Apply on company website Berlin, Germany Hybrid Full-time

Delivery Hero is hiring a Staff Security Engineer, Product Security team

Responsibilities

  • Lead the development and execution of a scalable technical strategy for product security across global web and mobile platforms.
  • Identify critical design vulnerabilities early in development using structured threat modeling and security architecture reviews.
  • Design and maintain a comprehensive, scalable vulnerability management program incorporating internal findings, automated tools, and external reports.
  • Evaluate and prioritize security flaws based on real business impact, ensuring accurate risk classification and remediation tracking.
  • Communicate technical security risks clearly to engineering and product leaders, enabling fast and effective resolution.
  • Improve security performance by monitoring and optimizing key metrics such as time to remediate and SLA compliance.
  • Integrate automated security testing into development pipelines to eliminate manual checkpoints and accelerate secure delivery.
  • Implement advanced AI and large language models to automate code analysis, triage vulnerabilities, and enhance security workflows.
  • Build intelligent automation systems that increase developer productivity while maintaining strong security controls.
  • Collaborate with infrastructure teams to align application security with cloud configuration risks using CSPM tools.
  • Ensure applications support effective detection and response through proper logging and alerting practices.
  • Work across teams to contextualize application risks within broader cloud and operational environments.
  • Establish secure-by-design principles in system architecture through collaborative blueprint development.
  • Embed security tools like SAST, DAST, and SCA directly into CI/CD environments for early risk detection.
  • Promote a proactive security culture by mentoring engineers at all levels and growing internal security expertise.
  • Serve as a technical leader and role model across security and engineering functions.
  • Define and track meaningful security metrics that reflect real improvements in organizational posture.
  • Support secure innovation by aligning security practices with agile development cycles.
  • Strengthen cross-functional coordination between product verticals and security teams.
  • Ensure security scales efficiently with growing application and user demands.
  • Leverage automation to reduce toil and increase consistency in security operations.
  • Guide the adoption of modern security frameworks and tools across engineering groups.
  • Enhance incident preparedness by aligning application design with detection and response needs.
  • Drive continuous improvement in secure coding practices across development teams.
  • Foster collaboration between product, engineering, and security stakeholders to align goals and outcomes.

Responsibilities

  • Drive Product Security Maturity: Drive the strategic technical roadmap for the Product Security team, ensuring threat-modeling methodologies and secure coding practices scale efficiently across our global web and mobile application ecosystem.
  • Lead Threat Modeling & Security Architecture Reviews: Apply your expertise to identify complex security design flaws early in the Software Development Life Cycle (SDLC) using frameworks and automation tools, co-authoring architectural blueprints that are secure by default.
  • Scale Vulnerability Management & Governance: Architect and run our vulnerability management program at scale. You will ingest inputs from internal testing, automated tooling, and external Bug Bounty / Vulnerability Disclosure Programs, systematically validating and ranking vulnerabilities based on actual business risk.
  • Master Stakeholder Management: Translate complex software and AI-related vulnerabilities into clear, actionable business risks, partnering closely with engineering leadership and product verticals to drive timely remediation without friction. systematically tracking and optimizing metrics such as Mean Time to Remediate (MTTR) and SLA Adherence % to elevate our overall security posture.
  • Automate DevSecOps & CI/CD Pipelines: Replace manual gates with seamless DevSecOps workflows, embedding automated security testing tools (SAST, DAST, SCA) directly into developer pipelines to catch high-risk flaws early.
  • Pioneer AI-Driven Security Automation: Champion the adoption of artificial intelligence and LLMs to revolutionize our security workflows. You will design and implement cutting-edge AI-powered code security automation, leverage AI for automated vulnerability triage, and build smart security automation guardrails that scale engineering productivity.
  • Cross-Domain Collaboration & CSPM Management: Drive domain-wide impact by collaborating with Infrastructure Security to leverage Cloud Security Posture Management (CSPM) platforms, ensuring that application vulnerabilities are contextualized with cloud risk. Partner with Security Operations (Detection & Response) to ensure proper application logging, alerting, and incident readiness.
  • Mentor and Inspire: Act as a technical beacon within the security and engineering organizations. Define key security metrics, drive a strong security culture, and mentor junior and senior engineers to foster a world-class community of Security Champions
Job Details
Location Berlin, Germany
Work mode Hybrid
Employment Full-time
Department Product Security
Category Security
Posted 2 months ago
Application On company website
About company
Delivery Hero logo
A global local delivery platform operating in over 70+ countries, headquartered in Berlin, Germany, and listed on the Frankfurt Stock Exchange.
All jobs at Delivery Hero Visit website