Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Product Security Engineer (m/f/d) image - Rise Careers
Job details

Product Security Engineer (m/f/d)

Company Description

About Redcare Pharmacy:

As Europe’s No.1 e-pharmacy, Redcare Pharmacy is powered by passionate teams and cutting-edge innovation. We strive to create a healthy, collaborative work environment where every employee feels valued and inspired to contribute to our vision “Until every human has their health”. If you’re seeking a career that offers purpose and aligns with your values, join us and begin your #Redcareer today. 

About the role:

The Product Security Engineer at Redcare will ensure that security is seamlessly integrated into all stages of the software development lifecycle (SDLC), safeguarding the organization’s custom-built software. This role is pivotal in driving a security-first mindset, aligning with Redcare’s goal to be data-driven and KPI-centric. Working closely with Product, Engineering, and Compliance & Governance teams, the Product Security Engineer will develop and implement strategies to protect customer data, meet regulatory requirements, and mitigate security risks across all digital and physical platforms. Key contribution will be to quantify the state of security.

Job Description

About the role:

  • Strategic Security Integration: Collaborate with Engineering to embed secure design principles across the online shops, native apps, AdTech/MarTech platforms, and other custom-built software. Implement security testing tools (SAST, DAST, IAST, SCA).
  • Security Audits: Perform security architecture reviews, threat modelling, and code analysis to identify and mitigate vulnerabilities early. As single point of contact, plan and steer security audits in collaboration with IT Governance and ensure alignment of the product roadmap for fast mitigation.
  • Vulnerability Management, Thread Detection and Risk Mitigation: Lead proactive vulnerability identification and management, ensuring risks are remediated efficiently. Use tools like Nessus, Qualys, or similar, for continuous scanning, result interpretation, and mitigation. Design, maintain, and execute incident response protocols, coordinating with engineering and governance during product security incidents.
  • Data Protection and Compliance: Work with Product Analytics and IT Compliance teams to ensure adherence to regulations like GDPR and PCI-DSS. Accountability of steering customer data security and privacy across personalization, search, and sponsored product features in the department.
  • Collaboration and Security Awareness: Partner with Engineering Managers, QA Leads, IT Operations and SRE teams to integrate fast and reliable security testing into development and continuous deployment pipelines. Drive education and training for developers on secure coding practices and threat awareness, and topics like OWASP Top 10, secure APIs, and compliance
  • Metrics and Continuous Improvement: Quantify the state of security by defining relevant metrics and driving their adoption through the entire engineering organization.

Qualifications

About you:

  • Proven experience in product security, cybersecurity, securing APIs and related fields. Strong skills in vulnerability management tools, secure code review, and automation frameworks.
  • Deep understanding of secure software development lifecycle, application security, DevSecOps practices, integrating security into CI/CD pipelines and cloud-native security practices. Proven ability to collaborate with DevOps, engineering, and security teams to promote a security-first mindset.
  • Familiarity with data protection regulations (e.g., GDPR) and their application in software development.
  • Strong coding and scripting skills in at least one of the following:
    • Python, Bash, or PowerShell for security automation, log analysis, and tool integration.
    • Java or Node.js for secure, high-performance systems and tools, and API and backend development.
    • Infrastructure automation languages such as Terraform HCL or Ansible YAML.
  • Knowledge of secure coding practices and the OWASP Top 10. 
  • Exceptional problem-solving and communication skills, with the ability to educate and influence cross-functional teams.

Additional Information

About your benefits:

In order to provide our employees with the best possible support for their individual needs, we offer a wide range of benefits:

  • Sports: Stay healthy. Profit from a membership (M) package at Urban Sports Club, so that you can take advantage of a huge variety of sport offers.

  • Mental Health: Get quick and professional help from psychologists of Likeminded if you feel overwhelmed in private or professional life. Anonymous and free of charge. 

  • Work from Home: If your job does not require you to be present in the office, we can arrange the place you work from individually - even for up to 20 days a year anywhere in the EU.

  • Mobility: We provide our employees with a fully costed Deutschland Ticket which can be used at any time. Click here to learn more.

  • Personal development: Grow! We support and encourage your individual development through various in- and external trainings.

  • And many more :)

 

Remote work policy:

Our offices are open, but you are free to work from home, from any location in Germany. It is entirely up to you if you want to pop into the office every now and again, or if you work from home all the time. At the same time, we value relationship between all members of the area and therefore we have regular team and area anchor days on which every team member is asked to come to the office.

Redcare Pharmacy Glassdoor Company Review
4.4 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Redcare Pharmacy DE&I Review
3.54 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of Redcare Pharmacy
Redcare Pharmacy CEO photo
Olaf Heinrich
Approve of CEO

Average salary estimate

$70000 / YEARLY (est.)
min
max
$60000K
$80000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Product Security Engineer (m/f/d), Redcare Pharmacy

Are you looking to make a real impact in the world of product security? At Redcare Pharmacy, we are excited to invite you to join our team as a Product Security Engineer (m/f/d) in our Cologne office! As Europe’s leading e-pharmacy, we are not just about filling prescriptions; we're passionate about ensuring every individual has access to health and wellness. In this pivotal role, you'll play a key part in integrating security seamlessly throughout the software development lifecycle, ensuring the integrity of our custom-built software. You'll collaborate closely with Product, Engineering, and Compliance teams to safeguard customer data while driving a security-first mindset across our organization. Your responsibilities will include implementing security testing tools, conducting security audits, and managing vulnerabilities, all while maintaining compliance with regulations like GDPR and PCI-DSS. If you have a background in product security and a passion for working in a collaborative environment where innovations thrive, this might just be your dream job. Join us in our mission to provide secure, user-friendly health solutions, and start your #Redcareer today at Redcare Pharmacy.

