Назад
Company hidden
1 день назад

Product Security Engineer (DevSecOps)

Формат работы
remote (только Poland)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Engineer (DevSecOps) (Cloud Security): Building secure CI/CD pipelines and integrating security controls across products, cloud platforms, and the software development lifecycle with an accent on SAST, DAST, SCA, container security, and cloud security. Focus on automating security testing, conducting threat modeling and security reviews, and driving vulnerability remediation with product and cloud engineering teams.

Location: Remote for candidates located in Poland

Company

hirify.global develops software products and cloud platforms and is expanding its Product Security organization.

What you will do

  • Design, develop, and maintain secure CI/CD pipelines using Jenkins, Kubernetes, Azure, and cloud-native technologies.
  • Integrate automated security testing and controls, including SAST, DAST, SCA, secrets detection, infrastructure-as-code scanning, container security, and software supply chain security.
  • Document and verify security mitigations, identify additional controls, and guide product development teams in remediation.
  • Conduct security reviews of applications, infrastructure, CI/CD workflows, and deployment architectures.
  • Support threat modeling, risk assessments, secure design reviews, security testing, and validation.
  • Develop automation with Python, PowerShell, Bash, or Groovy and collaborate with engineering, cloud, DevOps, and security stakeholders in Agile processes.

Requirements

  • 4+ years of hands-on experience with Jenkins or similar CI/CD platforms.
  • 3+ years of software development, automation, or scripting experience with Python, PowerShell, Bash, or equivalent languages.
  • Experience integrating SAST, DAST, SCA, container scanning, and secrets management into CI/CD pipelines.
  • Working knowledge of cloud security principles and Azure and/or AWS services, plus containerized environments and Kubernetes security.
  • Experience collaborating with engineering teams in Agile development environments.
  • Bachelor’s degree in computer science, information technology, cybersecurity, or equivalent practical experience.

Nice to have

  • Infrastructure as Code experience with Terraform, Bicep, or CloudFormation.
  • Experience with Azure DevOps pipelines and security integrations.
  • Knowledge of software supply chain security practices such as SBOM, SLSA, Sigstore, and provenance validation.
  • Experience securing Kubernetes and cloud-native platforms.
  • Relevant Azure, DevOps, or Kubernetes security certifications, including CKS or CKA.

Culture & Benefits

  • Security-first engineering culture across product and cloud teams.
  • Close collaboration with software engineers, cloud architects, DevOps teams, and security stakeholders.
  • Participation in daily standups, sprint planning, retrospectives, and collaborative design sessions.
  • Focus on reducing developer friction, automating compliance checks, and making security an engineering accelerator.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →