About the role
Clients ask us to make their software delivery safer without slowing it down. This role does that work inside their engineering teams. You integrate static analysis, dependency and container scanning into CI/CD, set up secrets management and signed builds, and agree sensible quality gates with developers. You also help clients produce SBOMs and the evidence that customers and auditors now expect. You work remotely within the EU with our cloud security architects and product security engineers, and with client platform teams.
What you will do
- Integrate SAST, SCA, container and infrastructure-as-code scanning into GitLab CI, GitHub Actions or Azure DevOps
- Set up secrets management, artefact signing and provenance for build pipelines
- Define policy as code and quality gates together with development teams
- Generate and maintain SBOMs and vulnerability handling workflows
- Coach developers on secure coding practices and triage of scanner findings
What you bring
- 3+ years in DevOps, platform engineering or software development
- Hands-on experience with at least one major CI/CD platform and with Kubernetes
- Working knowledge of security scanning tools such as Semgrep, Trivy, Snyk or SonarQube
- Scripting in Python, Go or Bash
- Reliable home workspace within the EU and occasional travel to client sites
Good to have
- Experience with Sigstore, SLSA or in-toto
- Knowledge of Open Policy Agent or Kyverno
Languages
English (C1), German (B1) an advantage