Qualysoft
Operational Security Engineer
- Location
- Bucharest
- Work model
- Hybrid
- Employment
- FullTime
- Source
- Lever
- Added to Codestelle
Language requirements
- German
- Not specified
- English alone
- Not specified
Based on explicit wording in the listing. “Not specified” does not mean a language is optional.
About this role
About Qualysoft
· 25 years of experience in software engineering, established in Vienna, Austria
· Active in Romania since 2007, with office in central Bucharest (Bd. Iancu de Hunedoara 54B)
· Delivering End to End IT Consulting Services - From Team Augmentation and Dedicated Teams to Custom Software Development
· We deliver scalable enterprise systems, intelligent automation frameworks, and digital transformation platforms
· Cross-industry experience by sustaining global players in BSFI (Banking, financial services and insurance), Telecom,Retail & E-commerce, Energy and Utilities, Automotive, Manufacturing, Logitics, High Tech
· Global Presence: Switzerland, Germany, Austria, Sweden, Hungary, Slovakia, Serbia, Romania, and Indonesia
· International team of 500+ software engineers
· Strategic partnerships: Microsoft Cloud Certified Partner, Tricentis Solutions Partner in Test Automation and Test Management, Creatio Exclusive Partner, Doxee Implementation Partner
· Powered by cutting-edge technologies: AI, Data & Analytics, Cloud, DevOps, IoT, and Test Automation.
· Project beneficiaries ranging from large-scale enterprises to startups
· Stable growth and revenue increase year over year, a resilient organisation in volatile IT market conditions
· Quality-first mindset, culture of innovation, and long-term client partnerships
· Global and local reach – trusted by key industry players in Europe and the US
Responsibilities
- Manage the end-to-end vulnerability and security compliance lifecycle, from scan preparation and execution to analysis, remediation tracking, and reporting.
• Perform and analyze vulnerability and compliance scans using Qualys, Tanium, PingCastle, and related security tools.
• Identify vulnerabilities, security weaknesses, configuration issues, and technical non-compliance across Windows, Linux, On-Premises, DMZ, and Cloud environments.
• Coordinate remediation activities with infrastructure, security, application, and business teams, ensuring vulnerabilities are addressed within defined SLAs. • Validate security configurations, patch management, and infrastructure compliance against internal and industry security standards.
• Define vulnerability ownership, provide remediation recommendations, maintain action plans, and escalate remediation risks or delays.
• Produce and maintain security KPIs, dashboards, and operational indicators using tools such as ELK Stack, Power BI, and Power Query.
• Maintain and improve vulnerability scanning coverage across infrastructure and cloud environments.
• Ensure operational availability and lifecycle management of vulnerability management platforms, including upgrades, patching, incident resolution, and maintenance.
• Perform technical assessments and Proofs of Concept (PoCs) for new security capabilities and tooling improvements.
• Monitor evolving security requirements and identify compliance gaps, proposing remediation and convergence plans.
• Collaborate with Security, Governance, IT Risk Management, infrastructure, and business security teams on vulnerabilities, exceptions, and security impact assessments.
• Maintain technical documentation, operational procedures, security guidelines, and contingency plans.
• Continuously improve vulnerability management processes, automation, reporting, and security controls.
Qualifications
- Strong experience in Vulnerability Management, Security Compliance, and Operational Security within complex enterprise environments.
• Hands-on experience with Qualys and Tanium, including vulnerability, compliance, SelfAssessment, API, and Comply capabilities.
• Experience with security assessment and compliance tools such as PingCastle.
• Good knowledge of ELK Stack, Power BI, and Power Query for security monitoring, analysis, and reporting.
• Strong understanding of security frameworks and standards including NIST, CIS Benchmarks, OWASP, ISO 27001, PTES, ISSAF, and OSSTMM.
• Good technical knowledge of Windows, Linux, Cloud, networking, infrastructure security, patch management, and system hardening.
• Ability to perform detailed analysis of standard network protocols and security-related infrastructure behavior.
• Scripting and automation skills using Python, PowerShell, and Regular Expressions (Regex).
• Experience managing vulnerability remediation processes, including SLA tracking, risk assessment, exception management, and stakeholder coordination.
• Ability to analyze technical vulnerabilities and translate findings into clear remediation actions for technical stakeholders.
• Experience with Agile environments, project coordination, process design, and continuous improvement.
• Strong analytical, organizational, and problem-solving skills with high attention to detail.
• Strong communication and cross-functional collaboration skills.
• Fluent French, both written and spoken, and a good command of English.
*We are an equal opportunity employer and value diversity. All employment decisions are made without regard to age, gender, disability, race, ethnicity, religion, sexual orientation, or any other protected characteristic. We encourage applicants from all backgrounds to apply.*