11 days ago
Bucharest, RomaniaMid Level
Responsibilities
- Embed and optimize automated security testing, including SAST, DAST, SCA, OSS management, container security, and Kubernetes configuration management, in GitLab CI/CD pipelines.
- Perform platform security assessments, verify reported exploits, and support vulnerability remediation and patch management.
- Participate in security audits, provide actionable feedback, and coordinate compliance activities with engineering teams.
- Provision isolated environments, deploy application builds, and coordinate secure access for penetration testing.
- Support security monitoring, observability, compliance reporting, security release evaluation, and incident response activities.
- Conduct internal software security training, promote secure coding and DevSecOps practices, and provide engineering teams with security automation support.
- Conduct threat modeling for new features and infrastructure changes and identify risks before production deployment.
- Troubleshoot and improve self-service security CI/CD tools, pipelines, infrastructure, and automation across the SDLC.
Requirements
- At least 2 years of cybersecurity experience with shift-left security, SAST, DAST, SCA, OSS management, threat modeling, secure code review, and awareness of black-box and white-box penetration testing.
- At least 4 years of DevOps and cloud infrastructure experience, preferably with AWS, Azure, or GCP.
- Advanced knowledge of software development lifecycle practices, source control, CI/CD tools, Git/GitLab, branching and versioning strategies, and pipeline development.
- Intermediate experience with Docker, Kubernetes, Terraform, and configuration management.
- Linux system administration experience, including networking, access management, and troubleshooting.
- Advanced scripting experience in Python or Bash.
- Experience with distributed systems, cloud administration, application performance management, and observability.
- Knowledge of ISO 27001/27002, NIST 800-53, PCI DSS, or CIS Controls, or active SecOps experience, is a plus.
- Strong communication, collaboration, analytical problem-solving, prioritization, operational judgment, attention to detail, and security-first mindset.
Benefits
- Full-time employee role with competitive compensation and incentives.
- Hybrid work arrangement requiring two days per week in the Bucharest office at One Park Cotroceni.
- Opportunity to work on cybersecurity for business-critical applications with supportive colleagues and career growth as the company grows.
- B2B and SRL arrangements are not accommodated.
