About the job
Teramind is seeking a Manager, DevSecOps Engineering to join our team in Romania. This leadership role centers on embedding security throughout the software development lifecycle and guiding the engineering organization in secure practices.
Key Responsibilities
Security in the SDLC
- Lead the adoption and enforcement of DevSecOps practices within CI/CD pipelines, including static and dynamic application security testing (SAST, DAST), software composition analysis (SCA), and related tools.
- Integrate automated security tools into development workflows to reduce reliance on manual checks.
- Work closely with development teams to conduct secure code reviews and perform threat modeling.
Vulnerability and Risk Management
- Oversee detection, prioritization, and remediation of vulnerabilities across infrastructure and applications.
- Manage the security tooling stack to ensure effective risk mitigation.
- Maintain a comprehensive risk register and track remediation Service Level Agreements (SLAs).
Penetration Testing, Crowd Testing, and Incident Response
- Coordinate or lead both internal and external penetration testing efforts.
- Manage crowd testing campaigns to uncover vulnerabilities.
- Develop and maintain an incident response playbook, and support investigations when incidents occur.
Compliance and Governance
- Support compliance initiatives for SOC 2, ISO 27001, GDPR, and other data protection standards.
- Establish security policies, standards, and training programs for developers with a focus on security awareness.
Leadership and Collaboration
- Act as the primary security Subject Matter Expert (SME) within the engineering organization.
- Mentor developers in secure coding and help build a security-first culture across engineering teams.
- Engage with external auditors, clients, and executive leadership on the company’s security posture.
