As an Information Security Engineer in a DevSecOps environment you will be responsible for designing the Secure Software Development Life Cycle (SSDLC) defining security requirements in CI/CD processes and supporting in securing the Kubernetes infrastructure. Your main tasks include:
- Establishing continuous security in all phases of the software development process (SSDLC).
- Holistic vulnerability management including identification and remediation of security flaws in source code dependencies and analysis of penetration test results.
- Development of technical security guidelines and processes.
- Monitoring security threats and trends and implementing proactive preventive measures.
- Support and advise teams and stakeholders on information security.
- Review and improve SSDLC processes.
- Liaising with the Security Operations Centre (SoC).
- Review and advise on security issues of Kubernetes clusters across the company.
- Ensuring NIS2 compliance and implementation.
Qualifications :
- Highly motivated and selfmotivated to implement security standards.
- Knowledge of recognised technical standards in the area of information security best practices and current trends.
- Knowledge of cloud container network and encryption security.
- Experience with tools and technologies such as Kubernetes Docker Jenkins Git Terraform.
- Experience in XDR/SIEM/Log/Metrics/Traces monitoring and SoC collaboration.
- Familiarity with onpremises infrastructure and migration to public cloud (AWS Azure).
- GIT in onpremises infrastructure openness to change of approach.
- Exploring solutions towards AD/Zero Trust in a 56 year timeframe.
- Supporting teams in securing CI/CD pipelines.
- Collaborate on planning for transition to public cloud.
Additional Information :
- Industry certifications such as CISSP CCSP CSSLP or comparable.
- Work is conducted in a hybrid system: 2 3 days a week from one of our office Warsaw Pozna or Lublin.
Remote Work :
No
Employment Type :
Fulltime