7 дней назад
DevOps Engineer (Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
DevOps Engineer (Security) (DevSecOps, AWS, Kubernetes): Building and securing CI/CD pipelines, cloud infrastructure, and automation tooling for a cybersecurity platform with an accent on shift-left security, vulnerability management, and compliance automation. Focus on integrating SAST, DAST, SCA, and container security, enabling penetration testing, and conducting threat modeling across the SDLC.
Location: Bucharest, Romania; hybrid role requiring two days per week from the One Park Cotroceni office. Candidates must be commutable to Bucharest.
Company
provides a cybersecurity platform for vulnerability management, change assurance, and continuous compliance across critical business applications such as SAP and Oracle.
What you will do
- Design, implement, maintain, and optimize security automation across the software development lifecycle.
- Integrate OSS, SAST, DAST, SCA, container security, and Kubernetes configuration management into GitLab CI/CD pipelines.
- Assess platform vulnerabilities, verify reported exploits, and support remediation and patch management.
- Provision isolated environments and deploy application builds to enable penetration testing.
- Support security monitoring, observability, incident response, compliance reporting, and security releases using Grafana, New Relic, or OpenTelemetry.
- Conduct threat modeling, provide secure coding guidance, and train engineering teams in DevSecOps practices.
Requirements
- At least 2 years of cybersecurity experience, including shift-left security, application security testing, threat modeling, and secure code reviews.
- At least 4 years of DevOps and cloud infrastructure experience, preferably with AWS; Azure and GCP experience is also relevant.
- Advanced experience with Git/GitLab, branching and versioning strategies, CI/CD pipeline development, and the SDLC.
- Working knowledge of Docker, Kubernetes, Terraform, Linux administration, networking, access management, and troubleshooting.
- Advanced scripting skills in Python or Bash, plus experience with observability and application performance management.
- Strong communication, analytical problem-solving, prioritization, collaboration, and security-first thinking.
Nice to have
- Knowledge of ISO 27001/27002, NIST 800-53, PCI DSS, or CIS Controls.
- Experience in security operations or penetration testing, including black-box and white-box methods.
Culture & Benefits
- Opportunity to contribute to the protection of business-critical applications.
- High-achievement, teamwork-oriented culture with supportive and knowledgeable colleagues.
- Competitive compensation and incentives.
- Full-time employee position; B2B contracts and SRLs are not accommodated.
Hiring process
- Applications should be submitted through reputable job boards or the careers page.
- Offers are extended only after a face-to-face video interview with an HR representative.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →