обновлено 4 дня назад
Senior DevOps Security & SBOM Obsolescence
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior DevOps Security & SBOM Obsolescence (CI/CD and software supply chain security): Building and maintaining industrial CI/CD pipelines with integrated security controls, artifact traceability, and SBOM-based dependency analysis with an accent on obsolescence, EOL, and open-source vulnerability risks. Focus on mapping CVEs and transitive dependencies, analyzing CycloneDX/SPDX data without source-code access, and standardizing secure delivery across multiple projects.
Location: Lisbon, Portugal; remote work with up to 2 days per week on-site. Candidates must have an existing legal right to work in Europe.
Company
provides technology services and places the role with a client focused on industrial-grade CI/CD and security-by-design.
What you will do
- Design, implement, and maintain industrial CI/CD pipelines across multiple projects using GitLab CI, Azure DevOps, Jenkins, or equivalent tools.
- Integrate security controls into CI/CD workflows and strengthen the software delivery lifecycle.
- Manage dependencies, repositories, and artifacts with Artifactory or equivalent solutions, ensuring traceability.
- Analyze SBOMs in CycloneDX, SPDX, or similar formats to identify library obsolescence and end-of-life risks.
- Perform open-source vulnerability analysis by mapping findings to CVEs and transitive dependencies, using JFrog Xray or similar tools.
- Collaborate with Development, Security, Software Factory, and Management to standardize and industrialize delivery practices.
Requirements
- 4+ years of hands-on DevOps and CI/CD experience, including industrial pipeline development and maintenance.
- Strong experience with GitLab CI, Azure DevOps, Jenkins, or equivalent CI/CD tools.
- Knowledge of dependency management and repository or artifact solutions such as Artifactory.
- Practical experience integrating security controls into CI/CD pipelines and using SBOM standards such as CycloneDX or SPDX.
- Experience with JFrog Xray or similar security scanning tools, CVE mapping, and transitive dependency risk analysis.
- English at communicative B2 working proficiency and an existing legal right to work in Europe are required.
Nice to have
- Interest in automation, agent-based approaches, or GitHub Copilot for security and SBOM workflows.
- Contributions to standards or development methodologies.
- French at B2 level.
Culture & Benefits
- Hybrid remote setup based in Lisbon, with up to 2 days per week on-site.
- Work in an environment where security-by-design and industrial-grade automation are essential.
- Cross-functional collaboration across Development, Security, Software Factory, and Management.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →