DevSecOps Architect / Technical Lead
Tech Stack / Keywords
Firma i stanowisko
The customer is a financial services organization providing banking products and digital solutions for individual and business clients. The company operates through an established service network and online platforms and is part of a larger international financial group. The project focuses on defining a structured architecture roadmap for a large-scale digital banking transformation program including platform modernization, API governance, security, data and analytics, system decoupling, and phased migration of business capabilities.
Wymagania
- Experience in DevSecOps, cloud security or platform security for 5+ years.
- Strong hands-on experience with Microsoft Azure.
- Practical experience with Azure DevOps or comparable enterprise CI/CD platforms.
- Experience designing and implementing secure CI/CD pipelines.
- Experience integrating security scanners and quality gates into pipelines.
- Practical knowledge of Kubernetes and container security, preferably AKS.
- Experience with Infrastructure as Code, preferably Terraform.
- Knowledge of identity, secrets and certificate management.
- Understanding of SAST, SCA, DAST, secret scanning, IaC scanning and container scanning.
- Ability to combine solution design and technical leadership with hands-on implementation.
- Strong communication and documentation skills.
- Level of English from Upper-Intermediate and above.
Nice to have:
- Experience in the banking domain.
- Experience with Jenkins, Bitbucket and migration to Azure DevOps.
- Experience with Azure Key Vault, Azure Container Registry and Defender for Containers.
- Familiarity with tools such as SonarQube, Sonatype, Nexus, Gitleaks, Checkov or OWASP ZAP.
- Understanding of SBOM, artifact signing and software supply-chain security.
- Experience with DefectDojo, Microsoft Sentinel or other vulnerability-management and SIEM solutions.
- Experience with Azure Policy, Gatekeeper, OPA or Kubernetes admission controls.
- Experience in banking or another regulated industry.
- Understanding of DORA, audit traceability and segregation-of-duties requirements.
Obowiązki
- Translating the DevSecOps master plan into a practical implementation roadmap.
- Defining reusable CI/CD, security and release-management standards.
- Supporting the transition from Bitbucket/Jenkins to Azure Repos and Azure Pipelines.
- Implementing security scanning and release gates in CI/CD pipelines.
- Configuring security controls for AKS, container images, identities and secrets.
- Establishing artifact signing, SBOM generation and secure promotion processes.
- Integrating platform security events with the bank’s monitoring and SIEM solutions.
- Defining vulnerability-management, audit-evidence and incident-response processes.
- Providing technical leadership, recommendations and knowledge transfer to delivery teams.
- Participating directly in configuration, integration and troubleshooting activities.
Benefity
- Opportunity to work in teams with leaders in FinTech, Healthcare, Retail, Telecom, and others.
- Ability to change projects or develop expertise in interesting business domains.
- Flexible work options: fully remote, office, or hybrid.
- Professional, financial, and career growth with mentoring and adaptation systems.
- Potential to earn up to an additional 1,000 EUR per month as part of annual bonus.
- Access to a corporate training portal with a comprehensive and updated knowledge base.
- Corporate life benefits including parties, pizza days, PlayStation, fruits, coffee, snacks, and movies.
- Certification compensation (e.g., AWS, PMP).
- Referral program.
- Private health insurance and sports compensation, dependent on employment type.
Inne informacje
Informujemy, że administratorem danych jest Andersen Soft UAB z siedzibą w Krakow, ul. Al. Pokoju 18, 31 - 564 dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
Andersen
54 aktywne oferty