14 часов назад
DevSecOps Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
DevSecOps Engineer (Python/Kubernetes): Scaling shift-left security across the software development lifecycle with an accent on security scanning pipelines, Kubernetes golden images, and vulnerability reporting. Focus on integrating SAST, DAST, and SCA tooling, maintaining automated security platforms, and remediating third-party dependency vulnerabilities through Java/Maven testing and Bamboo qualification pipelines.
Location: Veldhoven, Netherlands
Company
.
What you will do
- Own and maintain security scanning pipelines for product releases using Atlassian Bamboo, Bitbucket, and Azure DevOps.
- Develop shift-left security scanning and near real-time vulnerability reporting for product teams.
- Govern security-hardened Kubernetes golden images and propagate updates to consumer microservices.
- Administer ASPM tooling and contribute to the internal lifecycle and vulnerability management portal built with Python, Docker, Kubernetes, and Helm.
- Integrate and operate SAST, DAST, SCA, and artifact security tools, including SonarQube, Checkmarx, OWASP ZAP, Black Duck, Trivy, and JFrog Xray.
- Investigate and remediate third-party dependency vulnerabilities, update Maven dependencies, validate fixes with JUnit, and run Bamboo qualification pipelines.
Requirements
- 4+ years of experience in DevOps, DevSecOps, or a closely related engineering role.
- Bachelor’s or Master’s degree in a technical field, or equivalent professional experience.
- Python development skills and the ability to maintain and extend existing tooling.
- Working knowledge of Java and Maven, including dependency updates, version conflict resolution, and JUnit test execution.
- Experience with Docker, Kubernetes, Helm, CI/CD pipelines, Bash, and Git.
- Ability to collaborate with development, operations, and security stakeholders and translate security challenges into maintainable automated solutions.
Nice to have
- Knowledge of CIS, MITRE, NIST, ISO 27001, or EU CRA frameworks.
- Experience with ASPM, secrets management, infrastructure-as-code, or SIEM tools.
- Familiarity with JFrog Xray, Artifactory, SAST, DAST, and SCA tooling.
- Security certifications such as CISSP or Security+.
- Experience with AI-assisted development tools, including GitHub Copilot, AI agents, and agentic workflows.
Culture & Benefits
- Work in a central DevSecOps team alongside a Senior DevSecOps Engineer.
- Develop practical security expertise through hands-on work and guided learning.
- Collaborate across technical and non-technical teams to improve secure engineering practices.
- Access to a diverse and inclusive working environment.
- Access to controlled technology requires prior legal authorization under United States export administration regulations.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →