Now hiring

CYBER DEVSECOPS MANAGER (BUCHAREST, RO, 020335) @ JT International S.A.

BUCHAREST, RO, 020335OnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p> </p> <p> </p> <p>At JTI we celebrate differences, and everyone truly belongs. <strong>46,000 people from all over the world</strong> are continuously building their unique success story with us.<strong> 83% of employees feel happy </strong> working at JTI.</p> <p> </p> <p>To make a difference with us, all you need to do is bring your <strong> human best.</strong></p> <p><strong> </strong></p> <p>What will your story be? Apply now! </p> <p><strong>Learn more: <a href="https://www.jti.com/" target="_blank" rel="noopener">jti.com</a></strong></p> <p><strong> </strong></p> <p><strong> </strong></p><p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="text-align:center;margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="color:black"><strong><span style="font-size:24.0pt;line-height:115%;font-family:Arial, sans-serif">Cyber DevSecOps Manager</span></strong></span></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><span style="font-family:Arial, sans-serif">What this position is about – Purpose: </span></strong></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">This position exists to ensure the consistent security of JTI’s Digital Ecosystem (DES) and global applications, including e-commerce solutions. The role is responsible for defining and implementing technical security standards across these platforms, embedding secure DevOps practices into CI/CD environments (e.g., Azure DevOps, GitLab, GitHub), and protecting applications from internal and external threats while promoting shift-left security practices throughout the software development lifecycle.</span></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">As part of the Cyber Security Centre, this role contributes to the delivery of high-quality, cost-effective security services across JTI’s global infrastructure and application landscape—including security architecture, design, innovation, assurance, service delivery, and SOC operations.</span></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">The position also drives the adoption of security tools and best practices, conducts threat assessments, and partners closely with engineering, product, and operations teams to ensure the secure design, development, and deployment of cloud-based and mobile solutions. It requires a strong foundation in cloud and container security, Secure SDLC, application security tooling (e.g., SAST, DAST, SCA), and secure coding principles, with a particular focus on Azure environments.</span></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Ultimately, this role is critical to maintaining a secure, compliant, and resilient digital environment aligned with corporate and industry security standards.</span></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><span style="font-family:Arial, sans-serif">What will you do – Responsibilities: </span></strong></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><u><span style="font-family:Arial, sans-serif">Security Integration in CI/CD</span></u></strong></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul style="margin-top:0.0cm;margin-bottom:0.0cm" type="disc"> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Responsible for integrating and maintaining security tools in the CI/CD pipeline to ensure secure development and deployment</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Assist in identifying, tracking, and prioritizing security vulnerabilities in the development environment</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Support the remediation of vulnerabilities, collaborating with development and operations teams to address security issues</span></li> </ul> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><u><span style="font-family:Arial, sans-serif">Security Tool Administration, Monitoring and Reporting</span></u></strong></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul style="margin-top:0.0cm;margin-bottom:0.0cm" type="disc"> <ul style="margin-top:0.0cm;margin-bottom:0.0cm" type="disc"> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Assist in configuring, maintaining, and troubleshooting security tools used in the CI/CD pipeline, such as static and dynamic application security testing (SAST/DAST), and software composition analysis (SCA)</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Ensure that tools are functioning properly, with regular updates and maintenance to keep them current</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Monitor CI/CD environments for security threats, running regular security scans and audits</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Assist in generating reports on security findings, tracking resolution progress, and ensuring transparency in security posture</span></li> </ul> </ul> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><u><span style="font-family:Arial, sans-serif">Security Awareness &amp; Training</span></u></strong></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul style="margin-top:0.0cm;margin-bottom:0.0cm" type="disc"> <ul style="margin-top:0.0cm;margin-bottom:0.0cm" type="disc"> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Contribute to security awareness initiatives within development teams, promoting secure coding practices</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Educate teams on common vulnerabilities and industry best practices to enhance