Auf einen Blick
- Aufgaben: Arbeite eng mit Ingenieuren zusammen, um Sicherheitslösungen in Code und Plattformen zu integrieren.
- Unternehmen: On ist ein innovatives Unternehmen, das Technologie und Bewegung vereint.
- Vorteile: Attraktives Gehalt, flexible Arbeitszeiten und ein kreatives Arbeitsumfeld.
- Weitere Informationen: Wachsendes Team mit vielen Möglichkeiten zur beruflichen Weiterentwicklung.
- Warum dieser Job: Gestalte die Zukunft der Sicherheit und schütze unsere Plattform vor Risiken.
- Qualifikationen: Erfahrung in Plattform-Sicherheit und Teamarbeit sind erforderlich.
ph3In short /h3 pAt On, our technology moves as fast as our runners: always evolving, always pushing boundaries. We're building a world-class platform to ignite the human spirit through movement, and our Information Security team is the trusted guardian of that mission. Join a collaborative team of curious minds who believe security should not stop at recommendations. We are moving security closer to engineering — into the code, pipelines, platforms, cloud environments, and identity systems where risks are created and remediated. We are looking for a Platform Security Engineer who wants to work side-by-side with Engineering, Platform Ops, and Cloud Security Architecture teams. This is a deeply hands-on role for someone who can open pull requests, build guardrails, remediate vulnerabilities, reduce attack surface, and help make secure engineering the default way of working at On. This role is for someone who sees security not as a gate, but as a force multiplier for engineering excellence. /p h3In short /h3 pAt On, our technology moves as fast as our runners: always evolving, always pushing boundaries. We're building a world-class platform to ignite the human spirit through movement, and our Information Security team is the trusted guardian of that mission. Join a collaborative team of curious minds who believe security should not stop at recommendations. We are moving security closer to engineering — into the code, pipelines, platforms, cloud environments, and identity systems where risks are created and remediated. We are looking for a Platform Security Engineer who wants to work side-by-side with Engineering, Platform Ops, and Cloud Security Architecture teams. This is a deeply hands-on role for someone who can open pull requests, build guardrails, remediate vulnerabilities, reduce attack surface, and help make secure engineering the default way of working at On. This role is for someone who sees security not as a gate, but as a force multiplier for engineering excellence. /p h3Your mission /h3 pAs a Lead Platform Security Engineer, your mission is to turn security requirements into implemented controls. You will work directly with Engineering, Platform Ops, and Cloud Security Architecture teams to embed security into how platforms and products are designed, built, deployed, and operated. You will move beyond advisory security by contributing directly to platform repositories, CI/CD pipelines, infrastructure-as-code, identity controls, and security automation. Your success will be measured by risk reduction: merged fixes, fewer repeat findings, stronger guardrails, and a more resilient engineering ecosystem. /p ul liWork side-by-side with Engineering, Platform Ops, and Cloud Security Architecture teams to translate security requirements, threat models, and vulnerability findings into practical engineering outcomes. /li liContribute hands-on to platform, CI/CD, infrastructure-as-code, and security-control repositories through pull requests, configuration changes, automation, and policy-as-code. /li liBuild and improve scalable security guardrails across the software delivery lifecycle, including secrets scanning, dependency scanning, infrastructure-as-code checks, secure build controls, and AI development workflows. /li liPartner with engineering teams to remediate vulnerabilities, reduce attack surface, and prevent recurring findings through direct fixes, paired engineering work, or automated controls. /li liStrengthen identity and access security for both human and non-human identities, including service accounts, CI runners, automation workflows, coding agents, MCP servers, and bots. /li liSupport secure-by-design reviews and threat modeling for cloud, platform, identity, CI/CD, and AI-enabled development, ensuring risks are addressed before implementation starts. /li liParticipate in operational ownership for security-relevant infrastructure and controls you materially contribute to, including root-cause analysis and incident remediation where needed. /li /ul h3Your story /h3 pYou are a hands-on lead security engineer who enjoys working close to engineering teams, platforms, code, and infrastructure. You are not satisfied with writing recommendations and waiting for someone else to implement them. You like to build, fix, automate, and improve the system at the source. /p pYou combine strong security judgment with practical engineering skills and know how to make security controls work in real-world development environments. /p ul liYou bring 10+ years of experience in security engineering, platform security, cloud security, DevSecOps, application security, or infrastructure security. /li liYou have hands-on experience contributing to engineering workflows using Git, pull requests, code reviews, CI/CD pipelines, automation, or infrastructure-as-code. /li liYou are comfortable working with cloud environments, ideally including Google Cloud Platform, and understand cloud IAM, network exposure, platform security, and secure configuration patterns. /li liYou have practical experience with vulnerability remediation and know how to move from finding to fix, including validating closure and preventing recurrence. /li liYou understand CI/CD security and have experience with controls such as secrets scanning, dependency scanning, SAST, infrastructure-as-code scanning, policy-as-code, or secure build pipelines. /li liYou are familiar with identity and access security concepts, including least privilege, privileged access, service accounts, non-human identities, temporary access, and credential rotation. /li liYou are able to translate threat models, risk scenarios, and architecture requirements into concrete technical controls that engineers can implement and operate. /li liYou are curious about emerging AI security risks and motivated to secure modern development workflows involving AI-generated code, coding agents, MCP servers, and automation. /li liYou are a natural collaborator who can build trust with Engineering, Platform Ops, Cloud Security Architecture, Cyber Defence, and GRC teams. /li liYou communicate clearly with both technical and non-technical stakeholders, focusing on practical risk reduction rather than theoretical security perfection. /li liYou have a pragmatic mindset and know how to balance speed, security, engineering quality, and business impact. /li /ul h3What We Offer /h3 pOn is a place that is centered around growth and progress. We offer an environment designed to give people the tools to develop holistically – to stay active, to learn, explore and innovate. Our distinctive approach combines a supportive, team-oriented atmosphere, with access to personal self-care for both physical and mental well-being, so each person is led by purpose. /p pOn is an Equal Opportunity Employer. We are committed to creating a work environment that is fair and inclusive, where all decisions related to recruitment, advancement, and retention are free of discrimination. /p /p #J-18808-Ljbffr
Lead - Platform Security Engineer Arbeitgeber: On
On ist ein hervorragender Arbeitgeber, der eine dynamische und unterstützende Arbeitsumgebung bietet, in der Mitarbeiter ganzheitlich wachsen können. Mit einem starken Fokus auf Teamarbeit und persönliches Wohlbefinden fördert das Unternehmen Innovation und kontinuierliches Lernen, während es gleichzeitig eine faire und inklusive Kultur pflegt. Die Möglichkeit, an der Spitze einer der innovativsten Technologien im Bereich Fußbekleidung zu arbeiten, macht diese Position besonders attraktiv für alle, die in einem schnelllebigen, globalen Umfeld tätig sein möchten.