SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Product Security Engineer

Aiven - Helsinki, Uusimaa, Finland - Hybrid - posted 2026-08-10

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Aiven is seeking a Staff Product Security Engineer to join its Product Security team. The role focuses on identifying, reporting, and remediating security vulnerabilities across Aiven's cloud data platform, which provides open-source databases, search, streaming, and application infrastructure. Key responsibilities include: • Vulnerability Management: Triage and analyze vulnerability scanner results, identify false positives, and document findings to support risk-based remediation decisions and audit responses. • Security Assessment: Independently conduct security testing using tool-based and manual methodologies, applying industry-standard practices to meet audit requirements. • Issue Triage & Validation: Evaluate security issues from internal staff, customers, and third parties; determine reproducibility and track true positives. Validate engineering fixes and conduct gap analysis. • Network Security: Participate in regular internal network vulnerability scans, collaborate with infrastructure teams to prioritize remediation, and escalate critical issues. • Compliance Support: Contribute to compliance initiatives (PCI DSS, ISO 27001, SOC 2) by preparing documentation, validating compensating controls, and ensuring accurate reporting. • Scanner Optimization: Identify gaps in vulnerability scanning coverage and suggest improvements to scanning configurations. • Audit & Penetration Testing: Assist in execution of third-party audits and penetration tests. • IAM Automation: Support automation of identity and access management procedures and reporting. • AI Security: Assess security of AI algorithms in Aiven's products. Required qualifications: Bachelor's or Master's degree in computer science, engineering, information security, or equivalent; 5+ years in information security or related field; detailed knowledge of security, distributed systems, and microservices architecture; understanding of risk and vulnerability management in multi-cloud environments; experience with modern cloud technologies and networking; programming/software development experience; fluent English. Desirable: Senior certifications in hyperscaler clouds and security testing; experience in software development, SRE, architecture, business analysis, or project management.

Similar roles