2 months ago
Bucharest, RomaniaMid Level
Responsibilities
- Embed, maintain, and optimize SAST, DAST, SCA, and other security testing in GitLab CI/CD pipelines.
- Perform platform security assessments, verify exploits, and support vulnerability and patch remediation.
- Participate in security audits, provide actionable feedback, and coordinate compliance activities.
- Provision isolated environments and deploy application builds to enable penetration testing.
- Support security release evaluation, monitoring, observability, and compliance reporting.
- Conduct security training, promote secure coding and DevSecOps practices, and perform threat modeling for new features and infrastructure changes.
Requirements
- At least 2 years of cybersecurity experience, including Shift-Left-On-Security, SAST, DAST, SCA, OSS management, threat modeling, and secure code reviews.
- Awareness of black-box and white-box penetration testing methods.
- At least 1 year of DevOps and cloud infrastructure experience, preferably with AWS and also including Azure or GCP knowledge.
- Experience with Git/GitLab, CI/CD pipeline development, Docker, Kubernetes, Linux administration, networking, access management, and troubleshooting.
- Expertise in Python or Bash scripting.
- Knowledge of ISO 27001/27002, NIST 800-53, PCI DSS, CIS Controls, or SecOps experience is a plus.
- Terraform and Infrastructure as Code exposure is a plus.
- Strong communication, collaboration, prioritization, analytical problem-solving, attention to detail, and security-first practices are required.
Benefits
- Full-time employee role with competitive compensation and incentives.
- Career growth, a high-achievement teamwork culture, and supportive colleagues.
- Hybrid work arrangement requiring two days per week in the Bucharest office; candidates must be commutable to Bucharest.
- B2B and SRL arrangements are not accommodated.
