Назад
Company hidden
обновлено 4 дня назад

Senior DevOps Security & SBOM Obsolescence

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Portugal/Europe
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior DevOps Security & SBOM Obsolescence (CI/CD and software supply chain security): Building and maintaining industrial CI/CD pipelines with integrated security controls, artifact traceability, and SBOM-based dependency analysis with an accent on obsolescence, EOL, and open-source vulnerability risks. Focus on mapping CVEs and transitive dependencies, analyzing CycloneDX/SPDX data without source-code access, and standardizing secure delivery across multiple projects.

Location: Lisbon, Portugal; remote work with up to 2 days per week on-site. Candidates must have an existing legal right to work in Europe.

Company

hirify.global provides technology services and places the role with a client focused on industrial-grade CI/CD and security-by-design.

What you will do

  • Design, implement, and maintain industrial CI/CD pipelines across multiple projects using GitLab CI, Azure DevOps, Jenkins, or equivalent tools.
  • Integrate security controls into CI/CD workflows and strengthen the software delivery lifecycle.
  • Manage dependencies, repositories, and artifacts with Artifactory or equivalent solutions, ensuring traceability.
  • Analyze SBOMs in CycloneDX, SPDX, or similar formats to identify library obsolescence and end-of-life risks.
  • Perform open-source vulnerability analysis by mapping findings to CVEs and transitive dependencies, using JFrog Xray or similar tools.
  • Collaborate with Development, Security, Software Factory, and Management to standardize and industrialize delivery practices.

Requirements

  • 4+ years of hands-on DevOps and CI/CD experience, including industrial pipeline development and maintenance.
  • Strong experience with GitLab CI, Azure DevOps, Jenkins, or equivalent CI/CD tools.
  • Knowledge of dependency management and repository or artifact solutions such as Artifactory.
  • Practical experience integrating security controls into CI/CD pipelines and using SBOM standards such as CycloneDX or SPDX.
  • Experience with JFrog Xray or similar security scanning tools, CVE mapping, and transitive dependency risk analysis.
  • English at communicative B2 working proficiency and an existing legal right to work in Europe are required.

Nice to have

  • Interest in automation, agent-based approaches, or GitHub Copilot for security and SBOM workflows.
  • Contributions to standards or development methodologies.
  • French at B2 level.

Culture & Benefits

  • Hybrid remote setup based in Lisbon, with up to 2 days per week on-site.
  • Work in an environment where security-by-design and industrial-grade automation are essential.
  • Cross-functional collaboration across Development, Security, Software Factory, and Management.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →