Product Security Engineer at N26
Berlin
on-site · full-time · Visa sponsorship
Responsibilities:
- Advise engineering teams on secure architecture and design across microservices, mobile apps and AI-driven features (GenAI/LLM).
- Conduct threat modeling, application security design reviews and code reviews to embed security across the SDLC.
- Perform penetration tests and security assessments for internal and external services, including AI components and data pipelines.
- Build and maintain SSDLC tooling, automation frameworks and checks to detect vulnerabilities early.
- Develop automation to integrate security gates into CI/CD and enable self-service secure deployments.
- Train engineering teams and security champions on secure coding, AI-specific risks and data governance considerations.
- Respond to security incidents and participate in root-cause analysis and remediation guidance.
- Research and proactively surface new attack vectors targeting microservices, mobile apps and LLM-based systems.
Requirements:
- Strong experience in application and product security across cloud, web and mobile environments.
- Practical skills in threat modeling, penetration testing and secure code review methodologies.
- Proficiency with Python or Go and experience building security automation/tooling.
- Solid understanding of microservices architecture, cloud platforms and SSDLC practices.
- Knowledge of AI/LLM privacy and security risks, data governance and mitigations for model-enabled features.
- Familiarity with OWASP Top 10, SAST/DAST, fuzzing and vulnerability remediation workflows.
- Ability to communicate security trade-offs clearly to engineers and product stakeholders.
- Experience participating in incident response and proactive security research.