Principal Engineer, Product Security
commercetools
| Company | commercetools |
| Category | Engineering |
| Location | München |
| Remote | Hybrid |
| Employment | Not stated |
| Level | Lead |
| Salary | Not stated by the employer |
| Posted | 2 Jul 2026 |
| Last verified | 3 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
About Commercetools
Real innovation starts with a strong foundation, and at commercetools, that comes from the perfect balance of our product and our people. Behind every leap forward is a collective of builders, explorers, doers, makers, and problem-solvers. The kind of people who not only pioneered a more flexible approach to commerce architecture but also shaped the culture of experimentation that approach unlocked. Together they are the engine of commerce innovation today. At commercetools, we power the next era of commerce for our customers. Whether it’s AI-driven solutions that help enterprises make smarter business decisions, bridging digital and physical shopping experiences, or enabling entirely new ways for industries to connect with their customers, we help the world’s most ambitious companies experiment, scale, and grow without limits. Here the best idea wins, not the loudest voice. You will have the tools, trust, and space to not only build the future of commerce, but to build your own.
Your Impact
As our Principal Engineer Product Security , you’ll support the Engineering team by solving challenging technical problems for an ambitious product and enabling teams to "shift left" to build secure services on multi-cloud infrastructure .
You will:
Formulate, evangelise, and drive adoption of the product security strategy
Assess, advise on, and increase the security maturity posture
Create a standardised security architecture and operational best practices
Help track and drive remediation of security and technology risks
Educate product teams on risk assessments, threat modelling, and building secure api-first applications
Review requirements and designs to help product teams address shortcomings
Embed security tooling into the development process
Contribute to the review of external penetration tests and help teams prioritise fixes
Collaborate with product teams to improve overall security and resolve specific issues
Facilitate or lead customer conversations regarding product security
Triage and investigate new attack vectors to determine risk mitigation
Drive security and quality initiatives across the organization and support certification audits
Collaborate with Product Management, Principal Engineers, and legal/compliance teams
Identify skills gaps and facilitate knowledge sharing across the organization
This role is hybrid, with three days a week spent in our Berlin, London or Valencia office .
What Sets You Apart
You're a creative problem-solver who is wired to find solutions. You confidently dive into complex challenges and have a talent for making them simple for others. Your curiosity drives you to constantly grow and contribute to an environment of trust and teamwork. Great ideas come from many paths, and your unique perspective matters more than checking every box. What matters most is the mindset you bring to the work.
You bring:
A strong technical background and 5+ years of proven track record in hands-on Product Security
2+ years of experience improving Product Security in a leadership role
Experience with customer-facing security roles and influencing roadmaps in matrix organizations
Experience in a scale-up environment with ambitious and competing priorities
Expertise in formulating, elaborating, and clarifying requirements or priorities
Experience with Secure Architecture design reviews and Threat Modeling
Experience infusing security into various levels of the SDLC
Experience with Static Analysis and Secure Code Review implementations