12 days ago
Responsibilities
- Secure the data, software, and cloud platforms entrusted to the company.
- Advise development and DevOps teams on security best practices and provide security guidance for new projects and technologies.
- Provide subject matter expertise in architecture, authentication, and system security.
- Design, implement, and manage AWS security solutions using infrastructure as code.
- Implement and manage AWS Security Hub, GuardDuty, Inspector, CloudTrail, WAF, KMS, Config, and IAM Access Analyzer.
- Build secure CI/CD pipelines using DevSecOps principles and AI Security Agent technologies.
- Build internal tools to detect and respond to security problems and incidents.
- Monitor cloud environments for security incidents and anomalies and respond to suspected incidents.
- Integrate standardized security controls with infrastructure and application development teams.
- Implement security controls aligned with RED, EN18031, and CRA requirements.
- Prioritize vulnerability management activities, including CVE triage, CVSS scoring, coordinated disclosure, and external reporter collaboration.
- Ensure alignment with ISO 27001 and define organization-wide security policies and employee training.
Requirements
- Bachelor’s degree in Engineering, Information Systems, Computer Science, or a related field plus 6+ years of software engineering or related experience; alternatively, a master’s degree plus 5+ years or a PhD plus 4+ years.
- At least 3 years of experience with programming languages such as C, C++, Java, or Python.
- At least 5 years of security engineering or comparable DevOps/SRE experience.
- Experience with Docker and Kubernetes containerization and orchestration.
- Strong background in host, network, and cloud security and in designing secure cloud-native systems.
- Experience with applied cryptography, including PKI, TLS, and key management.
- Expertise with modern programming languages and Git/GitHub.
- Knowledge of ISO, SOC, NIST, GDPR, CIS, and CRA security compliance standards and regulations.
- Knowledge of OWASP, STRIDE, MITRE ATT&CK, CWE, internet security issues, and the threat landscape.
- Experience with security monitoring, incident detection and response, vulnerability management, threat modeling, risk assessment, and risk mitigation.
- Strong written and oral English communication skills and the ability to explain technical concepts to nontechnical audiences.
- Preferred experience with infrastructure and DevOps, AWS or GCP, Cloudflare, Auth0, Datadog, Arduino or microcontrollers, hardware security, and Go.
Benefits
- Competitive annual salary and benefits.
- Flexible working hours and working locations.
- Learning and training budget with individual growth objectives.
- Sport or gym benefit, office tournaments, seasonal celebrations, happy hours, drinks, snacks, rooftop lunch areas, and relaxation spaces for employees near an office.
- Annual discretionary bonus program and potential annual RSU grants.
- Accessible hiring and workplace accommodations are available.
Tech Stack
Categories
About Qualcomm
Inspired by 250 years of American ingenuity, we build technologies that expand what’s possible. From wireless to AI at scale and 6G, our innovations power progress worldwide.
