{"id":1901911,"url":"https://alion.io/job/qualysoft-devsecops-engineer","title":"DevSecOps Engineer","company":{"id":6361,"name":"Qualysoft","domain":"qualysoft.com","url":"https://alion.io/company/qualysoft","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Lever","truth_index":{"grade":"B","score":82,"open_postings":32,"ghost_share":0,"stale_share":0.938,"repost_share":0,"time_to_fill_p50_days":13,"computed_at":"2026-10-06T05:45:30Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bucharest, Romania"],"countries":["RO"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":31000,"max_usd":75000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":528},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Amazon EKS","optional":false},{"name":"AWS","optional":false},{"name":"Bash","optional":false},{"name":"CI/CD","optional":false},{"name":"Defense in Depth","optional":false},{"name":"GDPR","optional":false},{"name":"Git","optional":false},{"name":"Grafana","optional":false},{"name":"Kubernetes","optional":false},{"name":"Linux","optional":false},{"name":"Nessus","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"OWASP ZAP","optional":false},{"name":"Prometheus","optional":false},{"name":"Python","optional":false},{"name":"Qualys Cloud Platform","optional":false},{"name":"SonarQube","optional":false},{"name":"TCP/IP","optional":false},{"name":"Terraform","optional":false},{"name":"Agile","optional":true},{"name":"Ansible","optional":true},{"name":"HashiCorp Vault","optional":true},{"name":"IAM","optional":true},{"name":"Scrum","optional":true}],"status":"live","first_seen_at":"2026-10-05T09:31:05Z","employer_posted_date":"2026-10-05","last_verified_at":"2026-10-07T00:20:35Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Responsibilities\nCloud Security Engineering: Design and implement cloud security controls across AWS (primary), applying defense-in-depth across identity, network, and infrastructure layers. Translate security requirements into concrete, automated guardrails.\nSecurity Automation: Develop automation scripts and tools in Python and Bash to streamline security operations, enforce compliance, and reduce manual effort across the environment.\nSecure CI/CD: Integrate security into CI/CD pipelines and DevOps workflows, ensuring security is a first-class component of the delivery process rather than an afterthought.\nDevSecOps Architecture: Design, implement, and maintain enterprise DevSecOps architectures that integrate security throughout all phases of the SDLC. Establish reference architectures, technical standards, engineering patterns, and best practices for DevSecOps implementations.\nAutomated Security Testing: Integrate automated security testing into software delivery pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container and image scanning, secret detection and credential management, and infrastructure security scanning.\nVulnerability Management: Operate the vulnerability management lifecycle end to end - scanning, triage, prioritization, remediation tracking, and reporting - using tools such as Qualys.\nGovernance and Compliance: Implement security measures and governance policies - not just deploying controls, but writing policies, ensuring they are in place, and running periodic compliance reviews aligned with regulatory requirements (e.g., NIS2, GDPR).\nContainer and Kubernetes Security: Apply security best practices to containerized workloads and Kubernetes (EKS), including image scanning, runtime considerations, and hardening.\nDocumentation and Standards: Produce architecture artifacts and security documentation to support audit readiness and continuous compliance initiatives.\nCollaboration: Work with cross-functional teams - infrastructure, development, and cybersecurity - to ensure security controls are practical, adopted, and maintained.\nQualifications\nMinimum 3 years of relevant experience in DevSecOps, security engineering, or DevOps with a strong security focus.\nSolid understanding of AppSec principles, the OWASP Top 10, and secure coding practices.\nGood knowledge of Linux OS administration, TCP/IP networking concepts, virtualization, and databases.\nProficiency with versioning tools (Git) and hands-on experience with CI/CD concepts and methodologies.\nGood understanding of scripting languages (Python, Bash).\nKnowledge of vulnerability scanning tools (Qualys, Nessus, etc.).\nKnowledge of SAST/DAST tools (SonarQube, OWASP ZAP, Burp Suite, etc.).\nUnderstanding of the vulnerability management lifecycle.\nGood knowledge of monitoring technologies/tools (Grafana, Prometheus, etc.).\nFamiliarity with security tooling around Terraform, Kubernetes security, and vulnerability scanners.\nStrong documentation and technical writing skills (mandatory).\nUnderstanding of product lifecycle and software release processes.\nAttention to detail and the ability to quickly adapt to new technologies.\nNice to Have\nExperience with Infrastructure as Code (Terraform, Ansible), YAML, and orchestration.\nExperience working in Agile/Scrum methodologies.\nExperience supporting continuous Authority to Operate (ATO) initiatives.\nExposure to multi-account AWS governance (SCPs, IAM boundaries) and secret management (HashiCorp Vault, AWS Secrets Manager).","description_format":"text","description_chars":3586,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Romania","iso":"RO","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["DevSecOps","IT Consulting & Digital Transformation","IT Outsourcing & Dedicated Teams","Custom Software Development"],"lifecycle":[{"event":"open","at":"2026-10-05T11:28:58Z"}],"visa":[],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":0,"expected_fill_days":13,"reasons":["conf:0","stale_co","velocity","win:early"],"computed_at":"2026-10-06T05:45:30Z"},"pay":null,"html_url":"https://alion.io/job/qualysoft-devsecops-engineer","json_url":"https://alion.io/job/qualysoft-devsecops-engineer.json","meta":{"generated_at":"2026-10-07T00:56:02Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1539,"day_limit":5000,"remaining_today":3461,"minute_limit":60,"resets_at":"2026-10-08T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":6361},"rest":"https://alion.io/mcp/rest/get_company?id=6361"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fqualysoft-devsecops-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fqualysoft-devsecops-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fqualysoft-devsecops-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/qualysoft-devsecops-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fqualysoft-devsecops-engineer"}]}