# Principal Engineer, Product Security at commercetools
> Posted: 2026-08-07 | Status: Active | Source: StoreJobs.dev

## Role Metadata
- **Employment Type:** Full-Time
- **Workplace:** Hybrid — Berlin, Germany
- **Experience Level:** Senior / Manager
- **Primary Platform:** #commercetools
- **Salary Range:** Undisclosed
- **Required Stack:** commercetools, Kubernetes, Terraform, Vault, Linux, JavaScript, Go, REST API, Web Application Security, DevSecOps, Static Analysis, Secure Code Review, Threat Modeling, GCP, AWS, Azure, SDLC, API security, API, CISSP, CCSP, CKS

## Job Description
Your Impact
As our Principal Engineer Product Security, you'll support the Engineering team by solving challenging technical problems for an ambitious product and enabling teams to "shift left" to build secure services on multi-cloud infrastructure.

You will:

Formulate, evangelise, and drive adoption of the product security strategy
Assess, advise on, and increase the security maturity posture
Create a standardised security architecture and operational best practices
Help track and drive remediation of security and technology risks
Educate product teams on risk assessments, threat modelling, and building secure api-first applications
Review requirements and designs to help product teams address shortcomings
Embed security tooling into the development process
Contribute to the review of external penetration tests and help teams prioritise fixes
Collaborate with product teams to improve overall security and resolve specific issues
Facilitate or lead customer conversations regarding product security
Triage and investigate new attack vectors to determine risk mitigation
Drive security and quality initiatives across the organization and support certification audits
Collaborate with Product Management, Principal Engineers, and legal/compliance teams
Identify skills gaps and facilitate knowledge sharing across the organization

What Sets You Apart
You're a creative problem-solver who is wired to find solutions. You confidently dive into complex challenges and have a talent for making them simple for others. Your curiosity drives you to constantly grow and contribute to an environment of trust and teamwork. Great ideas come from many paths, and your unique perspective matters more than checking every box. What matters most is the mindset you bring to the work.

You bring:

A strong technical background and 5+ years of proven track record in hands-on Product Security
2+ years of experience improving Product Security in a leadership role
Experience with customer-facing security roles and influencing roadmaps in matrix organizations
Experience in a scale-up environment with ambitious and competing priorities
Expertise in formulating, elaborating, and clarifying requirements or priorities
Experience with Secure Architecture design reviews and Threat Modeling
Experience infusing security into various levels of the SDLC
Experience with Static Analysis and Secure Code Review implementations
Sound knowledge of Linux systems, Kubernetes, Terraform, Vault, API, and web application security
Practical experience in DevSecOps and proficiency in at least one scripting language like JavaScript or Go
Project management experience for projects affecting multiple teams
Experience working within an Agile environment with a strong customer focus
Experience setting up and running trainings or onboardings
Clear written and verbal communication in fluent English

AI Aptitude: A genuine curiosity for using AI tools to work smarter and more effectively, paired with a drive to learn and put them into practice in your role.

Nice to Have:
An eagerness to constantly improve and learn about leadership and new technologies

## How to Apply
To view the original listing, see applicant requirements, or apply directly, visit:
https://storejobs.dev/jobs/ct-1827-principal-engineer-product-security?utm_source=ai_assistant
