DevSecOps Service Owner

18k - 25k PLN/ mies.UoP
SeniorFull-time·Umowa o pracę
#425129·Dodano 22 dni temu·14
Źródło: nofluffjobs.com
Aplikuj teraz

Tech Stack / Keywords

CI/CDJiraGitHubServiceNowAWSAzure

Firma i stanowisko

Toyota Digital HUB & SSC (TME NV/SA) builds and maintains middleware systems supporting Toyota's digital systems and mobility solutions, including in-car multimedia services, EV charging platforms, factory digitalization, data-driven projects, and online sales technologies.

Wymagania

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field (or equivalent experience).
  • Experience in DevOps, DevSecOps, Platform Engineering, or Application Security roles.
  • Strong hands-on experience with CI/CD pipelines and modern SDLC practices.
  • Experience implementing security tooling such as SAST, DAST, SCA, container and artifact scanning, secrets management, and pipeline security controls.
  • Experience with cloud platforms (AWS, Azure, or GCP).
  • Strong understanding of Agile, DevOps, and secure-by-design principles.
  • Experience with incident and service management practices.

Preferred Qualifications:

  • Experience with enterprise toolchains (e.g., Jira, GitHub, GitHub Actions, ServiceNow).
  • Familiarity with DORA metrics and developer productivity frameworks.
  • Experience in regulated environments.
  • Knowledge of policy-as-code tools (e.g., OPA, Sentinel).
  • Security or cloud certifications (e.g., CISSP, CCSP, AWS Security).
  • Experience leading platform or shared services teams.

Obowiązki

Service Ownership & Strategy:

  • Own the end-to-end DevSecOps service lifecycle including design, build, run, and improvement.
  • Define and maintain the DevSecOps service roadmap aligned with business and security priorities.
  • Establish service standards, guardrails, and reference architectures.
  • Ensure the platform scales to support organizational growth and cloud adoption.

Secure SDLC Enablement:

  • Embed security controls into CI/CD pipelines and developer workflows.
  • Drive adoption of secure coding, SAST, DAST, SCA, secrets scanning, and container security.
  • Define and enforce security gates and quality thresholds.
  • Partner with AppSec and Security teams on risk management and remediation workflows.

Platform Reliability & Operations:

  • Ensure high availability, performance, and resilience of DevSecOps tooling and pipelines.
  • Define SLAs/SLOs and monitor service health.
  • Lead incident management and root cause analysis for platform issues.
  • Manage upgrades, capacity planning, and technical debt.

Governance, Risk & Compliance:

  • Ensure DevSecOps processes comply with internal security policies and external regulatory requirements.
  • Support audit readiness (e.g., SOX, ISO, SOC2).
  • Implement access controls, audit logging, and segregation of duties.
  • Maintain risk register and drive remediation plans.

Automation & Continuous Improvement:

  • Drive pipeline standardization and reusable automation patterns.
  • Reduce manual controls through policy-as-code and infrastructure-as-code.
  • Optimize lead time, deployment frequency, and failure rates.
  • Promote shift-left and shift-right security practices.

Stakeholder & Service Management:

  • Act as primary service owner and escalation point.
  • Manage service demand, intake, and prioritization.
  • Collaborate with Engineering, Security, Cloud, and Operations teams.
  • Provide service reporting to leadership.

Financial & Vendor Management:

  • Manage DevSecOps platform budget and forecast.
  • Optimize licensing.

Benefity

  • Health insurance
  • Sport card
  • Lunch subsidy
  • Car leasing
  • Language lessons
  • Bonuses
  • Annual or Quarterly bonus
  • Flexible hours
  • Remote or hybrid work
  • Private healthcare
  • Sport subscription
  • Lunch card
  • International projects
  • Retirement savings scheme (PPK)
  • E-learning platform (mindtools)
  • Career development
  • Employee Recommendation Programme
  • Mindfulness and Stress Management Programme
  • In-house trainings
  • Modern office
  • No dress code
Opieka zdrowotna
Karta sportowa
Premie
Płatny urlop
Elastyczne godziny
Kursy językowe
Parking dla aut
Szkolenia wewnętrzne

Inne informacje

  • Location: Wrocław, Silver Tower Office Center
  • Working Pattern: Hybrid - 2 to 3 days per week in the office, in line with the need
  • Reporting line: MW manager / Team Lead
  • Job Type: undefined time period contract
  • Starting date: Position available since September 2026
Toyota Digital HUB & SSC (TME NV/SA)

Toyota Digital HUB & SSC (TME NV/SA)

9 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz