Lead SecOps Engineer
⚲ Wroclaw
Do uzgodnienia
Wymagania
- Vulnerability Management
- Security Hardening
- GitHub Actions
- Secure SDLC
- DevSecOps
- Kubernetes
- CI/CD
- Software Composition Analysis
Opis stanowiska
We are looking for a Lead SecOps Engineer to join a team building security solutions that help organizations monitor, assess and improve the security posture of open-source software. The work focuses on a platform for unified visibility into open-source vulnerabilities and a solution that provides security ratings for open-source libraries, enabling better risk-based decisions across development teams.
Responsibilities
• Contribution to the development and enhancement of solutions for open-source vulnerability monitoring and security rating
• Support and improvement of CI/CD pipelines and GitHub Actions–based workflows
• Application of DevSecOps and secure engineering practices throughout the software lifecycle
• Close collaboration with cross-functional teams to deliver scalable, reliable and secure solutions
• Contribution as a team player by collaborating, sharing knowledge and supporting overall product quality
Requirements
• 7+ years of experience in DevOps or Site Reliability Engineering
• Skills in DevSecOps orchestration, Secure Software Development Life Cycle and security-as-code
• Knowledge of Software Composition Analysis and OSS license compliance
• Understanding of CVSS scoring, exploitability analysis and vulnerability remediation strategies
• Hands-on experience securing GitHub Actions workflows and integrating security gates into CI/CD pipelines
• Expertise in CI/CD, Kubernetes and Security Hardening
• Proficiency in Security Testing Tools, Security Assessment and Vulnerability Management
• Strong communication, ownership mindset and ability to work effectively in a team environment
• English proficiency at B2 level or higher
Nice to have
• Familiarity with Google Cloud Platform
• Background in Open Source Software Development
We offer
• We gather like-minded people:Engineering community of industry professionals
• Friendly team and enjoyable working environment
• Flexible schedule and opportunity to work remotely within Poland
• Chance to work abroad for up to 60 days annually
• Business-driven relocation opportunities
• We provide growth opportunities:Outstanding career roadmap
• Leadership development, career advising, soft skills, and well-being programs
• Certification (GCP, Azure, AWS)
• Unlimited access to LinkedIn Learning, Get Abstract, Cloud Guru
• English classes
• We cover it all:Stable income (Employment Contract or B2B)
• Participation in the Employee Stock Purchase Plan
• Benefits package (health insurance, multisport, shopping vouchers)
• Strategically located offices featuring entertainment and relaxation zones, table tennis and football, free snacks, fantastic coffee, and more
• Referral bonuses
• Corporate, social and well-being events
• Please, note:The set of bonuses might vary based on the role you apply for – specifics will be discussed with our recruiter during the general interview.
• We will reach out to selected candidates exclusively.
EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our customers, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.
Responsibilities
• Contribution to the development and enhancement of solutions for open-source vulnerability monitoring and security rating
• Support and improvement of CI/CD pipelines and GitHub Actions–based workflows
• Application of DevSecOps and secure engineering practices throughout the software lifecycle
• Close collaboration with cross-functional teams to deliver scalable, reliable and secure solutions
• Contribution as a team player by collaborating, sharing knowledge and supporting overall product quality
Requirements
• 7+ years of experience in DevOps or Site Reliability Engineering
• Skills in DevSecOps orchestration, Secure Software Development Life Cycle and security-as-code
• Knowledge of Software Composition Analysis and OSS license compliance
• Understanding of CVSS scoring, exploitability analysis and vulnerability remediation strategies
• Hands-on experience securing GitHub Actions workflows and integrating security gates into CI/CD pipelines
• Expertise in CI/CD, Kubernetes and Security Hardening
• Proficiency in Security Testing Tools, Security Assessment and Vulnerability Management
• Strong communication, ownership mindset and ability to work effectively in a team environment
• English proficiency at B2 level or higher
Nice to have
• Familiarity with Google Cloud Platform
• Background in Open Source Software Development
We offer
• We gather like-minded people:Engineering community of industry professionals
• Friendly team and enjoyable working environment
• Flexible schedule and opportunity to work remotely within Poland
• Chance to work abroad for up to 60 days annually
• Business-driven relocation opportunities
• We provide growth opportunities:Outstanding career roadmap
• Leadership development, career advising, soft skills, and well-being programs
• Certification (GCP, Azure, AWS)
• Unlimited access to LinkedIn Learning, Get Abstract, Cloud Guru
• English classes
• We cover it all:Stable income (Employment Contract or B2B)
• Participation in the Employee Stock Purchase Plan
• Benefits package (health insurance, multisport, shopping vouchers)
• Strategically located offices featuring entertainment and relaxation zones, table tennis and football, free snacks, fantastic coffee, and more
• Referral bonuses
• Corporate, social and well-being events
• Please, note:The set of bonuses might vary based on the role you apply for – specifics will be discussed with our recruiter during the general interview.
• We will reach out to selected candidates exclusively.
EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our customers, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.
🔍 Dekoder Ogłoszenia
🟡
Contribution to the development and enhancement of solutions for open-source vulnerability monitoring and security rating
Może oznaczać zarówno tworzenie nowych funkcji, jak i drobne poprawki oraz utrzymanie istniejących rozwiązań.
🟡
Support and improvement of CI/CD pipelines and GitHub Actions–based workflows
Oprócz tworzenia nowych potoków, będziesz głównie zajmować się utrzymaniem i naprawianiem istniejących.
🟢
Application of DevSecOps and secure engineering practices throughout the software lifecycle
Oczekuje się, że będziesz wdrażać i egzekwować najlepsze praktyki bezpieczeństwa na każdym etapie tworzenia oprogramowania.
🟢
Close collaboration with cross-functional teams to deliver scalable, reliable and secure solutions
Będziesz musiał efektywnie komunikować się i współpracować z różnymi zespołami, aby osiągnąć wspólne cele.
🟢
Contribution as a team player by collaborating, sharing knowledge and supporting overall product quality
Oczekuje się aktywnego udziału w życiu zespołu, dzielenia się wiedzą i dbania o jakość produktu.