Lead DevSecOps Engineer

McKesson’s Corporate

Cork

Hybrid

EUR 83,000 - 138,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

McKesson seeks an experienced cybersecurity engineering leader to own application security and DevSecOps across cloud, on-prem, and hybrid platforms. You will implement scalable security controls in CI/CD, drive adoption of security tools, and shepherd software supply chain security through Xray, Black Duck, and Sonatype.

This role requires mentoring teams, establishing security standards, and improving developer experience while reducing risk.

Qualifications

  • 10+ years of progressive experience in cybersecurity engineering, application security, DevSecOps, cloud security, or related security engineering disciplines.
  • Experience implementing and operating enterprise-scale security tools such as GitHub Advanced Security, SonarQube, and/or OWASP ZAP.
  • Experience with software supply chain security and open-source risk management tools such as JFrog Xray/Curation, Black Duck, Sonatype, or FOSSA.
  • Proficiency in scripting and automation using Python, Bash, JavaScript, or similar languages.
  • Experience designing and securing CI/CD pipelines using GitHub Actions, Jenkins, GitLab CI, Azure DevOps, or comparable platforms.
  • Hands-on experience securing cloud environments (AWS, Azure, and/or GCP).
  • Experience with containerization and orchestration technologies including Docker and Kubernetes.

Responsibilities

  • Lead enterprise application security and DevSecOps initiatives across cloud, on-premises, and hybrid environments.
  • Design and implement scalable security controls embedded within CI/CD pipelines and developer platforms.
  • Drive adoption and operationalization of security tools including GitHub Advanced Security, OWASP ZAP, Veracode, and SonarQube.
  • Lead software supply chain security programs using tools such as JFrog Xray/Curation, Black Duck, Sonatype, and FOSSA.
  • Develop automation and security integrations using Python, Bash, JavaScript, or similar scripting languages.
  • Partner with engineering and platform teams to establish secure-by-design practices for applications, APIs, containers, and cloud workloads.
  • Provide technical leadership during security incidents, vulnerability management efforts, and remediation activities.
  • Mentor engineers and influence enterprise security architecture, standards, and roadmaps.
  • Develop and maintain security standards and controls for Kubernetes, containers, Infrastructure as Code (Terraform), and cloud-native application platforms.
  • Build and operationalize security automation, policy-as-code, and self-service security capabilities that improve developer experience while reducing organizational risk.

Skills

DevSecOps
Cloud security
Application security
Scripting
CI/CD security

Education

Bachelor's degree in Computer Science/Cybersecurity/IT/Engineering

Tools

GitHub Advanced Security
SonarQube
OWASP ZAP
JFrog Xray
Black Duck
Sonatype
FOSSA
Terraform
Kubernetes
Docker
Jenkins
GitHub Actions

Job description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve - we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people.

