Celonis Logo

Celonis

Senior Security Automation Engineer

Reposted 3 Hours Ago
Be an Early Applicant
Hybrid
Madrid, Comunidad de Madrid
Senior level
Hybrid
Madrid, Comunidad de Madrid
Senior level
The Senior Security Automation Engineer will integrate automated security practices into CI/CD pipelines, develop security tooling, and enhance cloud security. Responsibilities include embedding security scans, maintaining tooling, securing Infrastructure as Code, and collaborating with teams to address and train on security issues.
The summary above was generated by AI

We're Celonis, the global leader in Process Intelligence technology and one of the world's fastest-growing SaaS firms. We believe there is a massive opportunity to unlock productivity by placing AI, data and intelligence at the core of business processes - and for that, we need your help. Care to join us?

The  Team:

Within our InfoSec organization, Our global security engineering team is responsible for designing, building, and enhancing the underlying security components that help with securing the Celonis Application and Platforms stacks. We think about both offensively and defensively. We continuously monitor our global security posture and are always adapting to the ever-changing threat landscape. The security engineering team is looking for talented subject matter experts in application, platform and offensive security.


The Role:

The Senior Security Automation Engineer is a technical role focused on integrating automated security practices into our software development lifecycle. You will architect and implement automated security solutions within our CI/CD pipelines, ensuring vulnerabilities are identified and resolved early. Sitting at the intersection of development, operations, and security, this role requires strong programming skills, deep security knowledge, and a passion for building scalable, automated security processes


The work you’ll do:

  • Security Integration in CI/CD: Embed automated security scans (SAST, DAST, SCA, container scanning) into CI/CD pipelines (GitHub Actions, Jenkins, GitLab CI). Implement “fail-fast” deployment gates for high-severity security findings.
  • Develop and Maintain Security Tooling: Build custom integrations and scripts (Python, Go, or similar) for third-party security tools (Snyk, Checkmarx, Semgrep, Trivy). Enhance code review, threat modeling, and vulnerability management processes with the Product Security team.
  • Infrastructure as Code Security: Secure Infrastructure as Code (IaC) deployments leveraging tools like Terraform, CloudFormation, and Checkov. Automate baseline security checks (CIS benchmarks, best practices) for cloud resources.
  • SBOM & Supply Chain Security: Implement and maintain Software Bill of Materials (SBOMs) using tools such as Syft or CycloneDX. Establish build signing and artifact verification (Cosign, GPG) to protect software supply chains.
  • Collaboration & Training: Partner closely with Cloud Security Engineers to address cloud application vulnerabilities and coordinate remediation. Provide security best practices and guidance to development teams on secure coding and secure CI/CD processes.
  • Continuous Improvement & Research: Stay current on emerging threats and DevSecOps tooling. Proactively propose improvements to existing security automation and tooling.

The qualifications you’ll need:

  • Security Automation Experience: 5+ years in security engineering or DevSecOps, emphasizing security automation. Proven expertise integrating SAST, DAST, and SCA into CI/CD pipelines.
  • Strong Coding & Scripting: Proficient in Python, Go, or similar scripting languages. Experienced using Git and version control best practices.
  • Container & Kubernetes Security: Experience with container technologies (Docker, Kubernetes) and container security scanning tools (Trivy, Aqua).
  • Cloud Infrastructure & IaC: Proficiency Infrastructure as Code frameworks (Terraform, CloudFormation).
  • Application Security Knowledge: Solid understanding of OWASP Top 10 vulnerabilities and best practices in application security.

Preferred Qualifications:

  • Supply Chain Security Expertise: Familiarity with SBOM tooling (Syft, CycloneDX) and build-signing technologies (Cosign, GPG).
  • Advanced DevSecOps Practices: Knowledge of “Security as Code” and “Policy as Code” approaches (OPA, Conftest).
  • Community Engagement: Contributions to open-source security projects or active participation in security communities.
  • Collaborative Communication: Excellent communication skills to articulate complex security issues to both technical and non-technical colleagues. Experience writing security documentation or standard operating procedures, and fostering a culture of security awareness within teams.

What Celonis Can Offer You:

  • Pioneer Innovation: Work with the leading, award-winning process mining technology, shaping the future of business.
  • Accelerate Your Growth: Benefit from clear career paths, internal mobility, a dedicated learning program, and mentorship opportunities.
  • Receive Exceptional Benefits: Including generous PTO, hybrid working options, company equity (RSUs), comprehensive benefits, extensive parental leave, dedicated volunteer days, and much more. Interns and working students explore your benefits here.
  • Prioritize Your Well-being: Access to resources such as gym subsidies, counseling, and well-being programs.
  • Connect and Belong: Find community and support through dedicated inclusion and belonging programs.
  • Make Meaningful Impact: Be part of a company driven by strong values that guide everything we do: Live for Customer Value, The Best Team Wins, We Own It, and Earth Is Our Future.
  • Collaborate Globally: Join a dynamic, international team of talented individuals.
  • Empowered Environment: Contribute your ideas in an open culture with autonomous teams.

About Us:

Celonis makes processes work for people, companies and the planet. The Celonis Process Intelligence Platform uses industry-leading process mining and AI technology and augments it with business context to give customers a living digital twin of their business operation. It’s system-agnostic and without bias, and provides everyone with a common language for understanding and improving businesses. Celonis enables its customers to continuously realize significant value across the top, bottom, and green line. Celonis is headquartered in Munich, Germany, and New York City, USA, with more than 20 offices worldwide.

Get familiar with the Celonis Process Intelligence Platform by watching this video.

Celonis Inclusion Statement:

At Celonis, we believe our people make us who we are and that “The Best Team Wins”. We know that the best teams are made up of people who bring different perspectives to the table. And when everyone feels included, able to speak up and knows their voice is heard - that's when creativity and innovation happen.

Your Privacy:

Any information you submit to Celonis as part of your application will be processed in accordance with Celonis’ Accessibility and Candidate Notices

By submitting this application, you confirm that you agree to the storing and processing of your personal data by Celonis as described in our Privacy Notice for the Application and Hiring Process.

Please be aware of common job offer scams, impersonators and frauds. Learn more here.

Top Skills

Checkmarx
Checkov
CloudFormation
Cosign
Cyclonedx
Git
Github Actions
Gitlab Ci
Go
Gpg
Jenkins
Owasp
Python
Semgrep
Snyk
Syft
Terraform
Trivy

Similar Jobs at Celonis

3 Hours Ago
Hybrid
Madrid, Comunidad de Madrid, ESP
Expert/Leader
Expert/Leader
Big Data • Information Technology • Productivity • Software • Analytics • Business Intelligence • Consulting
Lead Strategy and Operations for sales at Celonis, defining GTM strategy, key metrics, and managing a high-performance team to enhance productivity and business health.
3 Hours Ago
Hybrid
Madrid, Comunidad de Madrid, ESP
Mid level
Mid level
Big Data • Information Technology • Productivity • Software • Analytics • Business Intelligence • Consulting
The Technical Program Manager will lead large-scale security programs, collaborate with teams, manage project plans, and ensure effective communication across stakeholders.
Top Skills: ExcelGoogle SuiteJIRA
3 Hours Ago
Hybrid
Madrid, Comunidad de Madrid, ESP
Mid level
Mid level
Big Data • Information Technology • Productivity • Software • Analytics • Business Intelligence • Consulting
The Technical Program Manager will lead large-scale security programs, coordinate across teams, manage project plans using Jira and GSuite, and communicate effectively with stakeholders to drive program success.
Top Skills: ExcelGoogle SuiteJIRA

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account