1 день назад
Product Security Engineer (DevSecOps)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Product Security Engineer (DevSecOps) (Cloud Security): Building secure CI/CD pipelines and integrating security controls across products, cloud platforms, and the software development lifecycle with an accent on SAST, DAST, SCA, container security, and cloud security. Focus on automating security testing, conducting threat modeling and security reviews, and driving vulnerability remediation with product and cloud engineering teams.
Location: Remote for candidates located in Poland
Company
develops software products and cloud platforms and is expanding its Product Security organization.
What you will do
- Design, develop, and maintain secure CI/CD pipelines using Jenkins, Kubernetes, Azure, and cloud-native technologies.
- Integrate automated security testing and controls, including SAST, DAST, SCA, secrets detection, infrastructure-as-code scanning, container security, and software supply chain security.
- Document and verify security mitigations, identify additional controls, and guide product development teams in remediation.
- Conduct security reviews of applications, infrastructure, CI/CD workflows, and deployment architectures.
- Support threat modeling, risk assessments, secure design reviews, security testing, and validation.
- Develop automation with Python, PowerShell, Bash, or Groovy and collaborate with engineering, cloud, DevOps, and security stakeholders in Agile processes.
Requirements
- 4+ years of hands-on experience with Jenkins or similar CI/CD platforms.
- 3+ years of software development, automation, or scripting experience with Python, PowerShell, Bash, or equivalent languages.
- Experience integrating SAST, DAST, SCA, container scanning, and secrets management into CI/CD pipelines.
- Working knowledge of cloud security principles and Azure and/or AWS services, plus containerized environments and Kubernetes security.
- Experience collaborating with engineering teams in Agile development environments.
- Bachelor’s degree in computer science, information technology, cybersecurity, or equivalent practical experience.
Nice to have
- Infrastructure as Code experience with Terraform, Bicep, or CloudFormation.
- Experience with Azure DevOps pipelines and security integrations.
- Knowledge of software supply chain security practices such as SBOM, SLSA, Sigstore, and provenance validation.
- Experience securing Kubernetes and cloud-native platforms.
- Relevant Azure, DevOps, or Kubernetes security certifications, including CKS or CKA.
Culture & Benefits
- Security-first engineering culture across product and cloud teams.
- Close collaboration with software engineers, cloud architects, DevOps teams, and security stakeholders.
- Participation in daily standups, sprint planning, retrospectives, and collaborative design sessions.
- Focus on reducing developer friction, automating compliance checks, and making security an engineering accelerator.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
DevSecOps Engineer (Cybersecurity)
2 750 - 4 800€
17 часов назад
Senior DevSecOps Engineer
71 000 - 104 500€
4 дня назад
Application Security Engineer
1 день назад
Security Architect (AI)
3 дня назад
Product Security Engineer (Cybersecurity)
115 000 - 145 000$
23 часа назад
Product Security Engineer III (Cybersecurity)
107 700 - 285 900$