R&D Security Specialist

IT Security Team

We are looking for an R&D Security Specialist to join one of our teams - the IT Security team.

 

YOUR DAILY CHALLENGES

  • Collaborates closely with developers and product teams to help prioritise identified security issues and tasks within the development lifecycle;
  • Analyses results from tools like Snyk and assesses risks (e.g., using CVSS) to support informed decisions on what should be fixed, when, and why;
  • Participates in defining and maintaining security practices, including code reviews, source code protection measures, and internal awareness activities;
  • Contributes to developing and maintaining security-related documentation, policies, and procedures;
  • Coordinates with members of the central security team and the local technical lead to ensure alignment on security initiatives;
  • Supports and encourages security awareness among peers – e.g., by engaging in initiatives similar to Security Champions inside development teams;
  • While the position involves communication and coordination, it does not include managerial responsibilities. The focus is on technical expertise and accountable contribution, not on team management.

OUR EXPECTATIONS

  • Minimum of 2 years of experience as a software developer, DevOps engineer, QA engineer with security interest, or as an Application Security specialist;
  • Understanding of how R&D and software development environments operate, including Agile methodologiesbacklog managementJira, and CI/CD pipelines;
  • Familiarity with core security concepts, including the OWASP Top 10dependency management, and secure coding practices;
  • Experience with, or interest in, tools such as SnykCheckmarxSonarQube, or similar;
  • Ability to analyse vulnerabilities and communicate priorities to various stakeholders;
  • Understanding of relevant security frameworks and regulations such as GDPRCVSS, and secure SDLC;
  • Fluency in German (written and spoken) at C1–C2 level is a mandatory requirement;
  • Fluent in English;
  • Bachelor's degree in computer science studies.

CONSIDERED A PLUS

  • Experience with web application firewalls (WAFs)XDRcloud or application monitoring, or API security;
  • Hands-on experience with penetration testing tools or workflows;
  • Previous involvement in Security Champions, internal training, or peer knowledge-sharing initiatives;
  • Certifications such as CISSPCSSLPCompTIA Security+, or similar.

WHAT YOU WILL GET

  • Opportunity to work on meaningful products;
  • A supportive environment to express your ideas and challenge you to be your best;
  • An organisational culture that stimulates informal relationships and open communication;
  • Access to conferences, internal and external training and self-learning systems;
  • Opportunity to shape your role and contribution to the organisation;
  • A variety of choices for internal events & activities to bond with other colleagues within the organisation;
  • Great benefits and financial package.

We are looking for people with creative minds and enthusiasm to join us in developing what’s new, what’s next and what best serves our customers' needs.

We'll be happy to welcome you to our team!

 

PERKS AND BENEFITS

Choose your work model

We are all about flexibility. That's why we adopted the hybrid work model – enabling employees to choose the work arrangement that works best for them.

Enjoy a supportive work environment

Enjoy the freedom to express your ideas and to get the support you need, when you need it.

Benefits and parent-friendly policy

Enjoy health, wellness and commuter benefits as well as our parent-friendly company policy.


TRAINING AND DEVELOPMENT

Personal development

Stimulate personal growth through individual coaching, personal development programmes.

Trainings and conferences

Get easy access to many high-quality conferences and trainings, both onsite and online.

Knowledge sharing

Benefit greatly from internal knowledge sharing. Acquire new knowledge, expand your networking skills and build confidence through mentorship.

Nemetschek Bulgaria is a leading software development company in Eastern Europe. We boast 25+ years of experience in driving innovation in different business areas. With over 450 professionals on board who are committed to leveraging our clients’ performance, all our customers associate our name with a reliable worldwide partner.

Read more

Our IT Security team ensures security across all software development activities, supporting both Nemetschek Bulgaria’s and partners’ projects and initiatives. While managing and maintaining security-related systems and tools is also part of the role, the primary focus is on embedding security into development processes and promoting secure-by-design practices across our software landscape.

Apply for this position


Позволени са файлове с разширения: pdf, doc или docx.


Можеш да прикачиш максимум до два файла. Позволени са файлове с разширения: pdf, doc или docx.

Запознах се с Политика за поверителност на Немечек България.

Съгласявам се да получавам последваща информация, свързана с професионални възможности в Немечек България.

PERKS AND BENEFITS

Choose your work model

We are all about flexibility. That's why we adopted the hybrid work model – enabling employees to choose the work arrangement that works best for them.

Enjoy a supportive work environment

Enjoy the freedom to express your ideas and to get the support you need, when you need it.

Benefits and parent-friendly policy

Enjoy health, wellness and commuter benefits as well as our parent-friendly company policy.

TRAINING AND DEVELOPMENT

Personal development

Stimulate personal growth through individual coaching, personal development programmes.

Trainings and conferences

Get easy access to many high-quality conferences and trainings, both onsite and online.

Knowledge sharing

Benefit greatly from internal knowledge sharing. Acquire new knowledge, expand your networking skills and build confidence through mentorship.