12 days ago
Budapest, HungarySenior
Responsibilities
- Promote secure software development practices throughout the SDLC.
- Identify, assess, and manage security vulnerabilities using SAST, DAST, and vulnerability-scanning tools.
- Monitor and investigate security events using SIEM platforms such as Splunk or Elastic.
- Collaborate with development and infrastructure teams to implement security solutions.
- Facilitate threat-modeling workshops and translate risks into actionable mitigation plans.
- Support security governance and alignment with applicable compliance and security standards.
- Secure cloud-native applications, containers, and Kubernetes environments.
- Track security findings and remediation activities using Jira or similar ticketing systems.
- Analyze complex security findings and provide practical recommendations to technical and business stakeholders.
Requirements
- Experience with SDLC and secure development practices.
- Strong knowledge of application and cloud security principles.
- Hands-on experience with SAST, DAST, and vulnerability-scanning tools such as Tenable/Nessus, Rapid7, and Aqua Security/Trivy.
- Experience with SIEM solutions, preferably Splunk or Elastic.
- Experience with Jira or similar ticketing systems.
- Understanding of ISO 27001, SOC 2, PCI-DSS, IT-Grundschutz, and other security and compliance standards.
- Experience moderating or facilitating threat-modeling workshops.
- Deep understanding of cloud-native development, containers, and Kubernetes.
- Development experience with Python and/or Golang.
- Exposure to at least one major cloud platform: AWS, Azure, GCP, or OpenStack.
- Strong analytical, problem-solving, communication, and collaboration skills.
Benefits
- Qualysoft emphasizes transparency, openness, continuous learning, development, and a stable team environment.
- The role offers exposure to modern security tools, cloud technologies, containers, Kubernetes, and threat-modeling methodologies.
