System Security Specialist | SSCC [System Security Competence Centre]
- Maintain, improve, and enforce existing system security standards and requirements for all Frequentis products, projects, and services.
- Develop, maintain and distribute new system security requirements to ensure ongoing compliance with ISO/IEC 27001, NIS2, CIS Controls/Benchmarks, the Cyber Resilience Act and industry best practices.
- Translate regulatory and standard updates (ISO 27001/2, NIS2, CRA) into actionable product/project security requirements, processes and templates.
- Provide guidance and enablement to the Project Security Managers, Security Champions and collaborate closely with the Security Agents from the (Strategic) Business Units
- Conduct security risk assessments and evaluate vulnerability scans, clearly communicating findings and recommendations to relevant stakeholders.
- Evaluate results from SAST/SCA/DAST and infrastructure scans, ensuring clear, actionable reporting.
- Lead or support security assessments (audits, reviews, tests) to ensure that Frequentis system security processes are applied and followed.
- Design and deliver security training programs and courses for Frequentis employees, fostering a culture of security awareness and best practice.
- Enable teams to integrate security into daily work through targeted enablement, coaching, and practical guidance.
- Education: Degree in Informatics, Computer Science, IT Security, or a related technical field (or equivalent experience).
- Experience: Several years in IT/Information Security with hands‑on DevSecOps/SDLC enablement and product security exposure.
- Standards/Regulation: Practical application of ISO/IEC 27001/2, NIS2; awareness of Cyber Resilience Act (CRA) for product organizations.
- AppSec & SDLC: Working knowledge of OWASP ASVS, OWASP Top 10, OWASP SAMM; experience with ASPM/DAST concepts and rollout.
- Tooling: Familiarity with SAST (SonarQube, Coverity), SCA (Black Duck), DAST (OWASP ZAP, Invicti/Netsparker); vulnerability scanning (e.g., Nessus Pro).
- Ways of Working: Strong communication and stakeholder management; ability to coach teams and drive adoption across global, cross‑functional environments.
- Language & Travel: Fluency in English; additional languages are a plus. Willingness to travel internationally (~20%).
- CISSP, CSSLP, CompTIA Security+
- Proactive, self‑driven, and outcome‑oriented with high personal initiative.
- Analytical and pragmatic—able to solve complex security problems and facilitate risk‑based decisions.
- Team player with a coaching mindset and a passion for continuous improvement.
We offer a range of benefits focused on work-life balance, professional development and flexibility.
| | | | | | | | | | | | |
| PRIVATE MEDICAL | SPORT | LUNCH | EXTRA | EXTRA | PUBLIC TRANSPORT | CERTIFICATIONS | TRAININGS | UNEQUAL | WORK | PRIVATE | |
| INSURANCE | PACKAGE | TICKETS | VACATION DAYS | WINTER HOLIDAY | SUBSCRIPTION | WORKING HOURS | FROM HOME | PENSION |
We offer a range of benefits focused on work-life balance, professional development and flexibility.
| | | | | | | | | | | | |
| PRIVATE MEDICAL | SPORT | LUNCH | EXTRA | EXTRA | PUBLIC TRANSPORT | CERTIFICATIONS | TRAININGS | UNEQUAL | WORK | PRIVATE | |
| INSURANCE | PACKAGE | TICKETS | VACATION DAYS | WINTER HOLIDAY | SUBSCRIPTION | WORKING HOURS | FROM HOME | PENSION |
Sonia-Oana Campean-Diaconescu
Human Resources | sonia.diaconescu@frequentis.com | Social media contact