As part of our Information Security Engineering & Consulting Team you will be responsible for vulnerability management as well as for consulting our product teams and management regarding the technical implementation of our security requirements. Together with product teams, you’ll provide guidance throughout the product lifecycle by performing security consulting, threat modeling, technical security testing and reviews. You will be an active member of our security profession community.
Improving the security culture through training and coaching of administrators, software engineers, managers, and product owners with practical tasks in offensive security as well as Security by Design and Secure Coding.
Development, review and update of specific guidelines and support materials including concrete, practical activities and tools based on relevant information security policies.
As part of your work, you identify potential security risks and forward them to the necessary authorities.
Support and advise the product organization to ensure that all relevant security requirements are integrated into products and conducting vulnerability assessments and risk analyses.
Close cooperation and working together with the internal Security Operation Center as well as collaboration with development teams to integrate security measures, security tests, and acceptance criteria.
Promoting a culture of proactive vulnerability prevention and remediation within the product organization and implementation of best practices in vulnerability management.
Ensuring control and coordination for the remediation of identified vulnerabilities through close collaboration with the product organization, as well as providing suitable KPIs and product-specific dashboards and reports.
You work in close partnership with our infrastructure teams, information security governance teams and colleagues from the REWE Digital (DE).
IZ NÖ-Süd Straße 3 Objekt 16, 2355 Wiener Neudorf, Austria Hybrid Full-time 70.000 Euro