Frequently Asked Questions (FAQs) for Product Security Engineer (m/f/d) Role at Redcare Pharmacy
What are the responsibilities of a Product Security Engineer at Redcare Pharmacy?

As a Product Security Engineer at Redcare Pharmacy, your key responsibilities include integrating security into every phase of the software development lifecycle, performing security audits, managing vulnerabilities, and driving collaboration with various teams. You will ensure adherence to regulations such as GDPR while implementing security testing tools and strategies to protect our customer's data.

Join Rise to see the full answer
What qualifications are needed to become a Product Security Engineer at Redcare Pharmacy?

To step into the role of Product Security Engineer at Redcare Pharmacy, you will need proven experience in product security or cybersecurity, strong skills in vulnerability management tools, and a deep understanding of secure software development practices. Familiarity with data protection regulations, secure coding skills in languages like Python or Java, and exceptional problem-solving abilities are essential.

Join Rise to see the full answer
What is the work environment like for a Product Security Engineer at Redcare Pharmacy?

Working as a Product Security Engineer at Redcare Pharmacy, you will enjoy a dynamic and supportive environment that encourages collaboration and innovation. With flexible remote work options and a commitment to employee well-being, you will thrive in a culture that values security and teamwork while driving impactful health solutions.

Join Rise to see the full answer
How does Redcare Pharmacy support the personal development of a Product Security Engineer?

At Redcare Pharmacy, we believe in the constant growth of our team members. As a Product Security Engineer, you will have access to various in- and external trainings aimed at enhancing your skills. We encourage you to pursue individual development opportunities that will not only benefit you but also strengthen our team's security posture.

Join Rise to see the full answer
Why is the role of Product Security Engineer important at Redcare Pharmacy?

The role of Product Security Engineer at Redcare Pharmacy is critically important in ensuring the integrity of our pharmacy’s software systems. As we grow as a leader in e-pharmacy, safeguarding customer data and ensuring compliance with regulations is paramount. Your expertise will help us maintain a secure environment while fostering innovation in healthcare solutions.

Join Rise to see the full answer
Common Interview Questions for Product Security Engineer (m/f/d)
Can you explain the secure software development lifecycle?

Certainly! The secure software development lifecycle (SDLC) emphasizes integrating security practices at every stage of software development. From requirements gathering, design, and development, to deployment and maintenance, each phase must have security considerations such as threat modeling, secure coding, and vulnerability assessments to mitigate risks effectively.

Join Rise to see the full answer
How do you conduct a threat model?

Conducting a threat model involves identifying potential threats, vulnerabilities, and the overall risk to the system. Start by defining the architecture of the application, identify potential attackers, and analyze their motivations. Then evaluate what vulnerabilities may be exploited and prioritize them based on potential impact and likelihood, allowing for informed risk mitigation strategies.

Join Rise to see the full answer
What tools do you use for vulnerability management?

I frequently utilize tools such as Nessus and Qualys for vulnerability scanning and management. These tools help in continuous scanning of applications and infrastructure, allowing for quick identification, tracking, and remediation of vulnerabilities within the development cycle, ensuring a proactive approach to security.

Join Rise to see the full answer
Describe a time you identified and resolved a security vulnerability.

In a previous role, I discovered a critical security flaw within an API endpoint that allowed unauthorized access to sensitive data. I quickly analyzed the code, identified the issue, and implemented a secure fix. I then conducted a team training session on secure coding practices to prevent similar issues in the future, reinforcing the importance of a security-first mindset.

Join Rise to see the full answer
What is your approach to educating developers on secure coding practices?

My approach involves interactive workshops and regular training sessions focusing on secure coding practices, such as the OWASP Top 10 vulnerabilities. By using real-world examples and hands-on exercises, I can effectively engage developers and help them understand the significance of security in their daily tasks.

Join Rise to see the full answer
How do you ensure compliance with data protection regulations like GDPR?

To ensure compliance with regulations like GDPR, I implement privacy by design principles within the software development process. This involves training the team on compliance requirements, conducting regular audits, and ensuring that personal data is collected, processed, and stored securely, thereby safeguarding user privacy while aligning with legal obligations.

Join Rise to see the full answer
What is the role of DevSecOps in product security?

DevSecOps integrates security practices within the DevOps process, ensuring that security is a shared responsibility. It involves collaboration across development, security, and operations teams to automate security checks, conduct regular tests, and maintain compliance, therefore enhancing the overall security posture while allowing for rapid delivery of applications.

