We are seeking an experienced Senior Software & DevSecOps Engineer for one of our clients, a globally recognized financial enterprise. This hands-on role is embedded within a brand-new cybersecurity initiative focused on building a dedicated platform for threat modeling, vulnerability management, and supply chain security. You will play a pivotal role in designing and securing enterprise-level applications, driving the adoption of Secure Development Lifecycle (SDLC) practices across the organization.
What will your tasks involve?
- Secure Software Engineering: Design, develop, and maintain scalable, cloud-native enterprise solutions using Go (Golang) and Java, ensuring the highest security standards.
- Supply Chain Security: Implement and manage security controls for software dependencies and deployment processes, driving the adoption of Software Bill of Materials (SBOM) and artifact integrity controls.
- DevSecOps & CI/CD Automation: Design and optimize continuous integration and delivery pipelines, embedding automated security testing (e.g., code scanning, dependency analysis) into the workflow.
- Threat Modeling & SDL: Champion Secure Development Lifecycle practices, conduct security design reviews, and collaborate with cybersecurity teams to mitigate vulnerabilities in open-source components.
- Architecture & Mentorship: Lead code reviews, contribute to distributed system design, and promote Infrastructure-as-Code (IaC) best practices within the engineering teams.
What we expect from you?
- Proven Expertise: 5+ years of hands-on experience in enterprise software engineering with strong proficiency in Go and Java.
- Architecture Knowledge: Deep understanding of distributed systems, microservices, APIs, and modern software design patterns.
- CI/CD & DevSecOps: Extensive practical experience in building and managing CI/CD pipelines (e.g., GitHub Actions, GitLab, Jenkins) and implementing DevSecOps tools.
- Security Mindset: Strong knowledge of SDLC practices, secure coding, and software supply chain security concepts (SBOM, vulnerability management).
- Cloud & Containers: Solid familiarity with containerization (Docker, Kubernetes) and major cloud platforms (AWS, Azure, or GCP).
What you can expect from us?
- Stable Employment: A permanent employment contract providing stability within a highly regulated, global enterprise framework.
- Hybrid Work Model: A collaborative hybrid setup requiring 3 days a week from a modern office.
- Global Scope & Greenfield Impact: Direct impact on building a brand-new cybersecurity platform from scratch that will protect a global banking ecosystem.
- Modern Ecosystem: Opportunity to work with cloud-native architectures, advanced security tools, and influence enterprise-wide technical strategies.
Employment agency entry number 47
this job offer is intended for people over 18 years of age
...