AdTechTalent
Other1 month agoHybrid

Merkle

Security Analyst (CXM)

security analystsecurity assessmentspenetration testingvulnerability managementsecure development lifecycleSDLCcloud securityAWSAzureGCPWizOneTrustGitHubGitLabBitbucketCompTIA Security+CISMNetwork+risk managementcybersecurity

Key details

Salary

Not specified

Employment type

Full-time

Seniority

Mid-level

Years experience

3-5

Location

Brno, Czech Republic

Full job description

Security Analyst (CXM) role in Czech Republic with hybrid work. Responsible for conducting product security assessments, supporting remediation plans, assisting risk management, working with Cyber Operations on vulnerability remediation, ensuring third-party security assessments, collaborating with security teams, and embedding security early in the software development lifecycle. Requires knowledge of secure software development, SDLC, security tooling (GitHub, GitLab, Bitbucket), cloud infrastructure (AWS, Azure, GCP), and security certifications (CompTIA Security+, CISM, Network+). Benefits include 5 weeks vacation, volunteering days, wellness days, flexible hours, hybrid work, learning platform access, dog-friendly office, meal vouchers, team events, referral bonuses, and equipment provided.

What you'll do

  • Help teams build and maintain secure applications and products
  • Support day-to-day security activities across secure development processes, security testing, penetration testing, vulnerability management, and secure architecture
  • Assess current and new products against security requirements
  • Support risk management activities
  • Drive remediation of identified weaknesses and vulnerabilities
  • Work closely with Product, DevOps, Cyber Operations, Security Architecture, Project, Pen Testing and Risk teams
  • Embed security early in the software development lifecycle
  • Manage stakeholders effectively
  • Drive practical security outcomes

Requirements

  • Conduct product security assessments for existing and new products
  • Review products against defined security requirements
  • Partner with Product and DevOps teams to prioritise and support remediation plans
  • Assist with risk management process and technical risk assessment
  • Work with Cyber Operations team to ensure vulnerabilities are raised and remediated
  • Ensure third-party security assessments are completed as required
  • Collaborate with Security function teams including Cyber Operations, Security Architecture, Pen Testing and Risk
  • Build strong working relationships with business and development stakeholders
  • Apply knowledge of secure software development and SDLC
  • Support embedding security early in the lifecycle with guidance on secure design and coding practices
  • Respond to client RFIs and support due diligence activities
  • Analyze issues from multiple perspectives to drive effective outcomes
  • Familiarity with Wiz is highly beneficial
  • Knowledge of code repositories and security tooling such as GitHub, GitLab, Bitbucket
  • Experience with OneTrust is a plus
  • Understanding of cloud infrastructure across AWS, Azure, or GCP
  • Security-related certifications or training such as CompTIA Security+, CISM, or Network+ are a plus

Tech stack

WizGitHubGitLabBitbucketOneTrustAWSAzureGCPCompTIA Security+CISMNetwork+

Benefits

5 weeks of vacation2 volunteering days3 extra wellness daysMental Health First Aider and Employee Assistance programFlexible working hours and home office possibilityHybrid working with expectation of 1 day per week or 4 days per month in officeFull access to Dentsu Academy global online learning platformDog-friendly officeEdenred meal vouchers and cafeteria pointsTeam events such as company parties and breakfastsSnacks and drinks at the officeReferral bonus programLaptop and equipment providedCorporate mobile subscriptionFlexible hybrid home office working conditions

Apply now

Ready to take the next step in your career? Click the button below to continue to the application process.

Similar jobs

More roles worth a look

Related opportunities based on specialty and working model so candidates can keep momentum.