Senior DevSecOps Engineer – Kubernetes & Software Supply Chain Security

Twoday Denmark

København

On-site

DKK 1,100,000 - 1,600,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Twoday Denmark is seeking a hands-on Senior DevSecOps Engineer to strengthen security across development pipelines, Kubernetes platforms and production environments for a major public-sector client. The role is full-time and onsite in Copenhagen.

You will embed security into deployment and operations, implement automated controls (SAST, SCA, SBOM, signing), manage IaC and supply chain integrity, and contribute to risk-based remediation and incident response.

Qualifications

  • Hands-on DevSecOps experience
  • Experience implementing security controls in real development and production environments
  • Fluent in Danish and English
  • Experience with software supply chain security and SBOM

Responsibilities

  • Implement automated security controls across CI/CD pipelines (SAST, SCA, secret scanning, container scanning, IaC scanning)
  • Secure software supply chain (SBOM generation, artefact signing/verification)
  • Enforce least-privilege in CI/CD pipelines and runners
  • Hardening Linux/Windows and vulnerability remediation
  • Support runtime threat detection, security monitoring, and incident response
  • Document security controls for audit/compliance and transfer knowledge to team

Skills

DevSecOps
Kubernetes security
CI/CD pipelines
SBOM & software supply chain
IaC scanning
Threat detection
Policy-as-code
Python/Bash scripting
Cloud security
Vulnerability management

Education

Bachelor's degree in CS or related field
Security certification (e.g., CISSP/CISM)

Tools

GitLab CI
GitHub Actions
Terraform
Ansible
Vault

Job description

Senior DevSecOps Engineer - Kubernetes & Software Supply Chain Security
Permanent position at Twoday | Copenhagen

Twoday is the leading digital transformation partner in Northern Europe with a global presence. With approximately 3,000 technologies, we collaborate with the most admired private and public organizations to deliver cutting-edge digital solutions. Our deep industry expertise spans Data & AI, software development, digital experiences, and business applications. Operating across the Nordics and Lithuania, our team generated a revenue of 280 million euros in 2023. We serve over 8,000 customers, supporting their digital transformation journeys.

Twoday is a leading digital transformation partner in Northern Europe, with approximately 3,000 specialists delivering digital solutions to public and private organisations.

We are looking for an experienced, hands-on DevSecOps Engineer to strengthen security across development pipelines, Kubernetes platforms and production environments for one of our major public-sector clients.

This is a role for someone who implements, automates and maintains security controls - not someone who only advises on them.

Your role

You will work alongside an experienced operations team, embedding security into development, deployment and daily operations while helping the team adopt secure, sustainable engineering practices.

Your responsibilities will include:

  • Implementing automated security controls across CI/CD pipelines, including SAST, SCA, secret scanning, container scanning and Infrastructure as Code (IaC) scanning.
  • Securing the software supply chain through SBOM generation (CycloneDX/SPDX), artefact signing and verification (e.g. Sigstore/cosign), SLSA principles and secure branch, review and release processes.
  • Securing CI/CD pipelines and runners using least-privilege principles.
  • Implementing Kubernetes security controls, including admission control, policy-as-code, Pod Security Standards, RBAC, network policies and secrets management.
  • Hardening Linux and Windows environments and managing vulnerabilities from identification through to remediation.
  • Supporting runtime threat detection, security monitoring, incident response and forensic investigations.
  • Establishing security frameworks for AI-assisted development and autonomous AI agents, including controlled permissions, review gates, traceability and protection against prompt injection.
  • Documenting security controls for compliance and audit purposes, while sharing knowledge and transferring solutions to the internal team.
What we're looking for

You have practical DevSecOps experience and can demonstrate that you have implemented security controls in real development and production environments.

We are particularly interested in experience with:

  • Software supply chain security: SAST, SCA, secret scanning, SBOM, artefact signing and verification, container and IaC scanning.
  • CI/CD and automation: GitLab CI, GitHub Actions or similar, secure pipelines and runners, Terraform, Ansible and scripting with Python, Bash or PowerShell.
  • Kubernetes security: Kyverno, OPA Gatekeeper or similar, admission control, Pod Security Standards, RBAC, network policies and secrets management using Vault, External Secrets or equivalent.
  • Platform security: CIS-based Linux hardening, Windows Server hardening and runtime detection tools such as Falco.
  • Vulnerability management and incident response: Risk-based remediation, logging, SIEM solutions such as ELK or Wazuh, incident handling and forensics.
  • AI security: Security controls for AI-assisted and agentic workflows, including autonomy boundaries, human review, prompt injection protection and secure credential handling.
  • Compliance: NIS2, ISO 27001/27002 and GDPR.

Experience with virtualisation platforms such as Proxmox is useful. Experience from the public sector or organisations subject to NIS2 is an advantage, but not essential.

The environment follows an open-source-first approach with EU-based infrastructure. Experience with US hyperscalers is not relevant to this assignment.

You must be fluent in Danish and English, both written and spoken, and able to work onsite full time in Copenhagen.

Who you are

You are hands-on, security-conscious and pragmatic. You see security as an enabler rather than an obstacle, prioritise risks sensibly and enjoy helping experienced engineers strengthen their security practices. You take ownership, document your work and build solutions that others can maintain.

Why Twoday?

At Twoday, you will work with skilled colleagues on complex, business-critical solutions that make a real difference. We offer a collaborative environment with professional freedom, technical challenges and opportunities to develop your expertise.

Diversity & inclusion

Do you not meet all the requirements? Studies show that women and minorities are less likely to apply if they don’t meet every qualification. At Twoday, we are committed to building an inclusive workplace where everyone is welcome.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DevSecOps / Cloud Security Engineer – AI Platform Security
Senior DevSecOps / Cloud Security Engineer – AI Platform Security

Twoday • København

On-site
DKK 900,000 - 1,100,000
Hybrid work model
Office in Copenhagen
Senior Key Resource & Technical Lead – Digital Health
Senior Key Resource & Technical Lead – Digital Health

Twoday A/S • København

On-site
DKK 900,000 - 1,200,000
DevOps Engineer – Business-Critical Platforms
DevOps Engineer – Business-Critical Platforms

Twoday A/S • København

On-site
DKK 700,000 - 1,100,000
Senior Platform Engineer – AI-Assisted Development & Kubernetes
Senior Platform Engineer – AI-Assisted Development & Kubernetes

Twoday Denmark • København

On-site
DKK 900,000 - 1,100,000
Senior Platform Engineer – AI-Assisted Development & Kubernetes
Senior Platform Engineer – AI-Assisted Development & Kubernetes

Twoday • København

On-site
DKK 900,000 - 1,200,000
DevOps / Cloud Engineer – AI Platform & Kubernetes
DevOps / Cloud Engineer – AI Platform & Kubernetes

Twoday • Københavns Kommune

On-site
DKK 70,000 - 100,000
Opportunities for learning and certification
Flexible workplace
Strong professional environment for knowledge sharing
Senior Backend .NET Developer – Digital Health
Senior Backend .NET Developer – Digital Health

Twoday • København

On-site
DKK 900,000 - 1,300,000
Senior Key Resource & Technical Lead – Digital Health
Senior Key Resource & Technical Lead – Digital Health

Twoday • København

On-site
DKK 673,000 - 1,046,000
Senior Solution Architect – Digital Health & Technical Transition
Senior Solution Architect – Digital Health & Technical Transition

Twoday Denmark • København

On-site
DKK 900,000 - 1,200,000
Senior Java Developer
Senior Java Developer

Twoday Denmark • København

On-site
DKK 900,000 - 1,300,000