AppSec Jobs
← Back to all jobs

Bosch

IT Product Security Specialist (m/w/div.)

Berlin, Berlin, GermanyPosted 3 weeks agoNot disclosedWebsite
Apply on LinkedIn →

At a Glance

10+ years experienceCI/CDOWASPNISTThreat ModelingIncident Response

About This Role

Lead the Product Security Program by integrating security into the SDLC, conducting threat modeling, and deriving security requirements for features and architectural changes. Perform risk analyses and prioritize product-related risks (design, dependencies, compliance). Work closely with Product Managers to integrate security into product roadmaps and planning. Serve as mediator between governance and technical implementation by defining security policies and actively participating in their implementation and enforcement across products. Develop and implement secure tooling and automation processes in CI/CD pipelines (SCA, SAST/DAST, Secret Scanning). Manage Vulnerability Triage and Remediation SLAs and participate in Incident Response for product security incidents including root cause analysis, customer communication, and long-term measures. Monitor new regulatory requirements (e.g., EU Cyber Resilience Act, NIS2, Cybersecurity Labeling) and ensure compliance. Create and deliver security training, guidelines, and enablement initiatives for engineering and product teams. Report relevant security metrics and program status to management.

Responsibilities

  • Lead the Product Security Program by integrating security into SDLC and conducting threat modeling
  • Derive security requirements for features and architectural changes
  • Conduct risk analyses and prioritize product-related risks (design, dependencies, compliance)
  • Collaborate with Product Managers to integrate security in product roadmaps and planning
  • Serve as mediator between governance and technical implementation for security policies
  • Develop and implement secure tooling and automation in CI/CD pipelines (SCA, SAST/DAST, Secret Scanning)
  • Manage Vulnerability Triage and Remediation SLAs
  • Participate in Incident Response for product security incidents with root cause analysis and customer communication
  • Monitor new regulatory requirements (EU Cyber Resilience Act, NIS2, Cybersecurity Labeling)
  • Create and deliver security training, guidelines, and enablement initiatives
  • Report security metrics and program status to management

Requirements

OWASPNISTCISSP
  • Completed university degree with 5-10 years of experience in Product Security, Application Security, or Secure SDLC roles
  • Strong technical background in software development, security engineering, or architecture
  • Comprehensive knowledge of threats and mitigation measures (OWASP, Secure Design Patterns, authentication models, supply chain risks)
  • Experience with cloud security or relevant standards (NIST SSDF, ISO 21434)
  • Practical experience with threat modeling (STRIDE or comparable) and risk assessment frameworks
  • Proficiency with development tools and agile/DevOps environments
  • Strong stakeholder communication across all organizational levels
  • High self-motivation and independence
  • Strong sense of responsibility
  • Proactive work approach
  • CISM or CISSP certification (advantageous but not required)
  • Fluent German and English language skills (written and spoken)

Benefits & Perks

Attractive salaries with performance-related pay
Bonuses for contribution to company success
Private and company pension schemes
Benefit portals with discounts in numerous online stores and services
Special conditions on Bosch products
Comprehensive training opportunities
Wide range of career paths
Flexible working models including job sharing, flexible shift patterns, and part-time options
Sabbatical options
Health-promoting initiatives and preventative services
Physical and mental health support
Self-organized clubs and groups for hobbies and interests
Networks on various topics (family, diversity, etc.)
Comfortable commute options including Bosch shuttle and company bike
Support for working abroad and international relocation assistance

About Bosch

Bosch, officially known as Robert Bosch GmbH, is a leading German multinational engineering and technology company founded in 1886. With operations in over 150 countries and a workforce of approximately 440,000 associates, Bosch focuses on innovation, sustainability, and social responsibility. The company invests significantly in research and development, employing around 87,000 associates across 136 global locations. Bosch operates in four main business sectors: Mobility Solutions, Industrial Technology, Consumer Goods, and Energy and Building Technology. It is recognized as the world's largest automotive supplier, offering a range of products including fuel injection systems, ABS, and electrification solutions. In the consumer goods sector, Bosch is known for its home appliances, such as washing machines and kitchen machines. The company also develops precision tools and connectivity-driven products, emphasizing user-friendly technology across various industries.

Industry

information technology & services

Employees

163,000

10720 engineers

Revenue

$101B

Website

Visit →

Security at Bosch

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • Bosch follows a DevSecOps approach that integrates security into every phase of product development rather than treating it as an endpoint concern.
  • The philosophy emphasizes automating security and finding the optimal balance in automation for security testing.
  • The company establishes internal competence networks such as the Privacy Engineering Guild to distribute security expertise across the organization.
  • A 'Shift Left' strategy is core to their approach, integrating security from the earliest stages of product design and architecture.

Security Team

Bosch maintains a global security team led by Chief Cyber Security Officer Christoph Peylo. The organization includes the Bosch Product Security Incident Response Team (PSIRT) as the central point of contact for external security researchers. Paul Duplys heads Safety, Security & Privacy within Bosch Research. The specific headcount for the AppSec sub-team is not publicly disclosed, though the organization emphasizes a distributed security competence network approach.

Key Initiatives

  • Bosch maintains several key security initiatives including: (1) Security Champions Program through the internal Privacy Engineering Guild for knowledge sharing across teams.
  • (2) 'Shift Left' implementation that integrates security into every development phase.
  • (3) Centralized Vulnerability Management through PSIRT for external researcher intake and coordination.
  • (4) Secure SDLC artifacts covering specification, technical implementation, and penetration/fuzz testing.
  • (5) Digital Trust initiative led by CISO Christoph Peylo to ensure trustworthiness of AI products.
  • (6) Regulatory monitoring and compliance for evolving standards including EU Cyber Resilience Act, NIS2, and Cybersecurity Labeling requirements.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn