept decisions, and ensuring we continuously improve our security posture.
  • Perform secure design and architecture reviews and threat modeling for distributed, API- and microservices-based systems, helping teams understand security trade-offs and make sound, risk-based decisions.
  • Support and help coordinate application-layer security incidents and escalations, working closely with Engineering, Support, and other stakeholders to investigate, contain, and learn from issues.
  • Together with the rest of the InfoSec team, help with security audits, customer assurance, and other processes.

Qualifications

  • Ability and/or willingness to use our product.
  • Strong Software engineering and secure coding background, with substantial recent hands-on experience building and reviewing (Java) services, working in CI/CD environments, and shipping SaaS or other cloud-based applications securely.
  • Secure SDLC, architecture & risk assessment experience, including secure design reviews, threat modeling for distributed/API/microservices systems, and performing risk assessments on product changes or new features.
  • Vulnerability management & security tooling expertise, with a proven track record of implementing and tuning SAST/DAST/SCA and container/image scanning, evaluating and triaging findings (including false positives), and driving fix/mitigate/accept decisions with engineering teams.
  • Cross-team collaboration & communication skills, enabling you to work effectively with Engineering, Support, Sales, and other stakeholders while explaining complex security issues and trade-offs in a clear, pragmatic way to both technical and non-technical audiences.
  • Developer-centric, incident-savvy mindset, meaning you are comfortable managing and supporting security incidents and escalations, you see yourself as an enabler (not a gatekeeper), and you influence teams toward risk-based, practical security improvements.

Nice-to-haves:

  • Experience developing in Python, JavaScript, or TypeScript in addition to Java.
  • Hands-on experience securing Kubernetes- or container-based workloads and modern cloud environments.
  • Prior work in a B2B software company, especially in high-availability or multi-tenant contexts.
  • Experience running security training, talks, or workshops for engineering teams.

Requirements

This role is an existing vacancy.

Benefits

  • Compensation: Competitive, fair, and transparent compensation based on location.
  • Equity: Offered through our Virtual Stock Option Plan (VSOP).
  • Remote & Flexible: Work from anywhere with home office budget, co-working space support, and flexible time off.
  • In Person Connection: Annual Kickoff events, team offsites, and local gatherings.
  • Health & Wellbeing: Access to healthcare, mental wellbeing support, and a flexible lifestyle spending account.
  • Financial Security: Retirement and pension plans, plus life and disability insurance.
  • Professional Growth: Up to $/€/Β£1,000 per year for self-driven learning.
Before You Apply
️
remote Be aware of the location restriction for this remote position: EST (UTC-5), CET (UTC+1)
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Information Security Engineer @Camunda
Information Technology
Salary usd 143,800 - 2..
Remote Location
Employment Type full-time
Posted YDay
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 160,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: EST (UTC-5), CET (UTC+1)
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 160,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 160,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later