What You'll Do
  • Lead enterprise application security and DevSecOps initiatives across cloud, on-premises, and hybrid environments.
  • Design and implement scalable security controls embedded within CI/CD pipelines and developer platforms.
  • Drive adoption and operationalization of security tools including GitHub Advanced Security, OWASP ZAP, Veracode, and SonarQube.
  • Lead software supply chain security programs using tools such as JFrog Xray/Curation, Black Duck, Sonatype, and FOSSA.
  • Develop automation and security integrations using Python, Bash, JavaScript, or similar scripting languages.
  • Partner with engineering and platform teams to establish secure-by-design practices for applications, APIs, containers, and cloud workloads.
  • Provide technical leadership during security incidents, vulnerability management efforts, and remediation activities.
  • Mentor engineers and influence enterprise security architecture, standards, and roadmaps.
  • Develop and maintain security standards and controls for Kubernetes, containers, Infrastructure as Code (Terraform), and cloud-native application platforms.
  • Build and operationalize security automation, policy-as-code, and self-service security capabilities that improve developer experience while reducing organizational risk.
Basic Requirements
  • 10+ years of progressive experience in cybersecurity engineering, application security, DevSecOps, cloud security, or related security engineering disciplines.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or equivalent experience.
  • Experience implementing and operating enterprise-scale security tools such as GitHub Advanced Security, SonarQube, and/or OWASP ZAP.
  • Experience with software supply chain security and open-source risk management tools such as JFrog Xray/Curation, Black Duck, Sonatype, or FOSSA.
  • Proficiency in scripting and automation using Python, Bash, JavaScript, or similar languages.
  • Experience designing and securing CI/CD pipelines using GitHub Actions, Jenkins, GitLab CI, Azure DevOps, or comparable platforms.
  • Hands-on experience securing cloud environments (AWS, Azure, and/or GCP).
  • Experience with containerization and orchestration technologies including Docker and Kubernetes.
  • Experience managing enterprise source code management platforms such as Github or Gitlab, developer ecosystems, and software delivery infrastructure.
Preferred Skills/Experience
  • Master's degree in Cybersecurity, Computer Science, or related field.
  • Experience implementing policy-as-code, infrastructure-as-code security, and automated security guardrails.
  • Experience with threat modeling, secure code reviews, and application security testing methodologies.
  • Knowledge of zero-trust architectures, identity security, cryptography, and cloud-native security controls.
  • Experience building security metrics, dashboards, and executive-level reporting.
  • Relevant certifications such as CISSP, CCSP, CSSLP, AWS Security Specialty, Azure Security Engineer, or GIAC certifications.
  • Experience leading large-scale security transformation initiatives in highly regulated environments.
  • Experience mentoring engineers and serving as a technical leader across multiple teams.
  • Experience securing and managing Kubernetes platforms, container registries, and cloud-native application environments.
  • Experience implementing software supply chain security controls including artifact signing, SBOM management, provenance, dependency governance, and secure build practices.

At McKesson, we care about the well-being of the patients and communities we serve, and that starts with caring for our people. That's why we have a Total Rewards package that includes comprehensive benefits to support physical, mental, and financial well-being. Our Total Rewards offerings serve the different needs of our diverse employee population and ensure they are the healthiest versions of themselves. As part of Total Rewards, we are proud to offer a competitive compensation package at McKesson. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered.

Our Base Pay Range for this position €82,500 - €137,500

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead DevSecOps Engineer
Lead DevSecOps Engineer

Mckesson Corporation • Cork

On-site
EUR 83,000 - 138,000
Total Rewards benefits
Cybersecurity Risk Operations Lead – (Enterprise Applications)
Cybersecurity Risk Operations Lead – (Enterprise Applications)

Mckesson Corporation • Cork

On-site
EUR 62,000 - 103,000
Total Rewards package
Senior Third Party Risk (TPRM) Cybersecurity Analyst
Senior Third Party Risk (TPRM) Cybersecurity Analyst

McKesson’s Corporate • Cork

Hybrid
EUR 73,000 - 121,000
Cybersecurity Risk Operations Lead – (Enterprise Applications)
Cybersecurity Risk Operations Lead – (Enterprise Applications)

McKesson’s Corporate • Cork

On-site
EUR 62,000 - 103,000
Sr. Associate Cybersecurity IGA Tester
Sr. Associate Cybersecurity IGA Tester

McKesson’s Corporate • Cork

On-site
EUR 41,000 - 68,000
Total Rewards package
Annual bonus potential
Cybersecurity Risk Operations Lead – (Enterprise Applications) McKesson Medical-Surgical Inc. · Cork, Ireland Full-time · On-site €61,500–102,500 1 hour ago
Cybersecurity Risk Operations Lead – (Enterprise Applications) McKesson Medical-Surgical Inc. · Cork, Ireland Full-time · On-site €61,500–102,500 1 hour ago

Emploive • Cork

Remote
EUR 62,000 - 103,000
Senior Manager, Cloud Data Platform Engineering
Senior Manager, Cloud Data Platform Engineering

McKesson • Cork

On-site
EUR 69,000 - 114,000
Director, Data Engineering
Director, Data Engineering

McKesson • Cork

On-site
EUR 92,000 - 153,000
Sr. Associate Cybersecurity IGA Tester
Sr. Associate Cybersecurity IGA Tester

Mckesson Corporation • Cork

On-site
EUR 41,000 - 68,000
Senior Third Party Risk (TPRM) Cybersecurity Analyst
Senior Third Party Risk (TPRM) Cybersecurity Analyst

Mckesson Corporation • Cork

Hybrid
EUR 73,000 - 121,000
Total Rewards package
Competitive compensation