Senior DevSecOps Engineer (Security, CI/CD, Embedded Systems)
Brak informacji o wynagrodzeniu
SeniorFull-time
#329046·Dodano 14 dni temu·22
Źródło: YourITeamsTech Stack / Keywords
SecurityCI/CDEmbeddedSoftware DevelopmentTestingDevOpsC/C++GitHub
Firma i stanowisko
The role is part of a team working on a long-term technological project focused on aligning the software development environment with the Cyber Resilience Act (CRA) requirements. The project involves a broad portfolio of products including embedded systems and long lifecycle solutions, operating within an environment with many existing repositories and diverse build systems.
Wymagania
- Commercial experience as a DevOps Engineer or DevSecOps Engineer.
- Strong understanding of CI/CD processes and software development lifecycle.
- Experience in application security, including SAST, SCA, and vulnerability management.
- Proficiency with C/C++ or embedded environments.
- Familiarity with CI/CD tools such as GitHub, GitLab, GitHub Actions, and AWS.
- Experience working with multiple repositories and legacy codebases.
- Ability to integrate tools in heterogeneous build environments.
- Capability to design end-to-end solutions.
- Proficient communication skills in English.
Preferred Qualifications:
- Experience with security regulations such as the Cyber Resilience Act or similar frameworks.
- Experience in developing SBOMs and managing vulnerabilities at the organizational level.
- Knowledge of security tooling such as Veracode, CodeSonar, or equivalent.
- Experience designing auditable and compliance-aligned solutions.
- Experience scaling DevSecOps practices within large organizations.
Obowiązki
- Initiate and scale security processes such as Static Application Security Testing (SAST) and Software Composition Analysis (SCA) for existing codebases.
- Design and develop CI/CD pipelines with integrated security considerations.
- Generate and maintain Software Bill of Materials (SBOM).
- Integrate security tools with various build systems including CMake, Make, and custom vendor-specific solutions.
- Build scalable security workflows across multiple repositories and teams.
- Collaborate in developing approaches for vulnerability management and handling exceptions (waivers).
- Ensure traceability and support for audit requirements related to the Cyber Resilience Act.
- Work closely with development teams to implement and uphold security standards.
Oferta
- Opportunity to contribute to a significant, long-term project aligned with emerging cybersecurity regulations.
- Work with advanced technologies including cloud platforms, embedded systems, and sophisticated security tools.
- Flexible work arrangements with options for remote or hybrid work.
- Collaboration with diverse development teams across multiple products and repositories.
- Professional growth in security and DevSecOps domains within a complex, legacy environment.
- Unique TEAL culture, relationship- and respect-driven community, non-corporate atmosphere.
- Agile approach and no bureaucracy.
- Outstanding integration trips to various places in Europe for all employees.
- Activities to support your well-being and health.
- Luxmed Gold Extended medical care and Multisport Plus benefit.
Elastyczne godziny
Opieka zdrowotna
Karta sportowa
YourITeams
116 aktywnych ofert