Staff Product Security Engineer
Aiven · Helsinki
Hybridisenior💰 5,950–7,250 EURTech · SoftwareJulkaistu 23.09.2026 klo 03.00
Taidot
vulnerability managementsecurity testingrisk managementcompliance (pci dss, iso 27001, soc 2)distributed systemsmicroservices architecturenetwork security scanningpenetration testingiam automationai securityaudit support
Työn kuvaus
We’re a global team of over 400 people, working together to push the boundaries of open-source technology and multi-cloud solutions. Our vision is to help developers, builders, and creators bring their ideas to life with speed and simplicity, by providing a cloud data platform that makes open-source databases, search, streaming, and application infrastructure easily accessible to everyone.
The Role:
We are looking for a
Staff Product Security Engineer
to join our Product Security team. The role of Aiven’s product security is to identify, report, and assist with the remediation of security vulnerabilities, to manage our bug bounty program, and to provide technical security insights into new products that the Aiven engineering organization is developing. The Staff Product Security Engineer will also work closely with the Identity and Access Management team and Security Operations to ensure the security of our products and infrastructure.
What You'll Do:
Vulnerability Management: Triaging and analyzing results from our vulnerability scanners. This includes identifying and documenting false positives to minimize unnecessary remediation efforts. You will work with documentation and other team members to identify risk-based decisions and write responses to audit questions.
Network Security Scanning: Participate in the regular review of internal network vulnerability scans. Collaborate with network and system administrators to prioritize and remediate identified vulnerabilities, escalating critical issues as needed.
Security Assessment: Independently conduct security testing of our products using a variety of methodologies, including tool-based assessment and manual testing. Report and document findings for internal users. Apply and state industry-standard methodologies for testing to meet audit requirements.
Issue triage: You will evaluate issues reported by internal staff, customers, and third parties as to reproducibility, and track information on true positive security vulnerabilities.
Remediation validation: You will determine whether engineering changes have fixed security vulnerabilities, and conduct a gap analysis where required.
Compliance Support: Contribute to compliance efforts (e.g., PCI DSS, ISO 27001, SOC 2) by assisting in the preparation of reports and documentation related to vulnerability scanning activities. This may involve documenting false positives, validating compensating controls, and ensuring accurate reporting.
Scanner Optimization: Contribute to the ongoing improvement of our vulnerability scanning program by identifying and reporting any gaps in scanner coverage. This includes verifying that all intended systems and applications are being scanned and suggesting improvements to scanning configurations.
Audit: Assist in execution of 3rd-party audits and penetration tests IAM Automation: Assist with the automation of identity and access management procedures and reporting AI Security: Assess the security of artificial intelligence algorithms in Aiven’s products What We're Looking For:
We are looking for talented self-starters who want to learn about security and grow into roles such as Software Engineer in Security and Information Security Analyst. We will consider candidates with less security-specific experience but with the desire to learn!
Examples of attributes for success in this role include:
A bachelor's or master’s degree in computer science, engineering, information security, information technology, or equivalent training 5+ years of experience in information security or a related field Experience in software development, site reliability engineering, software or IT architecture, business analysis, risk management, and project management are assets Detailed knowledge of security, distributed systems, and microservices architecture Senior certifications in hyperscaler clouds and in security testing; certifications in risk management are beneficial Detailed understanding of risk management and vulnerability management practices, specifically in a multi-cloud environment Relevant experience from modern technologies such as public cloud and networking Experience with programming and software development Fluency in English, verbal and written Amazing! What’s next:
If you think Aiven is the place for you and that our Values align with yours, send us your resume and we’ll get in touch!
Global Benefits:
Our global benefits are designed to help you thrive and grow, personally and professionally:
Participate in Aiven’s equity plan.
Balance work and life with our hybrid work policy.
Choose the equipment you need to set yourself up for success.
Use your Professional Development Plan budget for learning opportunities.
Receive holistic wellbeing support through our global Employee Assistance Program.
Inquire about our Global Time Off Commitment (Parental and Sick Leave, as well as Personal Time) Enjoy country-specific benefits for our global cast.
How to Recognize and Avoid Employment Scams: