R&D Security Manager (US)

Bluebeam, Inc.

United States

Hybrid

USD 129.000 - 162.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Hebe dich für diese Rolle von der Masse ab — erstelle in etwa einer Minute einen maßgeschneiderten Lebenslauf und ein Anschreiben.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Hybrid work model
Health & wellness benefits
Flexible working hours

Zusammenfassung

Nemetschek Group's HCSS unit seeks an experienced R&D Security Manager to embed security into the product development lifecycle. You will partner with Agile teams to prioritize risks, build a security champions program, and conduct train-the-trainer initiatives across R&D.

You will oversee secure source code management, regulatory compliance, and security documentation frameworks, coordinating with Shared Services and security leadership.

Qualifikationen

  • Bachelor’s or Master’s in Information Security, CS, Engineering, or related field.
  • Multiple years of experience in a security role, preferably within R&D or high-tech environments.
  • Extensive knowledge of cybersecurity technologies (WAF/DAST, API security, cloud monitoring, XDR).
  • Strong technical writing abilities and understanding of OWASP Top Ten.
  • Experience with secure coding practices and vulnerability management.

Aufgaben

  • Implement security strategies for the R&D department as part of the product development process.
  • Establish a train-the-trainer initiative for awareness and knowledge exchange across R&D personnel.
  • Review and implement source code repository hardening and change management according to guidelines.
  • Prioritize security issues in Sprint backlog.
  • Interface with Shared Services and security leadership teams.
  • Establish Security Documentation Framework and ongoing maintenance.
  • Identify and document remediation information for R&D engineers based on CVSS scores.
  • Assess security risks related to IP, confidential data, and emerging technologies.
  • Ensure GDPR compliance and industry standards through workshops.

Kenntnisse

WAF & DAST
API security
Cloud monitoring
XDR
Secure coding
OWASP Top Ten
Pentesting
Technical writing

Ausbildung

Bachelor's or Master's in Information Security/CS/Engineering
CISSP
CSSLP

Tools

Snyk
Jira

Jobbeschreibung

The Nemetschek Group is a pioneer in the digital transformation of the AEC/O industry, with a strong focus on open standards such as OPEN BIM. As one of the world’s leading groups in this industry, Nemetschek improves the construction process through intelligent software solutions that help customers plan, build, and operate buildings more efficiently, sustainably, and with fewer demands on resources.

HCSS, part of the Nemetschek Group, provides innovative software solutions that help heavy civil construction companies streamline their operations and improve productivity. While this position sits within Nemetschek, the R&D Security Manager will provide dedicated security support to HCSS and collaborate closely with its product development and engineering teams.

The R&D Security Manager will integrate security seamlessly into HCSS’s product development lifecycle, partnering with Agile teams to embed security into sprint planning and prioritize relevant risks. This person will establish initiatives such as a security champions program and “train-the-trainer” efforts to strengthen security awareness across R&D. The role will also support secure source code management, regulatory compliance, and the development of security documentation frameworks. By monitoring emerging threats and managing vulnerabilities, the R&D Security Manager will help protect intellectual property and sensitive data while serving as a key liaison among HCSS R&D, Nemetschek Shared Services, and the appropriate security leadership teams.

About the Role:

  • Implement comprehensive security strategies for the R&D department as part of the product development process (Agile Sprint Planning) and Reporting to Brand CISOs
  • Establish a train the trainer initiative for awareness and knowledge exchange throughout the R&D personnel
  • Review and Implement source code repository hardening and change management according to guideline
  • Prioritize security issues in Sprint backlog
  • Act as interface to Shared Services
  • Establish Security Documentation (Setup and Maintenance of the Framework)
  • Identify and document vulnerability remediation information (based on CVSS 4) to R&D engineers
  • Identify and assess security risks related to R&D activities, including intellectual property, confidential data, and emerging technologies
  • Ensure compliance with relevant security regulations like GDPR, industry standards, and company policies in software development through workshops

About You:

