5 hours ago
Bucharest, RomaniaMid Level
Responsibilities
- Design and implement cloud security controls and automated guardrails across AWS.
- Develop Python and Bash automation to streamline security operations, enforce compliance, and reduce manual effort.
- Integrate security into CI/CD pipelines and DevOps workflows across the software development lifecycle.
- Design and maintain enterprise DevSecOps architectures, reference architectures, technical standards, and engineering patterns.
- Integrate SAST, DAST, SCA, container and image scanning, secret detection, credential management, and infrastructure security scanning into delivery pipelines.
- Operate the vulnerability management lifecycle, including scanning, triage, prioritization, remediation tracking, and reporting.
- Implement security governance policies and conduct periodic compliance reviews aligned with requirements such as NIS2 and GDPR.
- Secure containerized workloads and Kubernetes environments, including EKS, image scanning, runtime considerations, and hardening.
- Produce architecture artifacts and security documentation for audit readiness and continuous compliance.
- Collaborate with infrastructure, development, and cybersecurity teams to ensure security controls are practical, adopted, and maintained.
Requirements
- At least 3 years of relevant experience in DevSecOps, security engineering, or security-focused DevOps.
- Understanding of AppSec principles, the OWASP Top 10, secure coding practices, Linux administration, TCP/IP networking, virtualization, and databases.
- Proficiency with Git and practical understanding of CI/CD concepts and methodologies.
- Good understanding of Python and Bash scripting.
- Knowledge of vulnerability scanning tools such as Qualys and Nessus.
- Knowledge of SAST/DAST tools such as SonarQube, OWASP ZAP, and Burp Suite.
- Understanding of the vulnerability management lifecycle and monitoring technologies such as Grafana and Prometheus.
- Familiarity with Terraform, Kubernetes security, and vulnerability scanners.
- Strong documentation and technical writing skills.
- Understanding of product lifecycle and software release processes, with attention to detail and ability to adapt to new technologies.
- Nice-to-have experience with Terraform, Ansible, YAML, orchestration, Agile/Scrum, continuous Authority to Operate initiatives, multi-account AWS governance, SCPs, IAM boundaries, HashiCorp Vault, and AWS Secrets Manager.
Tech Stack
Categories
About Qualysoft
Qualysoft is a Vienna-headquartered IT services firm founded in 1999 that delivers CRM/ERP consulting, custom software development, test automation, integration, and application management for enterprises. It works on a project and managed-services basis across Central and Eastern Europe, supporting digitalization and data/BI initiatives. Privately held, the company serves clients in multiple industries.