Join Rise to see the full answer
Can you explain the OWASP Top 10 and its significance?

The OWASP Top 10 is a widely recognized list of the most critical security risks to web applications. It highlights vulnerabilities such as injection flaws and cross-site scripting. Understanding these vulnerabilities allows developers to focus on securing applications effectively, ultimately reducing the risk of security breaches.

Join Rise to see the full answer
How do you approach incident response in a product security role?

In product security, my approach to incident response includes establishing and maintaining an incident response plan. This encompasses identifying the incident, containing the breach, eradicating the cause, and recovering affected systems. Effective communication and collaboration among teams are crucial for resolving incidents promptly and learning for future improvement.

Join Rise to see the full answer
How do you quantify the state of security within an organization?

Quantifying the state of security involves defining relevant metrics and KPIs that reflect security performance, such as the number of vulnerabilities identified and remediated over time, compliance audit results, and user awareness training completion rates. By tracking these metrics, we can measure progress, identify areas for improvement, and foster a culture of continuous security enhancement.

Join Rise to see the full answer
Similar Jobs
Redcare Pharmacy Remote Probsteigasse 12-18, Cologne, Germany
Posted 11 days ago

Join Redcare Pharmacy as a Senior Data Analyst to lead strategic data initiatives and mentor a dynamic team in a thriving e-pharmacy environment.

Redcare Pharmacy Remote Erik de Rodeweg 11/13, Sevenum, Netherlands
Posted 9 days ago

Join Redcare Pharmacy as a Senior Recruiter to drive talent acquisition for corporate functions in a leading European e-pharmacy.

Drees & Sommer SE Remote Κτίριο GANAS & GANAS, Αγροτεμάχιο 51, Thermi 570 01, Greece
Posted 3 days ago

Join Drees & Sommer as a Senior Mechanical Engineer/HVAC Design Expert and lead international projects that shape sustainable futures.

MAT Holdings, Inc Hybrid 6700 Wildlife Wy, Long Grove, IL 60047, USA
Posted 2 days ago

Seeking an Engineering Intern at MAT Holdings to assist in friction material testing and engineering processes within a global manufacturing leader.

Photo of the Rise User

Rockwell Automation invites aspiring engineers to begin their careers in the Engineer in Training program that offers a structured path to practical experience and growth.

Photo of the Rise User
Posted 2 days ago

As a Roadway Design Lead at AECOM, you'll lead transformative roadway engineering projects, ensuring excellence from concept to construction.

Photo of the Rise User

Join Adtalem Global Education as a Software Engineer and foster innovation in higher education through advanced software solutions.

Photo of the Rise User
Posted 7 days ago

Embark on an internship at Kimley-Horn in Richmond, where engineering students contribute to impactful projects while learning from industry leaders.

Photo of the Rise User

Join Raytheon's mechanical design team to work on advanced Stealth technology and contribute to national defense.

Photo of the Rise User
American Express Remote Phoenix, Arizona, United States
Posted 2 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Join American Express as an Engineer and contribute to redefining the merchant payment experience through innovative solutions using Java technologies.

Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Customer-Centric
Fast-Paced
Growth & Learning
Medical Insurance
Dental Insurance
401K Matching
Paid Time-Off
Maternity Leave
Paternity Leave
Mental Health Resources
Flex-Friendly
MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 11, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Tallmadge just viewed Manufacturing and Process Engineer at CVRx
Q
Someone from OH, Columbus just viewed Part-Time Medical Assistant at QualDerm Partners
Photo of the Rise User
Someone from OH, Cincinnati just viewed Summer 2025 Intern – Finance – Michigan at Stryker
Photo of the Rise User
Someone from OH, Cleveland just viewed Remote Customer Service Representative at Conduent
Photo of the Rise User
Someone from OH, Cleveland just viewed Customer Support Team Lead (6-month Contract) at Jane App
o
Someone from OH, Cincinnati just viewed Marketing and Communications Consultant at osu
Photo of the Rise User
Someone from OH, Toledo just viewed Registered Nurse (Part-time) at Calibrate
Photo of the Rise User
19 people applied to Machinist Apprentice at LLNL
Photo of the Rise User
Someone from OH, Toledo just viewed Clinical Research Associate II at Alimentiv
Photo of the Rise User
Someone from OH, Cleveland just viewed IT Support Engineer at Level AI
Photo of the Rise User
Someone from OH, Dayton just viewed Customer Content Specialist at Cision
Photo of the Rise User
Someone from OH, Cuyahoga Falls just viewed Senior Corporate Communications Manager at Bumble Inc.
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Financial Analyst at Workday
Photo of the Rise User
Someone from OH, Cincinnati just viewed Financial Planning and Analysis Lead at JLL
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Financial Analyst at American Express
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Analyst, Operations at American Express
Photo of the Rise User
Someone from OH, Cincinnati just viewed Strategic Finance Analyst, Corporate at Benchling
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Analyst, Project Finance at Apex Clean Energy
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior FP&A Analyst, Sales at GitLab
Photo of the Rise User
Someone from OH, Cincinnati just viewed FP&A Analyst at Lithic