Location: Bucharest, Romania
Thales is a global technology leader trusted by governments, institutions, and enterprises to tackle their most demanding challenges. From quantum applications and artificial intelligence to cybersecurity and 6G innovation, our solutions empower critical decisions rooted in human intelligence. Operating at the forefront of defence and security, aerospace and space, cybersecurity and digital identity, we’re driven by a mission to build a future we can all trust.
In Romania, we are advancing innovation through software engineering, research and development, delivering solutions in key markets in which Thales Group operates. Our engineers design, develop and integrate solutions that impact global industries – from fully operational systems and subsystems for naval warfare and maritime security operations, to air traffic management systems, satellite-based solutions, tactical indoor simulations, identity and biometric technologies and more.
The mission:
A trusted, sovereign Google Cloud region operated end-to-end from within Europe by the joint venture between Thales and Google Cloud. Same Google Cloud power (GKE, Compute, Data, Vertex AI), European jurisdiction, European operators, Thales-grade cybersecurity.
In the last 6 months alone: world-first regulatory qualification (IaaS + CaaS + PaaS in a single decision, SecNumCloud 3.2, December 2025), named 2026 Google Cloud Partner of the Year for Sovereign Cloud, 3 data centres, 10,000+ devices, NVIDIA H100 GPU clusters in production, workloads across energy, banking, healthcare, and defense.
We are standing up the SRE function for this platform from scratch. Bucharest is the primary hub, Q3 / Q4 2026 hiring window. You are joining a greenfield team, not inheriting one.
HIRING ACROSS ALL EXPERIENCE LEVELS (Junior | Mid | Senior | Lead):
We are building this team from the ground up and are hiring engineers across all levels of experience. Whether you are starting your career in Site Reliability Engineering or already leading security platform initiatives, we encourage you to apply.
All candidates go through the same recruitment process. During the interview stages, we will assess your technical experience and determine the level that best matches your skills, background, and potential.
Why this role matters:
You will design and operate the security foundations of a sovereign cloud region: HashiCorp Vault as a platform-wide secrets service, PKI hierarchies, Cloud KMS strategies, Keycloak identity federation, TPM/HSM trust roots, and ELK-based SIEM detection.
You will partner with platform, network, and data SRE teams to ensure security-by-design is a real engineering discipline, not documentation.
What you will do:
Operate HashiCorp Vault at platform scale (topology, policies, secret engines, PKI backend)
Design and operate Cloud KMS strategies (rotation, BYOK/HYOK, HSM integration)
Own the platform PKI (root and intermediate CAs, certificate lifecycle, mTLS patterns)
Configure and maintain Keycloak / Identity Provider federation for human and machine identities
Implement ELK-based security monitoring (detection rules, log correlation, forensic workflows)
Contribute to TPM/HSM attestation and hardware trust root patterns
Drive incident response, post-mortems, and continuous improvement of the security posture
Participate in a follow-the-sun on-call rotation alongside Google Cloud SRE teams
What we are looking for:
We hire for strong engineering fundamentals, depth in at least one area of the stack, breadth across adjacent technologies, and the willingness to grow into the rest.
You may have experience in some or all of the following:
Site Reliability Engineering or Security Platform Engineering
HashiCorp Vault (or another enterprise secrets management platform)
Identity and Access Management (Keycloak, Google Workspace, Okta, or similar)
Cloud KMS and encryption key management
Linux administration and cloud security best practices
Kubernetes security and secrets management (External Secrets Operator, Sealed Secrets, CSI Driver)
Terraform or other Infrastructure as Code tools
SIEM / detection engineering with ELK
PKI, certificates, mTLS, HSMs, TPMs, or hardware roots of trust
Experience working in regulated industries such as banking, healthcare, telecommunications, energy, or defense
Minimum requirement:
Good Linux fundamentals
Strong interest in cloud infrastructure and security
Excellent English, as you will work in an international team and participate in a follow-the-sun operating model
Why join:
Greenfield SRE function, Bucharest hub. Join before the organisation exists and help define the standards that future teams will inherit.
Accelerated Google training program on Google's internal technical stack (Borg, Colossus, Spanner) as part of onboarding.
Direct technical collaboration with Google Cloud SRE teams in a follow-the-sun operating model.
Sovereign cloud, first-of-its-kind, SecNumCloud 3.2 qualified, supporting regulated workloads across banking, healthcare, energy, and defense.
Hyperscaler-level scale of operations from a single location. No relocation required.
Competitive package, private medical insurance, meal vouchers, sports benefit, and the standard Thales benefits package.
Apply
We welcome applications from Junior, Mid, Senior, and Lead engineers.
Applications are reviewed within a single recruitment pipeline, and candidates are matched to the appropriate seniority level based on their technical experience, interview performance, and overall fit for the team.
At Thales, we’re committed to fostering a workplace where respect, trust, collaboration, and passion drive everything we do. Here, you’ll feel empowered to bring your best self, thrive in a supportive culture, and love the work you do. Join us, and be part of a team reimagining technology to create solutions that truly make a difference – for a safer, greener, and more inclusive world.