Skús vyladenú mobilnú aplikáciu

rating

Senior Security Engineer

Menej ako 2 týždne

Zebra Technologies Slovakia s.r.o.

Bratislava, Slovak Republic

Vzdialenosť od teba uvidíš po zadaní adresy vo výpise ponúk.


Plat

od 3 000 € hrubého

Úväzok

Práca na plný úväzok

Vzdelanie

Stredoškolské alebo odborné vyučenie s maturitou

Jazyky

Angličtina (Stredne pokročilá)

Zaradené

Informačné technológie, Špecialista IT bezpečnosti


O pozícii

Náplň práce, právomoci a zodpovednosti:

About this position

We are looking for a practical, hands-on Senior Security Engineer to protect the company's multidisciplinary R&D infrastructure, cloud systems, and cutting-edge industrial products. You are not a compliance-only theorist — you are an engineer who understands systems from the ground up, thrives in technical problem-solving, and designs defensible security controls that work in practice. You will bridge the gap between corporate security, software/firmware engineering, and hardware operations, ensuring our fleet, supply chain, and deployment pipelines are resilient, compliant, and continuously hardened.

Location

Bratislava, Slovakia

Type of Employment

Full-time

Salary (brutto)

€3,000 - €3,500 (based on experience and seniority)

Reports to

Chief Technology Officer

Key Responsibilities:

  • Security Strategy & Architecture: Define baseline security standards, policies, and tooling roadmaps across the company; establish threat modeling and architectural security reviews for new products and features.
  • Vulnerability & Fleet Lifecycle Management: Own vulnerability management end-to-end across cloud, workstations, and a mixed Linux/ARM fleet. Triage CVEs, design pragmatic mitigations/rollbacks when patches are unavailable, and enforce CIS baseline hardening.
  • Secure Pipeline & Supply Chain: Implement automated security gates across the SDLC—driving SBOM generation, container scanning, secret scanning, and integrating SAST/DAST tools (SonarQube, Semgrep, OWASP ZAP) into active CI pipelines.
  • Identity, Secrets & Code-Signing Custody: Manage encrypted secret stores and safeguard production cryptographic infrastructure, including hardware tokens/HSMs, certificate lifecycles, and automated code-signing pipelines.
  • Compliance, Incident Response & Enablement: Act as the operational bridge to the corporate SOC. Drive security awareness across R&D teams, mentor engineers on secure coding practices. Lead incident triage to meet our 24-hour SLA, navigate regulatory frameworks (EU Cyber Resilience Act / NIS2), and partner directly with engineering teams to resolve security findings in Jira.

Requirements:

  • Education: Degree in Computer Science, Cybersecurity, Software Engineering, STEM field, or equivalent practical experience.
  • Experience: Minimum 5+ years of hands-on experience in infrastructure/product security, systems administration (Linux/embedded), or SecOps within an engineering or R&D environment.
  • Security & Infrastructure Tooling: Practical experience with IaC & scripting (Ansible, Python, Bash), vulnerability scanners (Tenable, Qualys, or cloud-native tools), container security (Trivy, Artifactory Xray, Snyk), and major cloud platforms (GCP preferred, AWS/Azure).
  • Cryptographic & Application Fundamentals: Solid understanding of secret hygiene, PKI/HSM key custody, and OWASP Top 10/ASVS standards.
  • Languages: Fluent English

Essential attributes:

  • Pragmatic Problem-Solver: You focus on real exploitability and attack surface reduction over theoretical check-the-box exercises, designing compensations when vendor patches don't exist.

  • Cross-Functional Bridge: You communicate security risks and remediation clearly to software, algorithm, and hardware engineers without relying on top-down authority.

  • Ownership & Vigilance: You take full ownership of system coverage, distinguishing between an asset that is truly secure and one that simply lacks monitoring.

Nice to have / Beneficial:

  • Experience with embedded/IoT security (Yocto hardening, secure boot, signed OTA updates like RAUC/SWUpdate).
  • Working knowledge of OT/industrial cybersecurity standards (IEC 62443) or product PSIRT/VEX reporting.
  • Familiarity with SIEM/EDR log analysis (CrowdStrike Falcon, ELK) and exploit verification in isolated lab environments.

Benefits
Core benefits from day one:

  • Daily breakfast at the office
  • Option to work from home / hybrid work model
  • Flexible working hours
  • Unlimited sick days
  • Parking for everyone, bicycle storage, showers, and lockers available on-site
  • Summer terrace with a view of Bratislava
  • Pet-friendly office – bring your pet to work
  • MultiSport Card
  • Professional development support
  • Generous referral bonus

Additional benefits after the first anniversary
Employees can choose one of the following:

  • Annual public transport pass (MHD)
  • Annual healthcare package at the private ProCare clinic
  • Annual MultiSport card
  • 3rd pillar pension – employer contribution (retirement savings)
  • Brain Boost – contribution toward professional development and other educational activities
  • Alza Explorer Pass - voucher for e-shopping
  • And more...

Alebo skús mobilnú apku

Uvidíš ponuky vo svojom okolí a všetky svoje odpovede budeš mať vždy poruke

Naskenuj kód

V Práci za rohom máš najväčšiu šancu nájsť si prácu blízko domova a prestať dochádzať. Vyberaj z voľných miest a brigád po celom Slovensku, napríklad v lokalitách Bratislava, Košice, Prešov, Žilina, Banská Bystrica, Nitra, Trnava, Trenčín a mnohých ďalších.

Používame cookies, pozri Podmienky služby. A tiež chránime tvoje osobné údaje, pozri Zásady ochrany súkromia. Viac o reklame na portáloch Alma Career a transparentnosti si môžete prečítať na našej Informačnej stránke. Tu je naša Technická špecifikácia.