1 month ago
Cluj-Napoca, RomaniaSenior
Responsibilities
- Lead DevSecOps and Secure-SDLC initiatives and enhance the company’s Secure-SDLC framework.
- Select, standardize, assess, and conduct proofs of concept for application security tools.
- Integrate Secure-SDLC requirements and security policies into DevSecOps processes for traditional, cloud, and container workloads.
- Define and enhance application security requirements and standards for agile development methods.
- Advise application security leadership on shift-left practices, application security tools, standards, and process improvements.
- Assess and rationalize existing security tooling across Software Development Lifecycle processes.
- Draft clear Secure-SDLC and DevSecOps documentation and process guidelines for internal customers.
- Assess the impact of security industry publications and trends on application security programs, tooling roadmaps, and processes.
- Promote secure coding standards and Global Information Security and Global Application Security priorities.
- Design, implement, and roll out DevSecOps automation and toolchain integrations.
- Automate and integrate security scanning and analysis tools into DevSecOps pipelines.
- Implement sensors to collect metrics for statistics and reporting.
- Serve as the subject matter expert for Secure-SDLC and DevSecOps.
- Assess tooling and remediation for threats and vulnerabilities in software, applications, and hosting environments.
Requirements
- At least 5 years of DevSecOps and Secure-SDLC work experience.
- CISSP, CSSLP, cloud security, DevSecOps automation, or a similar qualification is required.
- Post-secondary education or equivalent experience as a DevSecOps Engineer.
- Experience developing, enhancing, and implementing Secure-SDLC frameworks.
- Experience designing and implementing Secure-SDLC processes and supporting tooling.
- Hands-on experience automating and integrating security scanning and analysis tools into DevSecOps pipelines.
- Experience with software and application analysis tools such as SAST, DAST, SCA, threat modeling, and supply-chain security.
- Experience with one or more programming languages.
- Familiarity with OWASP Top 10, SANS Top 25, and CWE security frameworks.
- Ability to identify application security requirements and develop solutions using industry best practices.
- Ability to assess security tooling and vulnerability remediation within software, applications, and hosting environments.
Benefits
- Hybrid work arrangement requiring at least three days per week in the Cluj-Napoca office.
- Professional development opportunities, interesting work, and supportive leadership.
- Inclusive and collaborative culture with opportunities to create solutions and make an impact.
- Yearly budget and flexible benefits package of up to 20% of annual salary.
- More than 30 days off, including 25 legal days, a birthday day off, public holiday replacement days, and extra buy/sell options.
- Performance bonus scheme.
- Matching charity contributions, charity days off, and the Pay it Forward charity challenge.
- Core benefits including pension, life and medical insurance, meal vouchers, and travel insurance.
