yellowshark
Baden
Senior Product Security Engineer / DevSecOps (m/f) 80-100%
- 28 September 2026
- 100%
- Permanent position
- CHF 125 000 - 145 000 /year
- 5400 Baden
About the job
yellowshark AG is a leading Swiss personnel service provider specialising in IT, commercial professions, industry and technology. Throughout the German-speaking part of Switzerland, you can take your career to the next level with yellowshark by connecting you with renowned companies, and we have been doing this for over 15 years!
With sound market knowledge and a broad network, yellowshark offers you customised solutions for permanent positions. Benefit from a dedicated team that understands your career goals and opens up exciting opportunities with attractive employers. Take the next step with yellowshark by your side!
Have we piqued your interest? Then apply today with your complete and meaningful application documents. We look forward to getting to know you!
- Anchor security-by-design throughout the entire software development lifecycle
- Integrate security automatically into CI/CD pipelines and continuously optimise it
- Establish SAST, DAST as well as dependency and container scanning
- Create threat models and identify technical risks early
- Be responsible for vulnerability management and incident response
- Targeted further development of security toolchain, standards and processes
- Conduct security assessments, risk analyses and audits
- Transfer requirements from ISO 27001, NIS2, CRA and BSI into development
- Advise engineering, architecture and DevOps as a technical security sparring partner
- Several years of experience in software engineering with a strong security focus
- Profound know-how in product security, application security and security architecture
- Experience with secure software development and modern architectural principles
- Confident handling of threat modelling, ideally STRIDE
- Practical experience with DevSecOps, CI/CD and automated security checks
- Experience with SAST, DAST, dependency and container scanning
- Knowledge of NIS2, CRA, ISO 27001 or BSI standards
- Know-how in OT, IoT or SOC environments is an advantage
- Fluent German skills (C2) as well as very good English skills (at least B2)
- High scope for design and responsibility
- Flexible full-time or part-time employment
- Challenging technical topics with a long-term development focus
- Close collaboration with engineering, architecture and DevOps
- Targeted professional and personal training
- Short decision-making paths and a lot of personal responsibility
With sound market knowledge and a broad network, yellowshark offers you customised solutions for permanent positions. Benefit from a dedicated team that understands your career goals and opens up exciting opportunities with attractive employers. Take the next step with yellowshark by your side!
Have we piqued your interest? Then apply today with your complete and meaningful application documents. We look forward to getting to know you!
Responsibilities
- Design and further develop security architectures for demanding software products- Anchor security-by-design throughout the entire software development lifecycle
- Integrate security automatically into CI/CD pipelines and continuously optimise it
- Establish SAST, DAST as well as dependency and container scanning
- Create threat models and identify technical risks early
- Be responsible for vulnerability management and incident response
- Targeted further development of security toolchain, standards and processes
- Conduct security assessments, risk analyses and audits
- Transfer requirements from ISO 27001, NIS2, CRA and BSI into development
- Advise engineering, architecture and DevOps as a technical security sparring partner
Profile
- Degree in computer science, cyber security or comparable qualification (FH/Uni/ETH)- Several years of experience in software engineering with a strong security focus
- Profound know-how in product security, application security and security architecture
- Experience with secure software development and modern architectural principles
- Confident handling of threat modelling, ideally STRIDE
- Practical experience with DevSecOps, CI/CD and automated security checks
- Experience with SAST, DAST, dependency and container scanning
- Knowledge of NIS2, CRA, ISO 27001 or BSI standards
- Know-how in OT, IoT or SOC environments is an advantage
- Fluent German skills (C2) as well as very good English skills (at least B2)
Additional Information
- Central security role with direct influence on products and architecture- High scope for design and responsibility
- Flexible full-time or part-time employment
- Challenging technical topics with a long-term development focus
- Close collaboration with engineering, architecture and DevOps
- Targeted professional and personal training
- Short decision-making paths and a lot of personal responsibility