Sr Security Engineer

3 giorni fa

Turin, Piedmont, Italia Qualcomm Tempo pieno

Company

Qualcomm Europe, Inc. Italy Branch Office

Job Area

Engineering Group, Engineering Group > Software Engineering

General Summary

Arduino’s mission is to enable people to enhance their lives through accessible open-source electronics and digital technologies. Since 2005, millions of people from around the world—from young kids to university students and to professionals in diverse fields—have been using Arduino to innovate in music, games and toys, smart homes, farming, autonomous vehicles, and many more. We are looking for a Sr Cloud Security Engineer to join our team of expert professionals eager to share their knowledge and to be part of this vibrant company’s journey toward the democratization of technology. The role includes ensuring the security of Arduino Software and Cloud platforms and fostering awareness inside the company about security best practices.

What We Offer

  • A challenging career path in a rapidly growing company with a modern vision and talented teams.
  • A competitive salary (and benefits) that values people's skills and experience.
  • A young and inspiring work environment that encourages diversity and cultural exchange.
  • Individual growth objectives with a dedicated budget for learning/training.
  • Flexible working hours and working locations; we value work‑life balance.
  • A meaningful work opportunity in a mission‑driven company committed to empowering people around the world.
  • Ping pong and football tournaments (sport or gym benefit is also included for everyone).
  • Seasonal celebrations, happy hours, and everyday drinks and snacks at the office.
  • Sunny rooftop lunch breaks and hamacas for relaxation and concentration.

What You’ll Work On

  • Ensure that the data we are trusted to protect is secured to the highest standards.
  • Help the Development and DevOps teams with Security Best Practices.
  • Provide security guidance on a constant stream of new projects and technologies.
  • Provide subject‑matter expertise on architecture, authentication, and system security.
  • Design, implement, and manage security solutions for AWS environments through IaC technologies.
  • Implement and manage standard AWS security tools, including AWS Security Hub, GuardDuty, Inspector, CloudTrail, WAF, KMS, Config, and IAM Access Analyzer.
  • Build secure CI/CD pipelines adopting DevSecOps principles and AI Security Agent technologies.
  • Build internal tools for detecting and responding to security problems and incidents.
  • Monitor cloud environments for security incidents and anomalies, and respond to suspected incidents in a timely manner.
  • Collaborate with Infrastructure and Application development teams to integrate security controls in the cloud using standardized configuration tools.
  • Work with product development teams to implement security controls that comply with recognized regulatory, compliance, and standards such as R2, EN18031, and CRA.
  • Make informed prioritization decisions by assessing risk across vulnerability management activities, including CVE triage, CVSS scoring, coordinated disclosure, and collaboration with external reporters.
  • Ensure alignment and compliance with ISO27001 and provide the definition of Security policy for the organization, including training of company employees on security policy.

Minimum Qualifications

  • Bachelor’s degree in Engineering, Information Systems, Computer Science, or related field and 6+ years of Software Engineering or related work experience.
  • Master’s degree in Engineering, Information Systems, Computer Science, or related field and 5+ years of Software Engineering or related work experience.
  • PhD in Engineering, Information Systems, Computer Science, or related field and 4+ years of Software Engineering or related work experience.
  • 3+ years of work experience with a programming language such as C, C++, Java, Python, etc.

What You Bring

  • Bachelor or Master Degree in Computer Science or related field, or equivalent experience.
  • 5+ years of experience in security engineering or comparable experience (DevOps, SRE).
  • Experience in containerisation / orchestration with Docker and Kubernetes.
  • Strong, well‑rounded background in host, network, and cloud security.
  • Experience in designing and defining secure cloud native systems.
  • Experience with applied cryptography including PKI, TLS, and key management.
  • Expertise with modern programming languages and software versioning tools (GIT/GitHub).
  • Knowledge of relevant security compliance, standards and regulations (ISO, SOC, NIST, GDPR, CIS, CRA).
  • Knowledge of internet security issues and the threat landscape (OWASP, STRIDE, MITRE ATT&CK, CWE).
  • Experience with security monit