Position:
Senior SecOps Engineer
Company:
Showpad
Location:
Romania, Bucharest
Employment type:
Not Specified
Short Summary:
The Senior SecOps Engineer will play a critical role within Showpad's Security Operations team, collaborating with various departments to identify, manage, and mitigate cybersecurity risks. This role focuses on enhancing security capabilities, particularly in cloud-native environments.
Responsibilities:
- Manage cybersecurity operations related to application, hardware, and cloud infrastructure security.
- Act as the key cybersecurity contact for internal teams regarding daily practices and initiatives.
- Ensure development teams adopt best practices in software security development.
- Provide CI/CD processes that integrate security and quality tooling.
- Manage and improve the CNAPP solution.
- Oversee cybersecurity operations, ensuring continuous monitoring and protection of cloud infrastructure and applications.
- Manage and respond to events related to vulnerability programs, endpoint protection, and external threat intelligence.
- Collaborate with internal teams to ensure adherence to security best practices and policies.
- Develop and maintain security controls and automation strategies within CI/CD pipelines.
- Monitor and assess risks, manage vulnerabilities, and implement appropriate security measures.
Requirement:
- Proven experience in information security, with a background in security operations or application security.
- Skilled in identifying and handling phishing attempts and social engineering threats.
- Strong knowledge of modern web application security practices and frameworks.
- In-depth understanding of the Secure Software Development Life Cycle (SSDLC).
- Experience implementing security automation in Typescript or similar.
- Proficiency in container technologies (Docker, Kubernetes) and securing cloud-based applications (preferably AWS).
- Knowledge of securing microservices-based architectures.
- Practical experience conducting security assessments (SAST, DAST, SCA).
- Experience managing vulnerabilities through bug bounty programs and automated security scanning.
- Understanding of security and privacy frameworks (GDPR, ISO 27001, SOC 2) is an asset.
- Strong English communication and presentation abilities.
Benefits:
Not Specified