Security Engineer/ DevSecOps Engineer
- Hiring from
- Romania
- Work type
- Remote
- Posted
510,828 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
Who we are:
Ipsos is a global market research and insights company that helps clients make confident decisions in a rapidly changing world. More than a data provider, Ipsos acts as a strategic partner, delivering accurate and relevant insights that create a true understanding of society, markets, and people. By combining science, technology, and expertise, Ipsos enables clients to act faster, smarter, and with greater confidence. With a presence in 90 markets and over 20,000 employees worldwide, Ipsos serves more than 5,000 clients globally.
As Security Engineer in Ipsos, you will be allocated for 2 major projects - Ipsos Digital and Ipsos Askia.
Ipsos Digital: Ipsos Digital part of the Ipsos Group, delivers state-of-the-art digital research solutions that help clients make smarter, faster decisions. Our teams bring together software engineers, QA specialists, web designers, data scientists, product owners, and business development colleagues who work together to design, build, test, and scale digital solutions. We have a strong interest in market research and a practical focus on applying technology to this field. We continuously improve our platforms and tools to enhance how research results are delivered, visualized, and used by clients.
Ipsos Askia: We are Ipsos Askia, we are passionate about technology and insights. Ipsos Askia's ambition is to power Ipsos with tailored solutions that generate actionable insights and unlock business growth. We are a team of 65+ people working across France, Germany, Romania and the UK. What truly sets us apart is our culture of empowerment and ownership, harmoniously working together to create value. Our continuous quest for innovative solutions is aimed at proactively meeting the needs of the business.
Main responsibilities:
- Champion a shift-left security approach by having a very good understanding of the Ipsos Askia and Ipsos Digital ecosystems and embedding robust security practices early in the SDLC—partnering with development and product teams to enforce and implement threat modeling, secure coding standards, automate threat detection and testing, and drive continuous risk and vulnerability assessment from the initial stages of design to deployment and monitoring.
- Perform planned and ad-hoc internal technical audits, vulnerability scans and manage penetration tests to uncover any non-conformities, weaknesses, or potential threats.
- Support the internal Ipsos Askia and Ipsos Digital risk management part of SDLC and vulnerability management processes and ensure that appropriate actions are taken to mitigate identified issues and minimize risks.
- Supervise security and technical measures implemented and actively participate in governance and technical discussions related to platform information security and overall security and data protection strategies and propose new measures where appropriate.
- Supports the integration and continuous improvement of Ipsos Askia and Ipsos Digital ecosystems in applicable security monitoring tools and supports the Security Incident Management processes.
Requirements:
Proven experience in Secure Software Development Lifecycle (SSDLC) including:
- Conducting and documenting threat modeling (e.g., STRIDE, LINDDUN).
- Performing secure design reviews and architectural risk assessments.
- Executing manual and automated secure code reviews using industry-standard tools.
- Designing, implementing, and maintaining automated security testing pipelines (SAST, DAST, SCA, IaC, CNAPP, Endpoint protection).
- Providing security guidance to engineering, product and operations teams during software development lifecycles where required.
Hands-on experience in application security and modern development ecosystems from the following Ipsos tech stack:
- Programming languages such as C, C#, JavaScript, Python, Java, .NET, PHP
- Modern frameworks (e.g., Node.js, React, Angular, Django, Spring Boot, Laravel, Vue, Bootstrap).
- Cloud-native architectures, microservices, and API security (OAuth2, JWT, mTLS).
- Containerization and orchestration technologies: Docker, Kubernetes (GKE/EKS/AKS).
- CI/CD environments (Github Actions, GitLab CI, Github Rulesets)
Understanding of information security and compliance frameworks, such as:
- OWASP ASVS/Top 10, ISO 27001, ISO 9001, SOC 2, CIS Benchmarks, NIST CSF
- Experience supporting or leading initiatives to achieve or maintain security certifications for medium-to-large enterprises is highly advantageous.
Desirable: Google Cloud Platform (GCP) experience (e.g., IAM, Cloud Run, GKE, Secrets Manager, Cloud Security Command Center)
Benefits:
- Remote working
- Medical subscription (Regina Maria)
- Flexible Benefits platform (e.g.: Kindergarten, meal vouchers etc.)
- Referral bonus
- Bookster
- Eyeglasses reimbursement policy