overall security knowledge</span></li> </ul> </ul> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><u><span style="font-family:Arial, sans-serif">Governance</span></u></strong></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul style="margin-top:0.0cm;margin-bottom:0.0cm" type="disc"> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Ensure adherence to security standards, frameworks (e.g. OWASP, NIST, ISO, PCI DSS), and JTI security policies</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Support the development of security policies, ensuring that security best practices are consistently followed across the team</span></li> </ul> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><span style="font-family:Arial, sans-serif">Who are we looking for – Requirements: </span></strong></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><span style="font-family:Arial, sans-serif">Education:</span></strong><span style="font-family:Arial, sans-serif"> University degree in Computer Science, Computer Engineering, Information Systems, or related field or relevant experience</span></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><span style="font-family:Arial, sans-serif">Work experience: </span></strong><span style="font-family:Arial, sans-serif">working experience on the following new technology trends:</span></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul style="margin-top:0.0cm;margin-bottom:0.0cm" type="disc"> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">5+ years of solid knowledge in cloud and container security, including the specific characteristics of cloud-based security services and securing web/mobile applications</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">5+ years of hands-on experience in operational Cybersecurity, DevOps, or DevSecOps, with strong knowledge of the Secure SDLC approach and the ability to articulate security goals, lifecycle stages, and related processes</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Experience implementing Secure SDLC and integrating security into CI/CD pipelines with a shift-left approach</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Proficient in Azure, Python, Bash, and using tools like SCA, SAST, DAST/IAST, and image scanning</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Knowledge of security standards (OWASP, NIST, ISO, PCI DSS) and experience with tools like Blackduck, Coverity on Polaris, Advanced Security, WIZ etc.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Familiar with cloud-native security controls, secure coding practices, and threat modeling (e.g., OWASP Threat Dragon)</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Strong knowledge of network security, including common protocols and the OSI model.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Hands-on experience with Infrastructure-as-Code (IaC) tools (e.g., Terraform), and CI/CD platforms such as GitLab, Azure DevOps, and GitHub, including integrating security tools into pipelines.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Good understanding of containerization and Kubernetes, especially from a security perspective.</span></li> </ul> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><span style="font-family:Arial, sans-serif">Language:</span></strong><span style="font-family:Arial, sans-serif"> English professional working proficiency (spoken and written) </span></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong><span style="font-family:Arial, sans-serif">What are the next steps:</span></strong></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul style="margin-top:0.0cm;margin-bottom:0.0cm" type="disc"> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Interview with GBS Talent Attraction Expert </span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">Online interview with the Hiring Manager and one of his Team</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">2nd Line Interview for Finalists</span></li> </ul> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:Arial, sans-serif">All applications will be reviewed. Please be aware that you will receive the call from Poland (prefix +48), as our Global Business Services is based in Warsaw. </span></p> <p style="margin:0.0cm 0.0cm 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><em><span style="font-family:Arial, sans-serif"> </span></em></p><p> </p> <p>Are you ready to join us? Build your success story at JTI. Apply now!</p> <p>Next Steps:</p> <p> </p> <p>After applying, if selected, please anticipate the following within 1-3 weeks of the job posting closure: Phone screening with Talent Advisor > Assessment tests > Interviews > Offer. Each step is eliminatory and may vary by role type.</p> <p> </p> <p>At JTI, we strive to create a diverse and inclusive work environment. As an equal-opportunity employer, we welcome applicants from all backgrounds. If you need any specific support, alternative formats, or have other access requirements, please let us know.</p> <p> </p> <p><img style="height:102.0px;width:227.0px" src="https://performancemanager5.successfactors.eu/doc/custom/JTIPROD/Top_Employer_Romania_2025.png" alt=""> <img style="height:102.0px;width:227.0px" src=" https://performancemanager5.successfactors.eu/doc/custom/JTIPROD/Top_Employer_Europe_2025.png" alt=""> <img style="height:102.0px;width:227.0px" src="https://performancemanager5.successfactors.eu/doc/custom/JTISTAGING/Top_Employer_Global_2025.png" alt=""></p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores