Lead DevSecOps Security Engineer
Tech Stack / Keywords
Firma i stanowisko
Were the worlds leading sports technology company, at the intersection between sports, media, and betting. More than 1,700 sports federations, media outlets, betting operators, and consumer platforms across 120 countries rely on our know-how and technology to boost their business.
Wymagania
- Proven experience working in DevSecOps, Security Engineering, Application Security or Cloud Security roles.
- Strong understanding of modern software development practices and CI/CD pipelines.
- Experience securing cloud-native environments, preferably AWS.
- Experience working with Kubernetes and container security.
- Experience implementing security controls within software delivery pipelines.
- Strong understanding of vulnerability management processes and remediation workflows.
- Good knowledge of application security concepts and the OWASP Top 10.
- Experience collaborating with engineering teams in an advisory, enablement or security engineering capacity.
- Strong stakeholder management and communication skills.
- Ability to operate independently and drive initiatives forward in a global organisation.
- A pragmatic, solution-oriented approach to security.
Nice to Have:
- Experience with Cloud Security Posture Management (CSPM) platforms.
- Experience with Kubernetes Security Posture Management (KSPM) solutions.
- Knowledge of AWS and GCP security best practices.
- Experience with GitLab Ultimate.
- Experience with Infrastructure as Code and security automation.
- Experience in large-scale enterprise organisations.
- Experience supporting modern AI-enabled development environments.
- Relevant security certifications.
Obowiązki
Secure SDLC & DevSecOps:
- Contribute to the implementation of Secure Software Development Lifecycle practices across engineering teams.
- Help embed security controls and automated security testing into CI/CD pipelines.
- Help ensure security requirements are integrated into development processes from design through deployment.
- Partner with engineering teams to enable secure-by-design application development.
- Support security automation and continuous improvement across software delivery pipelines.
Cloud & Kubernetes Security:
- Support the development and enhancement of cloud security posture management capabilities.
- Work with engineering teams to secure AWS-based environments and cloud-native platforms.
- Contribute to improving Kubernetes security posture through the implementation of security controls, monitoring and best practices.
- Assess cloud security risks and provide practical remediation guidance.
Vulnerability Management:
- Support risk-based vulnerability management activities across applications and infrastructure.
- Analyse vulnerability findings, determine business risk and establish remediation priorities.
- Partner with engineering teams to ensure vulnerabilities are remediated effectively and within agreed timelines.
- Contribute to scalable processes for vulnerability identification, triage and reporting.
Application Security:
- Contribute application security guidance throughout the development lifecycle.
- Support engineering teams with secure coding practices and remediation recommendations.
- Work as a trusted security partner on security design decisions and implementation approaches.
- Contribute to security awareness and developer enablement initiatives.
Security Engineering & Tooling:
- Contribute to the management and enhancement of security tooling integrated within development and operational environments.
- Evaluate existing and future security platforms and identify opportunities for optimisation.
- Work with tools and technologies such as GitLab, SonarQube, Mend, Tenable, Sysdig and related solutions.
- Support proof-of-concept activities, platform integrations and security automation initiatives.
Benefity
- The opportunity to shape and mature DevSecOps capabilities within one of the world's leading sports technology companies.
- Meaningful ownership and the ability to influence security strategy and engineering practices.
- Access to modern cloud, platform and security technologies.
- A collaborative international environment working with highly skilled engineering and security professionals.
- Continuous learning and professional development opportunities.
- Competitive compensation and benefits package.
- Career growth opportunities within a global technology organisation.
Inne informacje
Sportradar is an Equal Opportunity Employer committed to diversity, equity, inclusion and belonging. All qualified applicants will receive consideration regardless of age, race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability, or protected veteran status. Role requires working from office in Warsaw five days per week.
Sportradar
8 aktywnych ofert