Security & Quality Specialist, Czech based
Job Description:
We are looking for a specialist with a strong understanding of secure software development and application security testing.The ideal candidate should have knowledge of CRA, SBOM, SAST, DAST, and vulnerability management, as well as practical experience with tools such as Snyk, SonarQube, OWASP ZAP, Trivy, or similar solutions.
The role will focus on establishing security testing processes, scanning applications and software dependencies, analyzing identified vulnerabilities, proposing remediation measures, and working closely with the development team to build and maintain a secure Software Development Life Cycle (SDLC).
Key Responsibilities
- Establish and continuously improve software testing and security control processes within the software development lifecycle.
- Perform and coordinate security assessments of applications and software development processes.
- Implement and manage tools for detecting vulnerabilities in applications and software dependencies.
- Assess identified vulnerabilities, propose remediation measures, and collaborate with development teams on their resolution.
- Support compliance with applicable regulatory and legislative requirements, particularly the Cyber Resilience Act (CRA).
- Develop basic methodologies, standards, and recommendations for secure software development.
- Support the creation and maintenance of Software Bills of Materials (SBOMs) and the management of third-party software components.
Cybersecurity Knowledge
- Secure Software Development Lifecycle (Secure SDLC) principles.
- Common application security vulnerabilities, including the OWASP Top 10.
- Knowledge of CVE, CVSS, and general vulnerability management practices.
- Security risk analysis and definition of appropriate mitigation measures.
- Vulnerability assessment.
Regulations and Standards
- Cyber Resilience Act (CRA).
- Software Bill of Materials (SBOM).
- Basic understanding of NIS2 and related cybersecurity requirements is an advantage.
Security Testing
- SAST – Static Application Security Testing.
- DAST – Dynamic Application Security Testing.
- SCA – Software Composition Analysis.
- Basic knowledge of penetration testing and threat modeling is an advantage.
Required Tool Experience
Hands-on experience with at least some of the following tools:
- Snyk
- Grype
- SonarQube
- OWASP ZAP
- Dependency-Check
- Trivy
- Checkmarx
- Veracode
- Fortify
- GitLab Security Scanning
Technical Skills
- Good understanding of CI/CD processes.
- Knowledge of Git and common software development workflows.
- Ability to integrate security controls and security scanning into the development lifecycle.
- Basic knowledge of Docker and Kubernetes is an advantage.
- Ability to read and understand source code, ideally Java.
- Knowledge of CVE and familiarity with the format and content of VEX and VDR documentation.
Expected Deliverables
- Established security testing process within the software development lifecycle.
- Defined rules and standards for SAST, DAST, and SCA scanning.
- Regular vulnerability reporting, assessment, and prioritization.
- Established process for creating and maintaining SBOMs.
- Recommendations and compliance checks related to CRA requirements.
- Close cooperation with development teams on remediation of identified security issues.