R&D Security Specialist
Sofia, Varna, Plovdiv
ā ļø We'll shut down after Aug 1st - try fooš¦ for all jobs in tech ā ļø
Nemetschek Bulgaria
Nemetschek Bulgaria is leading developer of BIM, document management, and enterprise solutions. Full-cycle IT services: development, implementation & support.Location: Sofia, Varna, Plovdiv,None,None
We are looking for an R&D Security SpecialistĀ to join one of our teams - theĀ IT Security team.
Ā
YOUR DAILY CHALLENGES
- Collaborates closely with developers and product teams to help prioritise identified security issues and tasks within the development lifecycle;
- Analyses results from tools likeĀ SnykĀ and assesses risks (e.g., usingĀ CVSS) to support informed decisions on what should be fixed, when, and why;
- Participates in defining and maintaining security practices, including code reviews, source code protection measures, and internal awareness activities;
- Contributes to developing and maintaining security-related documentation, policies, and procedures;
- Coordinates with members of the central security team and the local technical lead to ensure alignment on security initiatives;
- Supports and encourages security awareness among peers ā e.g., by engaging in initiatives similar toĀ Security ChampionsĀ inside development teams;
- While the position involves communication and coordination, it does not include managerial responsibilities. The focus is on technical expertise and accountable contribution, not on team management.
OUR EXPECTATIONS
- Minimum ofĀ 2 years of experienceĀ as a software developer, DevOps engineer, QA engineer with security interest, or as an Application Security specialist;
- Understanding of how R&D and software development environments operate, includingĀ Agile methodologies,Ā backlog management,Ā Jira, andĀ CI/CD pipelines;
- Familiarity with core security concepts, including theĀ OWASP Top 10,Ā dependency management, andĀ secure coding practices;
- Experience with, or interest in, tools such asĀ Snyk,Ā Checkmarx,Ā SonarQube, or similar;
- Ability to analyse vulnerabilities and communicate priorities to various stakeholders;
- Understanding of relevant security frameworks and regulations such asĀ GDPR,Ā CVSS, andĀ secure SDLC;
- Fluency in German (written and spoken) at C1āC2 levelĀ is a mandatory requirement;
- Fluent in English;
- Bachelor's degree in computer science studies.
CONSIDERED A PLUS
- Experience withĀ web application firewalls (WAFs),Ā XDR,Ā cloud or application monitoring, orĀ API security;
- Hands-on experience withĀ penetration testingĀ tools or workflows;
- Previous involvement inĀ Security Champions, internal training, or peer knowledge-sharing initiatives;
- Certifications such asĀ CISSP,Ā CSSLP,Ā CompTIA Security+, or similar.
WHAT YOU WILL GET
- Opportunity to work on meaningful products;
- A supportive environment to express your ideas and challenge you to be your best;
- An organisational culture thatĀ stimulates informal relationships and open communication;
- Access to conferences, internal and external training and self-learning systems;
- Opportunity to shape your role and contribution to the organisation;
- A variety of choices for internal events & activities to bond with other colleagues within the organisation;
- GreatĀ benefits and financial package.
We are looking for people with creative minds and enthusiasm to join us in developing whatās new, whatās next and what best serves our customers' needs.
We'll be happy to welcome you to our team!
Ā
Apply to this job* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index š°
Tags: Agile APIs Application security Checkmarx CI/CD CISSP Cloud CompTIA Computer Science CSSLP CVSS DevOps Firewalls GDPR Jira Monitoring OWASP Pentesting R&D SDLC SonarQube Vulnerabilities XDR
Perks/benefits: Career development Conferences Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.