Senior DevSecOps Engineer [M/F]
You will join the team responsible for Software Delivery Automation, whose goal is to strengthen security throughout the Software Development Lifecycle (SDLC). The project covers two parallel areas. The first is supporting ongoing security initiatives related to, among others, the evolving threat landscape, the increasing use of AI, and the need for faster vulnerability detection and remediation. The second is a strategic assessment of the current security model of the software delivery process and defining the target strategy and roadmap for Secure Software Delivery for the entire platform ecosystem.
Daily tasks
- Supporting and developing initiatives related to the security of the software delivery process.
- Implementing and developing GitHub Advanced Security capabilities.
- Utilizing AI-assisted security capabilities in the area of vulnerability detection and remediation.
- Developing and promoting secure coding practices and activities supporting developers.
- Strengthening dependency management and software supply chain security.
- Improving vulnerability management and remediation processes.
- Preparing the organization for major vulnerability-related events and scenarios requiring accelerated patching.
- Assessing the current landscape of security tools and solutions in the software delivery process.
- Analyzing the current operating model and the way security is integrated with development and platform engineering processes.
- Identifying areas requiring improvement and defining recommendations.
- Co-creating the Secure Software Delivery strategy and a long-term development roadmap.
Requirements
Min. 6 years of experience in a similar position: DevSecOps, Application Security, Software Security, Platform Security, or related. Experience in leading security transformation initiatives. Practical experience in defining security strategies for engineering organizations. Experience in building or developing Secure Software Delivery / Secure SDLC. Experience collaborating with Platform Engineering, Development, Architecture, and Security Teams. Very good knowledge of CI/CD processes, software supply chain security, dependency management, and vulnerability management. Experience with GitHub / GitHub Advanced Security or similar solutions. Knowledge of secure coding practices and ways to integrate security into the developer process. Advanced knowledge of English.
Must have: Security, DevOps