auticon
auticon
New

DevSecOps Engineer

130 - 160 PLN/ godz.B2B
SeniorFull-time·B2B
#413685·Dodano dziś·0
Źródło: auticon
Aplikuj teraz

Tech Stack / Keywords

JenkinsCI/CDJavaMavenNode.jsPythonHelmTerraform

Firma i stanowisko

auticon is a neurodivergent-friendly organization based in Kraków, Poland, with a majority of consultants on the autism spectrum. The company focuses on providing an inclusive and supportive workplace with accommodations for individuals to thrive, including autism-friendly workspaces, culture, and policies.

Wymagania

  • 7+ years of experience in software engineering.
  • Minimum 3 years working with CI/CD platforms or in a DevSecOps role.
  • Strong hands-on experience with Jenkins and developing Jenkins Shared Libraries using Groovy.
  • Advanced Python programming skills focused on automation, scripting, and JSON/YAML processing.
  • Deep understanding of packaging and dependency management for Maven, NPM, and Python, with practical exposure to Helm, Terraform, and container image metadata.
  • Solid knowledge of software supply chain security concepts including SLSA, CycloneDX SBOM, and artifact digests.
  • Experience with security tools such as SonarQube, Sonatype IQ, SAST solutions, and container image scanning.
  • Proven ability to optimize CI/CD pipelines via caching, parallelization, dependency pruning, and performance improvements.
  • Good understanding of compliance requirements and secure software delivery practices.

Nice to have:

  • Experience with artifact signing and attestations using tools like Cosign and OCI.
  • Knowledge of Terraform module publishing and Helm chart publishing workflows.
  • Experience with GitOps methodologies or release automation.
  • Hands-on experience with AWS and/or GCP cloud environments.

Obowiązki

  • Design, develop, and maintain Jenkins Shared Library components written in Groovy to support build, test, packaging, security scanning, and deployment processes.
  • Extend and enhance Python-based tooling for SLSA provenance generation, SBOM creation, hash and digest calculations, and aggregation of security scan results from tools like SonarQube, Sonatype IQ, SAST, and container image scanners.
  • Optimize pipeline performance using parallel execution, caching, dependency prefetching, and reducing BOM scope.
  • Ensure artifact integrity via SHA1/SHA256 mapping, reproducible builds, and evidence modeling.
  • Refactor legacy scripts to remove global state, consolidate hashing mechanisms, and standardize reusable templates.
  • Create and maintain documentation for ci-config.yaml standards, best practices, and usage guidelines.
  • Mentor engineering teams on secure CI/CD development and software supply chain security best practices.
  • Investigate, troubleshoot, and proactively prevent CI/CD pipeline issues and incidents.

Benefity

  • Inclusive workplace designed for neurodivergent individuals.
  • Tailored support and accommodations to help employees thrive.
  • Transparent and straightforward recruitment processes avoiding unnecessary stress.
  • Autism-friendly workspaces, culture, and policies supporting flexibility and open communication.
auticon

auticon

19 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz