Jobs › Companies › Qualysoft › DevSecOps Engineer

Sobre este puesto de DevSecOps Engineer en Qualysoft

Qualysoft · Híbrido · Bucharest

Responsibilities

  • Cloud Security Engineering: Design and implement cloud security controls across AWS (primary), applying defense-in-depth across identity, network, and infrastructure layers. Translate security requirements into concrete, automated guardrails.
  • Security Automation: Develop automation scripts and tools in Python and Bash to streamline security operations, enforce compliance, and reduce manual effort across the environment.
  • Secure CI/CD: Integrate security into CI/CD pipelines and DevOps workflows, ensuring security is a first-class component of the delivery process rather than an afterthought.
  • DevSecOps Architecture: Design, implement, and maintain enterprise DevSecOps architectures that integrate security throughout all phases of the SDLC. Establish reference architectures, technical standards, engineering patterns, and best practices for DevSecOps implementations.
  • Automated Security Testing: Integrate automated security testing into software delivery pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container and image scanning, secret detection and credential management, and infrastructure security scanning.
  • Vulnerability Management: Operate the vulnerability management lifecycle end to end - scanning, triage, prioritization, remediation tracking, and reporting - using tools such as Qualys.
  • Governance and Compliance: Implement security measures and governance policies - not just deploying controls, but writing policies, ensuring they are in place, and running periodic compliance reviews aligned with regulatory requirements (e.g., NIS2, GDPR).
  • Container and Kubernetes Security: Apply security best practices to containerized workloads and Kubernetes (EKS), including image scanning, runtime considerations, and hardening.
  • Documentation and Standards: Produce architecture artifacts and security documentation to support audit readiness and continuous compliance initiatives.
  • Collaboration: Work with cross-functional teams - infrastructure, development, and cybersecurity - to ensure security controls are practical, adopted, and maintained.

Qualifications

  • Minimum 3 years of relevant experience in DevSecOps, security engineering, or DevOps with a strong security focus.
  • Solid understanding of AppSec principles, the OWASP Top 10, and secure coding practices.
  • Good knowledge of Linux OS administration, TCP/IP networking concepts, virtualization, and databases.
  • Proficiency with versioning tools (Git) and hands-on experience with CI/CD concepts and methodologies.
  • Good understanding of scripting languages (Python, Bash).
  • Knowledge of vulnerability scanning tools (Qualys, Nessus, etc.).
  • Knowledge of SAST/DAST tools (SonarQube, OWASP ZAP, Burp Suite, etc.).
  • Understanding of the vulnerability management lifecycle.
  • Good knowledge of monitoring technologies/tools (Grafana, Prometheus, etc.).
  • Familiarity with security tooling around Terraform, Kubernetes security, and vulnerability scanners.
  • Strong documentation and technical writing skills (mandatory).
  • Understanding of product lifecycle and software release processes.
  • Attention to detail and the ability to quickly adapt to new technologies.

Nice to Have

  • Experience with Infrastructure as Code (Terraform, Ansible), YAML, and orchestration.
  • Experience working in Agile/Scrum methodologies.
  • Experience supporting continuous Authority to Operate (ATO) initiatives.
  • Exposure to multi-account AWS governance (SCPs, IAM boundaries) and secret management (HashiCorp Vault, AWS Secrets Manager).
¿Listo para postularte en Qualysoft?
Postúlate en Qualysoft

Empleos similares

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Qualysoft

Ver todos los empleos en Qualysoft →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis