IT Security Engineer at PSI Groups
Berlin, Berlin, Germany -
Full Time


Start Date

Immediate

Expiry Date

07 Dec, 26

Salary

0.0

Posted On

08 Sep, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Industry

Information Technology & Services

Description

JOB TITLE

IT Security Engineer

SKILLS

With professional experienceSeveral years of professional experiencedockerContinuous IntegrationISO 2700xCloud ComputingContinuous DeploymentAIKubernetesIncident ManagementIT securityPenetration testsSoftware developmentApplication safetyITOWASPPractical experienceSolid knowledge

The PSI Group develops software products for optimizing energy and material flows in utilities and industry. As an independent software manufacturer with over 2,300 employees, PSI has been a technology leader in process control systems since 1969. These systems combine AI methods with industrially proven optimization techniques to ensure sustainable energy supply, production, and logistics. The innovative industry products can be operated by the customer themselves or in the cloud.

The Grid & Energy Management business unit specializes in developing software solutions for the energy sector. Our portfolio includes intelligent solutions for network operators in the electricity, gas, heat, oil, and water sectors. Our focus is on modern network control systems and energy trading software for the energy market.

Security Engineer (m/f/d)

  • Aschaffenburg, Berlin, Dortmund
  • PSI Software SE Grid & Energy Management
  • IT security
  • Full-time

Tasks that inspire you

As a software developer for critical infrastructure in the energy sector, we create products whose security is a key factor in ensuring the security of supply for entire networks. With the Cyber ​​Resilience Act and our IEC 62443-4-1 certification, security is evolving from a technical feature to a regulatory requirement for market access.

We are filling a key position that will be responsible for security in the product development of our "Grid & Energy Management (GEM)" business unit. You will not work in a single development team, but rather as a cross-functional enabler for approximately 300 developers at locations in Germany and Poland. The role reports directly to the SVP Engineering and offers high visibility and significant autonomy. Your primary focus will be on empowerment and setting standards across the entire development organization, rather than daily hands-on implementation in the code.

Secure Software Development Lifecycle (sSDLC):

  • You define, establish, and measure the sSDLC practices in a binding manner across all development teams of GEM product development.
  • You define security gates in the CI/CD pipeline and are responsible for their content and compliance.

Security Champions Program:

  • You will build and professionally lead a network of designated security champions within the agile teams.
  • You develop training programs and playbooks, empowering champions to work independently within their teams.

Threat Modeling & Security Governance:

  • You provide methodology, templates and training for threat modeling and review safety-critical models together with our solution architect.
  • You advise Solution Architects and Product Management on security-relevant architecture and roadmap decisions.

Vulnerability & SBOM Management:

  • You are responsible for the product vulnerability management process, including CVE triage and prioritization of mitigation measures.
  • You define the policy and thresholds for SBOM creation as well as the evaluation of open-source and third-party components.
  • You ensure the process capability for the CRA's regulatory reporting obligations.

Regulatory evidence:

  • You are responsible for the safety-related evidence for certification according to IEC 62443-4-1 and the CRA-compliant technical documentation.
  • You support customer audits on the product development side.

Control of security testing:

  • You define the tooling strategy for SAST, DAST and dependency scanning and manage their implementation.
  • You commission and manage external penetration tests and are responsible for following up on the findings.

Interfaces:

  • You will work closely with Solution Architects, Product Management, Operations & Support, and the company-wide Security Governance (CISO), and provide consulting services for product-related security incidents.


Responsibilities
Loading...