
Cyber Security DevOps Manager
- București
- Permanent
- Full-time
- Responsible for integrating and maintaining security tools in the CI/CD pipeline to ensure secure development and deployment
- Assist in identifying, tracking, and prioritizing security vulnerabilities in the development environment
- Support the remediation of vulnerabilities, collaborating with development and operations teams to address security issues
- Assist in configuring, maintaining, and troubleshooting security tools used in the CI/CD pipeline, such as static and dynamic application security testing (SAST/DAST), and software composition analysis (SCA)
- Ensure that tools are functioning properly, with regular updates and maintenance to keep them current
- Monitor CI/CD environments for security threats, running regular security scans and audits
- Assist in generating reports on security findings, tracking resolution progress, and ensuring transparency in security posture
- Contribute to security awareness initiatives within development teams, promoting secure coding practices
- Educate teams on common vulnerabilities and industry best practices to enhance overall security knowledge
- Ensure adherence to security standards, frameworks (e.g. OWASP, NIST, ISO, PCI DSS), and JTI security policies
- Support the development of security policies, ensuring that security best practices are consistently followed across the team
- 5+ years of solid knowledge in cloud and container security, including the specific characteristics of cloud-based security services and securing web/mobile applications
- 5+ years of hands-on experience in operational Cybersecurity, DevOps, or DevSecOps, with strong knowledge of the Secure SDLC approach and the ability to articulate security goals, lifecycle stages, and related processes
- Experience implementing Secure SDLC and integrating security into CI/CD pipelines with a shift-left approach
- Proficient in Azure, Python, Bash, and using tools like SCA, SAST, DAST/IAST, and image scanning
- Knowledge of security standards (OWASP, NIST, ISO, PCI DSS) and experience with tools like Blackduck, Coverity on Polaris, Advanced Security, WIZ etc.
- Familiar with cloud-native security controls, secure coding practices, and threat modeling (e.g., OWASP Threat Dragon)
- Strong knowledge of network security, including common protocols and the OSI model.
- Hands-on experience with Infrastructure-as-Code (IaC) tools (e.g., Terraform), and CI/CD platforms such as GitLab, Azure DevOps, and GitHub, including integrating security tools into pipelines.
- Good understanding of containerization and Kubernetes, especially from a security perspective.
- Interview with GBS Talent Attraction Expert
- Online interview with the Hiring Manager and one of his Team
- 2nd Line Interview for Finalists
Assessment tests
Interviews
Offer. Each step is eliminatory and may vary by role type.At JTI, we strive to create a diverse and inclusive work environment. As an equal-opportunity employer, we welcome applicants from all backgrounds. If you need any specific support, alternative formats, or have other access requirements, please let us know.