We're Celonis, the global leader in Process Mining technology and one of the world's fastest-growing SaaS firms. We believe there is a massive opportunity to unlock productivity by placing data and intelligence at the core of business processes - and for that, we need you to join us.
The Team:
Within our InfoSec organization, Our global security engineering team is responsible for designing, building, and enhancing the underlying security components that help with securing the Celonis Application and Platforms stacks. We think about both offensively and defensively. We continuously monitor our global security posture and are always adapting to the ever-changing threat landscape. The security engineering team is always looking for talented subject matter experts in application, platform and offensive security.
Want more jobs like this?
Get Software Engineering jobs that are Remote delivered to your inbox every week.
The Role:
Celonis is looking for a Senior Application Security Engineer to help assess and validate that our services, applications, and websites are designed and implemented to the highest security standards. You will be responsible for analyzing the security of applications and services, discovering and addressing security issues, building security automation, and quickly reacting to new threat scenarios. You will have the opportunity to mentor the application security engineers who are building and securing our cutting-edge application layer services.
The work you’ll do:
- Conduct threat modeling, secure code reviews, and security assessments across web/native application, and infrastructure, proactively identifying vulnerabilities and providing clear recommendations to the development teams.
- Conduct security architecture reviews of the application stack, including applications built on cloud and emerging technologies.
- Review source code for potential security issues, writing security test cases to check for vulnerabilities or broken/missing security controls.
- Provide specific risk assessment and remediation guidelines for developers and business owners.
- Research the latest security best practices, trends, threats and vulnerabilities, and technology frameworks.
- Perform in-depth security review of new features. This includes identifying security vulnerabilities (including, but not limited to OWASP top ten), reviewing code in Java or C++, verifying security posture through source-assisted security assessments and penetration testing (using manual/automated techniques with tools such as Burp suite and Semgrep).
- Partner with engineering and operation teams to integrate mitigation controls into continuous integration, delivery and deployment processes.
- Work on essential areas to develop security baseline for application, container, cloud, orchestration platforms, and integrate it into the CI/CD pipeline.
- Implement security architecture, methods, and controls required to meet security, compliance, and audit requirements (NIST controls, SOC2, etc.).
- Lead complex security projects, from initial planning through execution and completion.
- Act as internal advocate and subject matter expert on secure software development practices.
- Lead secure development awareness communications and training initiatives.
The qualifications you’ll need:
- 5+ years of previous experience in information security.
- 3+ years of previous experience working within software development.
- A bachelor’s degree in Computer Science/Information Security/Cyber Security or equivalent.
- Proven track record of performing secure design reviews and threat modeling on complex systems.
- Comprehensive knowledge of fundamental application security principles, secure coding practices, and common web application vulnerabilities, including those listed in OWASP Top 10.
- Excellent written and oral communication skills; ability to articulate and communicate risks to both technical and non-technical audiences.
- Demonstrated ability to work both independently and in cross-functional teams, effectively multitasking in a fast-paced environment.
- Firm understanding of enterprise class application architectures that are highly scalable and reliable and the expertise to secure them.
- History of leading and delivering complex security projects.
What Celonis Can Offer You:
- The unique opportunity to work with industry-leading process mining technology
- Investment in your personal growth and skill development (clear career paths, internal mobility opportunities, L&D platform, mentorships, and more)
- Great compensation and benefits packages (equity (restricted stock units), life insurance, time off, generous leave for new parents from day one, and more). For intern and working student benefits, click here.
- Physical and mental well-being support (subsidized gym membership, access to counseling, virtual events on well-being topics, and more)
- A global and growing team of Celonauts from diverse backgrounds to learn from and work with
- An open-minded culture with innovative, autonomous teams
- Business Resource Groups to help you feel connected, valued and seen (Black@Celonis, Women@Celonis, Parents@Celonis, Pride@Celonis, Resilience@Celonis, and more)
- A clear set of company values that guide everything we do: Live for Customer Value, The Best Team Wins, We Own It, and Earth Is Our Future
About Us:
Celonis helps some of the world’s largest and most esteemed brands make processes work for people, companies and the planet. With over 5,000 enterprise customer deployments across nearly every industry, the Celonis Process Intelligence Platform uses process mining and AI to give you a living digital twin of your business operation. It’s system-agnostic and without bias, and empowers companies to reduce waste, create value and benefit people across the top, bottom, and green lines. Since 2011, the Celonis platform has enabled its customers to identify more than $18 billion in value. Celonis is headquartered in Munich, Germany, and New York City, USA, with more than 20 offices worldwide.
Get familiar with the Celonis Process Intelligence Platform by watching this video.
Data Privacy, Equal Opportunity, and Accessibility Information
Celonis is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment and equal opportunity in all aspects of employment. We will not tolerate any unlawful discrimination or harassment of any kind. We make all employment decisions without regard to race/ethnicity, color, sex, pregnancy, age, sexual orientation, gender identity or expression, transgender status, national origin, citizenship status, religion, physical or mental disability, veteran status, or any other factor protected by applicable anti-discrimination laws. As a US federal contractor, we are committed to the principles of affirmative action in accordance with applicable laws and regulations. Different makes us better.
Any information you submit to Celonis as part of your application will be processed in accordance with Celonis’ Statements on Data Privacy, Equal Opportunity and Accessibility.
Please be aware of common job offer scams, impersonators and frauds. Learn more here.
By submitting this application, you confirm that you agree to the storing and processing of your personal data by Celonis as described in our Privacy Notice for the Application and Hiring Process.