DevOps / DevSecOps - Industrialization & Cybersecurity (M/F)
As part of the structuring of its development organization, our client wishes to strengthen its human-sized IT team with a DevOps / DevSecOps profile.
The objective of the position is to better structure and secure the application lifecycle: version management, packaging, deployment, automation, traceability, and the integration of cybersecurity issues into development practices. In an environment where versatility is important, the recruited person will be required to intervene on several technical subjects and work closely with developers and other members of the IT team. The position is also part of a process of preparing for the requirements of the Cyber Resilience Act (CRA).
Main Missions You will specifically intervene on:
- the structuring of build, packaging, version management, and deployment processes;
- the preparation and maintenance of deployment sheets and procedures;
- the industrialization and automation of CI/CD pipelines;
- the automation of certain operations with tools such as Ansible;
- the tracking of versions, actions, and evolutions in Jira;
- the deployment and operation of technical tools, notably around OpenSearch;
- collaboration with developers in order to integrate operational, deployment, and security constraints earlier;
- participation, as needed, in various cross-functional subjects related to the development and operation environment.
Cybersecurity / DevSecOps The position will also have an important dimension around application security:
- taking security into account from the design and development phases;
- monitoring vulnerabilities related to software components and dependencies;
- use or implementation of monitoring tools such as OWASP Dependency-Track;
- improving the traceability of components and versions used;
- participation in securing build and deployment processes;
- supporting the development team in applying security best practices.
The position will also contribute to evolving internal practices within the framework of the Cyber Resilience Act, particularly on the subjects of security by design, vulnerability management, and software component traceability.
Envisaged Technical Environment DevOps / DevSecOps - CI/CD - Ansible - OpenSearch - Jira - Packaging - Release Management - Vulnerability Management - Dependency-Track - Linux / Windows
With a background in IT, you have a minimum of 3 years of experience in DevOps, industrialization, or the operation of development environments, with a real sensitivity to cybersecurity issues. You are comfortable with version management, packaging, deployment, and automation issues, and know how to work closely with development teams.
Knowledge of application security issues, vulnerability management, and DevSecOps principles will be particularly appreciated. In a human-sized team, we are looking for a versatile, autonomous, structured, and rigorous person who is proactive, capable of moving from one subject to another and contributing to the progressive implementation of methods and tools adapted to the organization. Professional English (international context)