R&D Security Specialist

IT Security Team

We are looking for an R&D Security Specialist to join one of our teams - the IT Security team.

YOUR DAILY CHALLENGES

  • Collaborate with developers and product teams to prioritise security issues and tasks within Agile development lifecycles;
  • Analyse results from security tools like Snyk (SAST), Wiz (CNAPP), and Bright (DAST) to assess risks and recommend remediation priorities;
  • Define and maintain security practices, including secure code reviews, source code protection, and internal security awareness initiatives;
  • Conduct risk assessments and establish treatment plans for missing or partially implemented security controls;
  • Act as the primary liaison between R&D, IT, and Product Management teams to coordinate security initiatives and align on priorities;
  • Support security awareness among development teams through Security Champions programs and knowledge-sharing initiatives;
  • Monitor the effectiveness of security controls, participate in internal audits, and maintain security documentation and evidence for compliance.

OUR EXPECTATIONS

  • 2+ years of professional experience as a software developer, DevOps engineer, QA engineer with a security focus, or Application Security specialist;
  • Understanding of R&D and software development environments, including Agile methodologies, backlog management, Jira, and CI/CD pipelines;
  • Solid knowledge of core security concepts, including OWASP Top 10, dependency management, and secure coding practices;
  • Familiarity with security tools such as Snyk, Checkmarx, SonarQube, or similar (or strong willingness to learn);
  • Ability to analyse vulnerabilities and communicate priorities effectively to technical and non-technical stakeholders;
  • Understanding of security frameworks and regulations such as GDPR, CVSS, and secure SDLC principles;
  • Strong collaboration and communication skills with the ability to work across interdisciplinary teams;
  • Excellent English proficiency (written and verbal);
  • Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or related field preferred.

CONSIDERED A PLUS

  • Experience with web application firewalls (WAFs), XDR, cloud monitoring, or API security tools;
  • Hands-on experience with penetration testing tools or workflows;
  • Previous involvement in Security Champions programs, internal training, or peer knowledge-sharing initiatives;
  • Security certifications such as CISSP, CSSLP, CompTIA Security+, CEH, or similar;
  • Experience with DevSecOps practices and security automation in CI/CD pipelines;
  • Knowledge of container security (Docker, Kubernetes security scanning);
  • Background in threat modelling or security architecture.

WHAT YOU WILL GET

  • Protect software innovation and secure development processes for products used by millions of professionals worldwide;
  • Choose when and how often you work from our Sofia, Varna, or Plovdiv offices;
  • Access to conferences, security training programs, certifications, and self-learning platforms;
  • Supportive environment where your security expertise matters and proactive ideas are valued;
  • Shape your role and grow within a 450+ person organisation with 25+ years of software excellence;
  • Diverse internal events and activities to build relationships across teams;
  • Comprehensive benefits and financial compensation.

We're looking for people with creative minds and enthusiasm to join us in developing what's new, what's next, and what best serves our customers' needs.

Ready to make an impact in software development? We'd be happy to welcome you to our team.

PERKS AND BENEFITS

Choose your work model

We are all about flexibility. That's why we adopted the hybrid work model – enabling employees to choose the work arrangement that works best for them.

Enjoy a supportive work environment

Enjoy the freedom to express your ideas and to get the support you need, when you need it.

Benefits and parent-friendly policy

Enjoy health, wellness and commuter benefits as well as our parent-friendly company policy.


TRAINING AND DEVELOPMENT

Personal development

Stimulate personal growth through individual coaching, personal development programmes.

Trainings and conferences

Get easy access to many high-quality conferences and trainings, both onsite and online.

Knowledge sharing

Benefit greatly from internal knowledge sharing. Acquire new knowledge, expand your networking skills and build confidence through mentorship.

Nemetschek Bulgaria is a leading software development company in Eastern Europe. We boast 25+ years of experience in driving innovation in different business areas. With over 450 professionals on board who are committed to leveraging our clients’ performance, all our customers associate our name with a reliable worldwide partner.

Read more

Our IT Security team embeds security-first practices across all software development activities, supporting secure development lifecycles for Nemetschek Bulgaria and partner projects. The team focuses on secure-by-design principles, security architecture, threat mitigation, and maintaining security infrastructure to protect software innovation.

Apply for this position


Позволени са файлове с разширения: pdf, doc или docx.


Можеш да прикачиш максимум до два файла. Позволени са файлове с разширения: pdf, doc или docx.

Запознах се с Политика за поверителност на Немечек България.

Съгласявам се да получавам последваща информация, свързана с професионални възможности в Немечек България.

PERKS AND BENEFITS

Choose your work model

We are all about flexibility. That's why we adopted the hybrid work model – enabling employees to choose the work arrangement that works best for them.

Enjoy a supportive work environment

Enjoy the freedom to express your ideas and to get the support you need, when you need it.

Benefits and parent-friendly policy

Enjoy health, wellness and commuter benefits as well as our parent-friendly company policy.

TRAINING AND DEVELOPMENT

Personal development

Stimulate personal growth through individual coaching, personal development programmes.

Trainings and conferences

Get easy access to many high-quality conferences and trainings, both onsite and online.

Knowledge sharing

Benefit greatly from internal knowledge sharing. Acquire new knowledge, expand your networking skills and build confidence through mentorship.