  • Education & Experience:
    • Bachelor’s or Master’s degree in Information Security, Computer Science, Engineering, or related field.
    • Multiple years of experience in a security role, preferably within R&D or high-tech environments.
  • Technical Skills:
    • Excellent Deep knowledge of cybersecurity technologies, such as web application firewalls, DAST, API security, Cloud and App Monitoring, XDR
    • Familiarity with security challenges in R&D, such as secure coding, technology transfer, and emerging technologies.
    • Technical Writing: Strong abilities for creating clear and comprehensive security documentation.
    • OWASP Top Ten: In-depth knowledge of the security risks and practical experience in mitigating these vulnerabilities.
    • Understanding of product development lifecycles and integrating security into R&D processes.
    • Proficiency in security-related software like Snyk and Jira.
    • Pentesting
  • Soft Skills:
    • ”Speaking Developers Language”
    • Strong problem-solving skills and the ability to manage complex projects.
    • Excellent communication and collaboration skills to work with multidisciplinary teams.
    • High ethical standards and attention to detail.
    • Mentoring and knowledge transfer
  • Certifications (preferred):
    • Certified Information Systems Security Professional (CISSP)
    • Certified Secure Software Lifecycle Professional (CSSLP) or similar

Why Nemetschek?

  • Impact:We offer you a diverse position in a motivating work environment where you can realize your ideas.
  • Sustainable Growth:In our sustainably growing and innovative company you have the chance to develop yourself further.
  • Culture:With us you work in an international team with flat hierarchies and short decision-making processes, in which you can make a difference.
  • Work-Life-Balance:We offer you various benefits in the areas of sports, nutrition, childcare and much more.
  • Health:The health of all employees is important to us, which is why we offer you a wide range of health and preventive care services.
  • Hybrid Way Forward:Through mobile working and variable working hours without core working hours, we enable you to be flexible, both professionally and privately.

We, the Nemetschek Group, are a global organization with employees from 60 nations. For us, diversity, equity, inclusion, and belonging are the keys to unleashing our full potential and driving true innovation. We can best support our customers in shaping the world through a diverse culture. We aim to treat EVERYONE with respect and appreciation, regardless of differences. Valuing diverse opinions and creating equal opportunities for all is of the utmost importance for us as an organization, and as individuals.

This role will report out of our Dallas or Sugarland office in a hybrid model.

Base Pay Range: $129,400 - $161,800 + Annual bonus

#Nemetschek #LI-FT1

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

R&D Security Manager
R&D Security Manager

Nemetschek Group • Dallas (TX)

Hybrid
USD 129.000 - 162.000
Hybrid work model
Health benefits
Career growth
R&D Security Manager
R&D Security Manager

NEMETSCHEK AG • Dallas (TX), Sugar Land (TX)

Vor Ort
USD 129.000 - 162.000
Hybrid work model
Health and preventive care
Sports and fitness programs
+1
R&D Security Manager — Secure Dev Lifecycle & Training
R&D Security Manager — Secure Dev Lifecycle & Training

NEMETSCHEK AG • Dallas (TX), Sugar Land (TX)

Vor Ort
USD 129.000 - 162.000
Hybrid work model
Health and preventive care
Sports and fitness programs
+1
Hybrid R&D Security Manager — Secure SDLC & Mentoring
Hybrid R&D Security Manager — Secure SDLC & Mentoring

Bluebeam, Inc. • USA

Hybrid
USD 129.000 - 162.000
Hybrid work model
Health & wellness benefits
Flexible working hours
Director, Security Architecture & Engineering
Director, Security Architecture & Engineering

Apply now! • Morrisville (NC)

Vor Ort
USD 180.000 - 200.000
401k match
Flexible PTO
Parental leave
Director, Cyber Security Wanted!
Director, Cyber Security Wanted!

HealthCare Talent • Irvine (CA)

Vor Ort
USD 130.000 - 160.000
RS/HS Security Engineer - R-10066853
RS/HS Security Engineer - R-10066853

NXP Semiconductors NV • San Jose (CA)

Vor Ort
USD 140.000 - 210.000
Director, Security Architecture & Engineering
Director, Security Architecture & Engineering

Bertelsmann-Jobs • Morrisville (NC)

Vor Ort
USD 180.000 - 200.000
401k match
Flexible PTO program
Inclusive parental leave policy
+2
Sr. Manager, R&D Operations
Sr. Manager, R&D Operations

Ladders • USA

Remote
USD 163.000 - 239.000
Health coverage
Parental leave
Self-care days (quarterly)
+4
Director, Security
Director, Security

Nexxen • Columbia (MD)

Vor Ort
USD 180.000 - 219.000
Medical insurance
401(k)
Unlimited vacation
+1