Define and establish standards, frameworks, and secure coding guidelines based on industry best practices such as OWASP, Microsoft SDL, NIST SSDF, and ISO 27034
Conduct security reviews, threat modeling sessions, and architecture assessments to identify and evaluate application security risks
Integrate security requirements and tools such as SAST, DAST, SCA, Secret Scanning, and Container Security into modern development and CI / CD processes
Collaborate closely with Development Squads, Platform Engineering, Architecture, and Pentesting Teams to remediate vulnerabilities and implement security requirements sustainably
Build and enhance an international Secure Development Community through training programs, Security Champion initiatives, and continuous knowledge sharing
Monitor emerging threats, vulnerabilities, and trends in Application Security and assess their relevance for ista
Several years of experience in Application Security, Secure Software Development, or Software Architecture
Strong understanding of modern software development processes and secure development methodologies
Hands-on experience with OWASP Top 10, OWASP ASVS, OWASP SAMM, and relevant secure coding standards
Knowledge of Threat Modeling, Security Architecture Reviews, and Vulnerability Management
Experience with cloud technologies, web and API security, as well as modern development platforms and CI / CD processes
Ability to communicate technical risks effectively and provide guidance to a wide range of stakeholders
Excellent communication skills with the ability to successfully build, engage, and nurture communities, combined with a pragmatic and solution-oriented mindset; fluent English required, German language skills are an advantage
Do the right thing with purpose and a future: Our services save CO₂ and protect the environment – we are working for a sustainable world of tomorrow
Shape the future of secure software development: Take on a key role in building and advancing Application Security at ista and make a lasting impact on security standards, processes, and our international Secure Development Community
Enjoy many benefits: Look forward to an attractive salary, 30 days' vacation per year and flexible working hours, including the opportunity to work up to 50% of the week on a mobile basis
Secure good prospects for yourself: We are an internationally successful company with agile working methods and an open corporate culture. Our future course offers you long-term and excellent career options
Stay curious and develop yourself further: Standing still is not an option for us, which is why we support you in every aspect of your development – a variety of learning opportunities await you
Experience a working environment full of trust: We all pull together
Have fun in a motivated team: Whether it's a barbecue event, international soccer cup or ice cream for everyone in summer – we always come up with something new, so stay tuned!
BATO1_DE
Estimate based on 11 job ads with stated pay from the last 6 months on baito. This is not an offer from this employer.

Systemadministrator*in – IT Security & Endpoint Management
Campact

IT-Security-Administrator/in (d/m/w)
Hochschule Flensburg · Flensburg

(Senior) IT Manager / IT-Security (m/w/d) – Frankfurt School of Finance & Management
Frankfurt School of Finance & Management gGmbH · Frankfurt am Main

IT Security Specialist
Deutsches Krebsforschungszentrum · Heidelberg